Skip to content
FormSubmit

Protection

Captcha

Add Google reCAPTCHA v2/v3, hCaptcha or Cloudflare Turnstile to your forms with your own keys.

FormSubmit supports four captcha providers. You bring your own site key and secret; we verify the token server-side on every submission. Secrets are encrypted at rest (AES-256-GCM) and never shown again in full.

ProviderToken fieldNotes
reCAPTCHA v2 (checkbox)g-recaptcha-responseVisible challenge
reCAPTCHA v3g-recaptcha-responseInvisible; set a minimum score (default 0.5)
hCaptchah-captcha-responseVisible challenge
Cloudflare Turnstilecf-turnstile-responseUsually invisible, free

Setup

  1. Create a site in your provider's console and add your domain(s).
  2. In FormSubmit, open Settings → Captcha, choose the provider, paste the site key and secret, and save.
  3. Add the provider's widget to your form, as below.

Once enabled, submissions without a valid token are rejected with captcha_failed.

Cloudflare Turnstile

turnstile.html
<script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async defer></script>
<form action="https://formsubmit.app/f/YOUR_FORM_ID" method="POST">
  <input type="email" name="email" required>
  <div class="cf-turnstile" data-sitekey="YOUR_SITE_KEY"></div>
  <button type="submit">Send</button>
</form>

hCaptcha

hcaptcha.html
<script src="https://js.hcaptcha.com/1/api.js" async defer></script>
<div class="h-captcha" data-sitekey="YOUR_SITE_KEY"></div>

reCAPTCHA v2

recaptcha-v2.html
<script src="https://www.google.com/recaptcha/api.js" async defer></script>
<div class="g-recaptcha" data-sitekey="YOUR_SITE_KEY"></div>

reCAPTCHA v3

v3 has no widget; request a token on submit and add it to the form data:

recaptcha-v3.html
<script src="https://www.google.com/recaptcha/api.js?render=YOUR_SITE_KEY"></script>
<script>
  document.querySelector("#contact").addEventListener("submit", function (e) {
    e.preventDefault();
    const form = this;
    grecaptcha.ready(function () {
      grecaptcha.execute("YOUR_SITE_KEY", { action: "submit" }).then(function (token) {
        let input = form.querySelector('[name="g-recaptcha-response"]');
        if (!input) {
          input = document.createElement("input");
          input.type = "hidden";
          input.name = "g-recaptcha-response";
          form.appendChild(input);
        }
        input.value = token;
        form.submit();
      });
    });
  });
</script>

Tips

  • Turnstile and reCAPTCHA v3 are invisible to most visitors — the best choice for conversion.
  • Keep the honeypot enabled alongside a captcha; it costs nothing.
  • If submissions suddenly fail with captcha_failed, check that your production domain is registered with the provider.