SUPPORT POLICY

Predictable contracts, explicit retirement windows.

This policy applies to public GIWS CAPTCHA HTTP contracts and browser assets. V1, V2, and V3 identify distinct CAPTCHA experiences; they are not a sequence in which a higher number silently replaces a lower one.

Maintained documentation5 sectionsAPI contract

Current contract status

The checked-in OpenAPI contract is currently 0.x preview. Its info.version tracks the whole documented schema, while public path families and browser asset paths identify the integration surface.

  • OpenAPI is the source of truth for public HTTP shapes
  • No dedicated server or framework package is supported until it is listed in the changelog
  • Preview changes are always recorded and must include migration guidance when client work is required

Compatible changes

A contract release may add an endpoint, an optional request member, or a response member without moving an existing public path. Integrations must ignore unknown response members and handle unknown error codes as a failed verification.

  • No required request member is added in place
  • Existing field meaning and type remain stable
  • Security failures remain fail closed

Breaking-change process

A change that removes or renames a path or field, changes a type or meaning, or adds a required input needs a new contract boundary and a migration guide. After API 1.0 GA, a superseded public major remains supported for at least 12 months after its successor reaches GA.

  • Record the change in the public changelog
  • Publish migration and rollback instructions
  • Announce an ordinary final sunset at least 90 days in advance
  • Do not repurpose an existing SDK major path

Deprecation and security exceptions

During an announced retirement, documentation identifies the replacement and final support date. A confirmed security threat may require a faster restriction or removal when continued operation would expose customers; notice and remediation guidance are published as soon as disclosure is safe.

  • No silent ordinary retirement
  • Security controls are never weakened for compatibility
  • Use request_id for support correlation and never submit secrets or response tokens

Package support

Composer, npm, CMS, and framework packages are unsupported until their names and compatibility matrices appear in this documentation. Once published, each supported package major follows the same 12-month minimum window after a successor major reaches GA.

Review the current changelog