HCAPTCHA MIGRATION

Preserve accessible completion while changing providers.

Choose V1 for an explicit challenge or V2 for managed step-up. GIWS keys, response fields, challenge providers, and verification results are independent.

Maintained documentation3 sectionsAPI contract

Choose V1 or V2

V1 always presents a challenge. V2 can complete low-risk requests before escalating to proof of work or an accessible V1 provider.

  • Explicit interaction → V1
  • Managed escalation → V2
  • Audio and accessible text remain available

Replace markup and verification

Remove provider-specific markup only after the GIWS client and backend path work together on a registered staging hostname.

  • Use giws-captcha-response
  • POST it to /api/siteverify from the backend
  • Keep the new secret server-side
  • Reject mismatched action and hostname

Test the complete journey

Exercise keyboard use, locale, audio, accessible text, expiry, regeneration, duplicate submission, and server rejection before cutover.

  • No inaccessible fallback removal
  • No shared provider secrets
  • Explicit rollback plan
Open the V1 guide