CAPTCHA V3 GUIDE
Keep scoring invisible and enforcement on the backend.
V3 returns only an opaque response to the browser. Your server receives the verified score, risk level, decision, reasons, and immutable model and policy versions.
Execute for one registered action
Load one SDK version on the page and execute close to the protected submission so the short-lived response is verified promptly.
<script src="https://captcha.giws.us/sdk/v3/giws-captcha.js" defer></script>
<script>
giwsCaptcha.ready(async () => {
const response = await giwsCaptcha.execute('YOUR_SITE_KEY', {
action: 'checkout',
timeout: 15000,
});
await submitOrder({ captchaResponse: response });
});
</script>Enforce the verified context
success=true proves authenticity and consumes the token, but your application must still compare action and hostname and enforce the returned decision or approved score threshold.
- Never accept a browser-provided score
- Reject an unexpected action or hostname
- Use action-specific policy
- Log request_id instead of credentials
Understand session context
The SDK keeps an opaque, short-lived session token in tab-scoped sessionStorage when available. It is not a verification credential and missing storage begins a neutral session.
- No durable browser identifier
- No cookie requirement
- Origin, site, and action bound
Handle failure safely
Reset cancels active work and clears the local response. Timeouts, missing risk configuration, or unavailable security state must not authorize the protected action.
- Use error-callback for visible recovery
- Request a fresh response after expiry
- Fail closed on verification errors