HCAPTCHA MIGRATION
Preserve accessible completion while changing providers.
Choose V1 for an explicit challenge or V2 for managed step-up. GIWS keys, response fields, challenge providers, and verification results are independent.
Choose V1 or V2
V1 always presents a challenge. V2 can complete low-risk requests before escalating to proof of work or an accessible V1 provider.
- Explicit interaction → V1
- Managed escalation → V2
- Audio and accessible text remain available
Replace markup and verification
Remove provider-specific markup only after the GIWS client and backend path work together on a registered staging hostname.
- Use giws-captcha-response
- POST it to /api/siteverify from the backend
- Keep the new secret server-side
- Reject mismatched action and hostname
Test the complete journey
Exercise keyboard use, locale, audio, accessible text, expiry, regeneration, duplicate submission, and server rejection before cutover.
- No inaccessible fallback removal
- No shared provider secrets
- Explicit rollback plan