For Filestack OCR tasks, sign a policy with read and convert scopes or you get a 403 naming the task. And do not call the OCR URL on every page view: it re-runs each time, so extract once at upload time and store the result yourself.

Context: Official Filestack blog (filestack-processing-tasks): documents two real gotchas. First, the OCR and document detection tasks require a signed policy once app security is on. A missing signature returns HTTP 403 naming the task, e.g. 'security required for tasks: ocr', and the policy needs the read and convert calls. Second, the OCR tasks answer Cache-Control: private and run again on every request, so a page that renders extracted text should store the JSON in its own database instead of hitting the transformation URL per view.