DEVELOPER DOCUMENTATION

Build verification on a server-owned boundary.

Start with one implemented CAPTCHA version, collect its opaque response in the browser, and consume that response exactly once from your trusted backend.

Maintained documentation3 sectionsAPI contract

Choose an experience

V1 is an explicit accessible challenge, V2 is a managed step-up flow, and V3 returns a frictionless action score after backend verification.

  • V1 widget: /widget/v1.js
  • V2 SDK: /sdk/v2/giws-captcha.js
  • V3 SDK: /sdk/v3/giws-captcha.js

Keep the secret on the server

The public site key belongs in browser markup. The secret key must only be sent by your backend to the verification endpoint.

  • Never embed a secret in JavaScript
  • Validate hostname and action
  • Treat every response token as one-time

Use the contract

The checked-in OpenAPI 3.1 document describes every implemented public API path and the stable response shapes.

  • Versioned API paths
  • Closed request schemas
  • Stable error codes
Download OpenAPI YAML