QUICKSTART

From site key to verified action.

This V3 example is the shortest implemented path. Use V1 or V2 when your policy requires an explicit or managed challenge.

Maintained documentation3 sectionsAPI contract

1. Register the boundary

Create a site in the customer dashboard, register the exact production hostname, and create the action your backend will enforce.

  • Copy the public key into the browser
  • Store the displayed-once secret in a secret manager
  • Use a stable action such as login or register

2. Execute in the browser

The SDK derives the browser origin and returns an opaque response. Score and decision remain server-side.

html
<script src="https://captcha.giws.us/sdk/v3/giws-captcha.js" defer></script>
<script>
giwsCaptcha.ready(async () => {
    const response = await giwsCaptcha.execute('YOUR_SITE_KEY', {
        action: 'login',
        timeout: 15000,
    });

    document.querySelector('[name="giws-captcha-response"]').value = response;
});
</script>

3. Verify before the protected action

Send the browser response to your backend, then call siteverify with the secret, expected public key, and expected action.

  • Reject success=false
  • Require the expected hostname and action
  • Enforce the returned decision or score policy
Choose a server example