Skip to content

reCAPTCHA Validate — Reference

Reference · Advanced · Server Connect

Verify a received reCAPTCHA response with the configured server secret.

Verify a received reCAPTCHA response with the configured server secret.

  • An appropriately configured Server Connect action and isolated test inputs.

Verify a received reCAPTCHA response with the configured server secret.

Setting Meaning
NameIdentifies the validation result in the action scope.
Secret KeyThe server secret paired with the site’s reCAPTCHA integration. It is not the public site key and must not be placed in page code.
MessageThe field-validation message used when verification fails. The default is Recaptcha check failed.

Place the validation step before the protected write. The submitted form must include g-recaptcha-response from the matching client integration. Test a fresh valid response and a missing, expired or reused response; verify that the failure prevents the write and is shown to the user.

This module calls Google’s siteverify endpoint and checks its success result. It does not implement an Enterprise assessment flow or automatically enforce v3 score/action policies. The PHP implementation also disables TLS peer verification in its cURL call; do not assume the two runtimes have identical transport behavior. Follow the current provider requirements and test your deployed integration.

Google’s verification documentation states that a response token expires after two minutes and can be verified once. Generate a fresh response for another attempt. See Google’s server verification guide for the current request and error-code contract.

Place the check or file operation before the work that depends on it, then verify the final HTTP response and any resulting data or file changes.

You can configure this operation and verify both its expected result and its failure boundary.