CAPTCHA V2 GUIDE
Let policy add friction only when evidence requires it.
V2 can complete silently, require bounded proof of work, or escalate to an accessible V1 challenge. Every successful path returns the same one-time server response.
Render a form-associated control
The SDK adds a hidden response field, pauses an unverified form submission, and resumes with the original submit button after completion.
<form method="post" action="/login">
<div id="giws-captcha"></div>
<noscript><p>Enable JavaScript to complete verification.</p></noscript>
<button type="submit">Sign in</button>
</form>
<script src="https://captcha.giws.us/sdk/v2/giws-captcha.js"></script>
<script>
giwsCaptcha.ready(() => giwsCaptcha.render('#giws-captcha', {
sitekey: 'YOUR_SITE_KEY',
action: 'login',
appearance: 'checkbox',
}));
</script>Execute programmatically
Use execute for an invisible flow. A direct execution that requires interaction reports interactive-required through the documented challenge path instead of pretending success.
const controller = new AbortController();
const response = await giwsCaptcha.execute('YOUR_SITE_KEY', {
action: 'login',
timeout: 15000,
signal: controller.signal,
});Handle the complete lifecycle
Use reset to cancel work and clear responses, remove to detach a rendered widget, and explicit callbacks or events for failure and expiry.
- giws-captcha-success
- giws-captcha-error
- giws-captcha-expired
- giws-captcha-challenge
Content Security Policy
Proof of work runs in a Web Worker created from a Blob URL. The server still recomputes the SHA-256 proof and bounds difficulty.
- script-src 'self' https://captcha.giws.us
- connect-src 'self' https://captcha.giws.us
- worker-src blob: