CAPTCHA V2 GUIDE

Let policy add friction only when evidence requires it.

V2 can complete silently, require bounded proof of work, or escalate to an accessible V1 challenge. Every successful path returns the same one-time server response.

Maintained documentation4 sectionsAPI contract

Render a form-associated control

The SDK adds a hidden response field, pauses an unverified form submission, and resumes with the original submit button after completion.

html
<form method="post" action="/login">
    <div id="giws-captcha"></div>
    <noscript><p>Enable JavaScript to complete verification.</p></noscript>
    <button type="submit">Sign in</button>
</form>
<script src="https://captcha.giws.us/sdk/v2/giws-captcha.js"></script>
<script>
giwsCaptcha.ready(() => giwsCaptcha.render('#giws-captcha', {
    sitekey: 'YOUR_SITE_KEY',
    action: 'login',
    appearance: 'checkbox',
}));
</script>

Execute programmatically

Use execute for an invisible flow. A direct execution that requires interaction reports interactive-required through the documented challenge path instead of pretending success.

javascript
const controller = new AbortController();
const response = await giwsCaptcha.execute('YOUR_SITE_KEY', {
    action: 'login',
    timeout: 15000,
    signal: controller.signal,
});

Handle the complete lifecycle

Use reset to cancel work and clear responses, remove to detach a rendered widget, and explicit callbacks or events for failure and expiry.

  • giws-captcha-success
  • giws-captcha-error
  • giws-captcha-expired
  • giws-captcha-challenge

Content Security Policy

Proof of work runs in a Web Worker created from a Blob URL. The server still recomputes the SHA-256 proof and bounds difficulty.

  • script-src 'self' https://captcha.giws.us
  • connect-src 'self' https://captcha.giws.us
  • worker-src blob:
Verify the final response