CAPTCHA V3 GUIDE

Keep scoring invisible and enforcement on the backend.

V3 returns only an opaque response to the browser. Your server receives the verified score, risk level, decision, reasons, and immutable model and policy versions.

Maintained documentation4 sectionsAPI contract

Execute for one registered action

Load one SDK version on the page and execute close to the protected submission so the short-lived response is verified promptly.

html
<script src="https://captcha.giws.us/sdk/v3/giws-captcha.js" defer></script>
<script>
giwsCaptcha.ready(async () => {
    const response = await giwsCaptcha.execute('YOUR_SITE_KEY', {
        action: 'checkout',
        timeout: 15000,
    });

    await submitOrder({ captchaResponse: response });
});
</script>

Enforce the verified context

success=true proves authenticity and consumes the token, but your application must still compare action and hostname and enforce the returned decision or approved score threshold.

  • Never accept a browser-provided score
  • Reject an unexpected action or hostname
  • Use action-specific policy
  • Log request_id instead of credentials

Understand session context

The SDK keeps an opaque, short-lived session token in tab-scoped sessionStorage when available. It is not a verification credential and missing storage begins a neutral session.

  • No durable browser identifier
  • No cookie requirement
  • Origin, site, and action bound

Handle failure safely

Reset cancels active work and clears the local response. Timeouts, missing risk configuration, or unavailable security state must not authorize the protected action.

  • Use error-callback for visible recovery
  • Request a fresh response after expiry
  • Fail closed on verification errors
Apply server-side checks