API REFERENCE · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP
Get captcha settings
GET /api/v1/sites/captcha
GEThttps://securessmtp.com/api/v1/sites/captcha
Returns the captcha the site uses and what you need to show its widget on your form. Secret keys are never returned.
Headers
- x-securessmtp-api-keystringrequired
- The site’s API key (
qcs_live_…).x-securesmtp-api-keyandx-qcs-api-keyare accepted too. See Sites and API keys.
Parameters
None.
Request
curl https://securessmtp.com/api/v1/sites/captcha \
-H "x-securessmtp-api-key: $SECURESSMTP_API_KEY"Response
200
{
"ok": true,
"provider": "shared",
"site_key": "0x4AAAAAAA...",
"widget_js": "https://challenges.cloudflare.com/turnstile/v0/api.js",
"widget_class": "cf-turnstile",
"response_field": "cf-turnstile-response"
}Response fields
- okbooleanrequired
true.- provider'shared' | 'turnstile' | 'hcaptcha' | 'recaptcha' | 'recaptcha_v3' | 'none'required
- The site’s captcha.
sharedis our own Cloudflare Turnstile key (the default).nonemeans no captcha. - site_keystring | nullrequired
- The public key to render the widget with.
nullfornone. - widget_jsstring | nullrequired
- The script to load on the page.
- widget_classstring | nullrequired
- The class of the element the widget mounts on (with
data-sitekeyset tosite_key). - response_fieldstring | nullrequired
- The form field the widget’s token is in. Send its value as
captcha_tokento POST /forms/submit.
Values by provider
| provider | widget_js | widget_class | response_field |
|---|---|---|---|
shared | https://challenges.cloudflare.com/turnstile/v0/api.js | cf-turnstile | cf-turnstile-response |
turnstile | https://challenges.cloudflare.com/turnstile/v0/api.js | cf-turnstile | cf-turnstile-response |
hcaptcha | https://js.hcaptcha.com/1/api.js | h-captcha | h-captcha-response |
recaptcha | https://www.google.com/recaptcha/api.js | g-recaptcha | g-recaptcha-response |
recaptcha_v3 | https://www.google.com/recaptcha/api.js | g-recaptcha-v3 | g-recaptcha-response |
none | null | null | null |
For shared, site_key is our Turnstile key. For the other providers it is the key you saved with POST /sites/captcha.
Errors
Errors have an error field and no ok field.
| HTTP | Value | Meaning | What to do |
|---|---|---|---|
| 401 | missing_api_key | No key header was sent. | Send the key in the x-securessmtp-api-key header. |
| 401 | invalid_api_key | No site has this key. Keys stop working as soon as they are rotated. | Copy the current key from the dashboard, or rotate it to get a new one. |
| 403 | site_disabled | The site is disabled. | Check GET /blocks/status. See Blocks. |
See Spam protection.