FormSubmit supports four captcha providers. You bring your own site key and secret; we verify the token server-side on every submission. Secrets are encrypted at rest (AES-256-GCM) and never shown again in full.
| Provider | Token field | Notes |
|---|---|---|
| reCAPTCHA v2 (checkbox) | g-recaptcha-response | Visible challenge |
| reCAPTCHA v3 | g-recaptcha-response | Invisible; set a minimum score (default 0.5) |
| hCaptcha | h-captcha-response | Visible challenge |
| Cloudflare Turnstile | cf-turnstile-response | Usually invisible, free |
Setup
- Create a site in your provider's console and add your domain(s).
- In FormSubmit, open Settings → Captcha, choose the provider, paste the site key and secret, and save.
- Add the provider's widget to your form, as below.
Once enabled, submissions without a valid token are rejected with captcha_failed.
Cloudflare Turnstile
turnstile.html
<script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async defer></script>
<form action="https://formsubmit.app/f/YOUR_FORM_ID" method="POST">
<input type="email" name="email" required>
<div class="cf-turnstile" data-sitekey="YOUR_SITE_KEY"></div>
<button type="submit">Send</button>
</form>hCaptcha
hcaptcha.html
<script src="https://js.hcaptcha.com/1/api.js" async defer></script>
<div class="h-captcha" data-sitekey="YOUR_SITE_KEY"></div>reCAPTCHA v2
recaptcha-v2.html
<script src="https://www.google.com/recaptcha/api.js" async defer></script>
<div class="g-recaptcha" data-sitekey="YOUR_SITE_KEY"></div>reCAPTCHA v3
v3 has no widget; request a token on submit and add it to the form data:
recaptcha-v3.html
<script src="https://www.google.com/recaptcha/api.js?render=YOUR_SITE_KEY"></script>
<script>
document.querySelector("#contact").addEventListener("submit", function (e) {
e.preventDefault();
const form = this;
grecaptcha.ready(function () {
grecaptcha.execute("YOUR_SITE_KEY", { action: "submit" }).then(function (token) {
let input = form.querySelector('[name="g-recaptcha-response"]');
if (!input) {
input = document.createElement("input");
input.type = "hidden";
input.name = "g-recaptcha-response";
form.appendChild(input);
}
input.value = token;
form.submit();
});
});
});
</script>Tips
- Turnstile and reCAPTCHA v3 are invisible to most visitors — the best choice for conversion.
- Keep the honeypot enabled alongside a captcha; it costs nothing.
- If submissions suddenly fail with
captcha_failed, check that your production domain is registered with the provider.