Skip to main content

Keys

Create an account or sign in, then add a site under Sites & keys. Verify the domain using the DNS or file instructions on its panel. Copy the public site key for your page and issue a secret key for your backend. Copy the secret when it appears; it is shown only once.

Collector

result.requestId is a 32-character hex string. Send it to your server unchanged.

Read the verdict

ok: true means collection completed. Read verdict.verdict on your server to learn the result. The signup rules guide covers attempt binding and account checks; the verdict schema describes the response fields.

Challenge widget

For a complete form and backend, follow the ten-minute plain HTML guide, Next.js guide, or SvelteKit guide. Node, Python and PHP clients cover each server API.
In its default mode, the widget returns a token for an uncontradicted probe. A contradicted or refused probe requires a phone challenge first. The token appears in the form’s hidden heretic-response field. Verify the token on your server:
Require success === true before creating the account. Set expected_hostname, expected_action, and expected_cdata from your backend’s own session. Use policy: "challenge" if a ceremony is required. The response includes the original verdict and request_id, plus challenge_id and devices after a phone challenge. Fields and error codes are on the siteverify page.