RECAPTCHA MIGRATION
Replace both browser and server contracts deliberately.
reCAPTCHA credentials, tokens, field names, and response shapes are not compatible with GIWS CAPTCHA. Provision a separate GIWS site and keep rollback explicit.
Map the interaction
Select the GIWS version that matches the user experience and enforcement model you actually need.
- Visible challenge → V1
- Checkbox or invisible managed flow → V2
- Action score → V3
Replace integration boundaries
Change the browser loader, public key, submitted response name, backend endpoint, and secret as one reviewed change.
- Load only one GIWS SDK version per page
- POST the GIWS response to /api/siteverify
- Validate hostname, action, and decision
Run a reversible rollout
Use separate staging credentials first. During a controlled production comparison, keep provider results isolated and never reuse one provider token with another endpoint.
- Record pass and challenge rates without raw tokens
- Define a rollback checkpoint
- Remove old scripts, secrets, and CSP origins after cutover