API REFERENCE · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP

Get captcha settings

GET /api/v1/sites/captcha

GEThttps://securessmtp.com/api/v1/sites/captcha

Returns the captcha the site uses and what you need to show its widget on your form. Secret keys are never returned.

Headers

x-securessmtp-api-keystringrequired
The site’s API key (qcs_live_…). x-securesmtp-api-key and x-qcs-api-key are accepted too. See Sites and API keys.

Parameters

None.

Request

curl https://securessmtp.com/api/v1/sites/captcha \
  -H "x-securessmtp-api-key: $SECURESSMTP_API_KEY"

Response

200
{
  "ok": true,
  "provider": "shared",
  "site_key": "0x4AAAAAAA...",
  "widget_js": "https://challenges.cloudflare.com/turnstile/v0/api.js",
  "widget_class": "cf-turnstile",
  "response_field": "cf-turnstile-response"
}
Response fields
okbooleanrequired
true.
provider'shared' | 'turnstile' | 'hcaptcha' | 'recaptcha' | 'recaptcha_v3' | 'none'required
The site’s captcha. shared is our own Cloudflare Turnstile key (the default). none means no captcha.
site_keystring | nullrequired
The public key to render the widget with. null for none.
widget_jsstring | nullrequired
The script to load on the page.
widget_classstring | nullrequired
The class of the element the widget mounts on (with data-sitekey set to site_key).
response_fieldstring | nullrequired
The form field the widget’s token is in. Send its value as captcha_token to POST /forms/submit.

Values by provider

providerwidget_jswidget_classresponse_field
sharedhttps://challenges.cloudflare.com/turnstile/v0/api.jscf-turnstilecf-turnstile-response
turnstilehttps://challenges.cloudflare.com/turnstile/v0/api.jscf-turnstilecf-turnstile-response
hcaptchahttps://js.hcaptcha.com/1/api.jsh-captchah-captcha-response
recaptchahttps://www.google.com/recaptcha/api.jsg-recaptchag-recaptcha-response
recaptcha_v3https://www.google.com/recaptcha/api.jsg-recaptcha-v3g-recaptcha-response
nonenullnullnull

For shared, site_key is our Turnstile key. For the other providers it is the key you saved with POST /sites/captcha.

Errors

Errors have an error field and no ok field.

HTTPValueMeaningWhat to do
401missing_api_keyNo key header was sent.Send the key in the x-securessmtp-api-key header.
401invalid_api_keyNo site has this key. Keys stop working as soon as they are rotated.Copy the current key from the dashboard, or rotate it to get a new one.
403site_disabledThe site is disabled.Check GET /blocks/status. See Blocks.

See Spam protection.