DEVELOPER PLATFORM

A short path from site key to verified request.

Register a site, load the SDK for your CAPTCHA version, receive a token, and verify that token from a trusted backend.

Developer experience

Load the versioned client

Each CAPTCHA version has a stable browser entry point so integrations can upgrade intentionally.

  • Async-compatible loader
  • CSP-aware assets
  • Origin validation
Implementation
<script src="https://captcha.giws.us/sdk/v2/giws-captcha.js" async></script>

Developer experience

Verify on your backend

Presented tokens are only evidence after the server verifies them with the site secret.

  • Secret stays server-side
  • Single-use token
  • Hostname and action checks
Implementation
POST /api/siteverify
secret=YOUR_SECRET&response=TOKEN

Developer experience

Handle stable outcomes

Bounded error codes let applications distinguish invalid, expired, replayed, mismatched, and rate-limited requests.

  • invalid-token
  • expired-token
  • replayed-token

Build a safer user journey.

Register a hostname and choose the amount of verification friction each action deserves.

Create account