IMPLEMENTED API
Endpoints that exist in the running application.
All public CAPTCHA API routes are stateless at the HTTP boundary and rate limited. Browser challenge routes require a registered origin; siteverify is server-only.
V1 challenge API
Create, render, complete, or regenerate an explicit challenge.
- POST /api/v1/challenges — 60/minute
- GET /api/v1/challenges/{challenge}/asset — 120/minute
- POST /api/v1/challenges/{challenge}/verify — 60/minute
- POST /api/v1/challenges/{challenge}/regenerate — 30/minute
V2 and V3 issue APIs
V2 produces a managed outcome; V3 produces an opaque score token without returning the score to the browser.
- POST /api/v2/challenges — 60/minute
- POST /api/v2/challenges/{challenge}/verify — 60/minute
- POST /api/v3/challenges — 60/minute
Server verification
Both paths invoke the same one-time token verifier. The compatibility alias is recommended for new integrations.
- POST /api/siteverify — 120/minute
- POST /api/v1/siteverify — 120/minute
- JSON or form-encoded request