IMPLEMENTED API

Endpoints that exist in the running application.

All public CAPTCHA API routes are stateless at the HTTP boundary and rate limited. Browser challenge routes require a registered origin; siteverify is server-only.

Maintained documentation3 sectionsAPI contract

V1 challenge API

Create, render, complete, or regenerate an explicit challenge.

  • POST /api/v1/challenges — 60/minute
  • GET /api/v1/challenges/{challenge}/asset — 120/minute
  • POST /api/v1/challenges/{challenge}/verify — 60/minute
  • POST /api/v1/challenges/{challenge}/regenerate — 30/minute

V2 and V3 issue APIs

V2 produces a managed outcome; V3 produces an opaque score token without returning the score to the browser.

  • POST /api/v2/challenges — 60/minute
  • POST /api/v2/challenges/{challenge}/verify — 60/minute
  • POST /api/v3/challenges — 60/minute

Server verification

Both paths invoke the same one-time token verifier. The compatibility alias is recommended for new integrations.

  • POST /api/siteverify — 120/minute
  • POST /api/v1/siteverify — 120/minute
  • JSON or form-encoded request
Download the complete OpenAPI contract