CAPTCHA V1 GUIDE
Add an explicit challenge with accessible alternatives.
V1 is intended for flows that require visible human interaction. The server controls the provider policy and successful completion returns a one-time response token.
Embed the form-associated widget
Place the custom element inside the protected form. The widget pauses native submission until verification succeeds and contributes the response using its name attribute.
<form method="post" action="/contact">
<input name="email" type="email" required>
<giws-captcha
sitekey="YOUR_SITE_KEY"
action="contact"
name="giws-captcha-response"
lang="en"
></giws-captcha>
<button type="submit">Send</button>
</form>
<script src="https://captcha.giws.us/widget/v1.js" async defer></script>Respect provider and accessibility policy
The site setting selects image or puzzle as the default visual provider. Users can still move to audio or accessible text without replacing the challenge envelope.
- Use lang="ar" for Arabic and RTL rendering
- Keep native focus indicators visible
- Do not hide audio or accessible-text alternatives
- Treat the provider attribute as a request, not an authorization decision
Handle completion and verify
Traditional forms can use the submitted field. SPA flows may listen for giws-captcha-success or configure a restricted global callback name.
document.querySelector('giws-captcha').addEventListener('giws-captcha-success', (event) => {
const response = event.target.value;
// Send response to your backend, then call POST /api/siteverify there.
});Content Security Policy
A strict host policy must allow the CAPTCHA origin for the loader and API, plus its protected image and audio assets.
- script-src: https://captcha.giws.us
- connect-src: https://captcha.giws.us
- img-src: https://captcha.giws.us
- media-src: https://captcha.giws.us