How to integrate the captcha
Three steps: create a widget, embed the script, verify the token on your server.
Create a widget
Sign up, open the panel and configure the look: colors, opacity, size (by role), pulsation, quality and the caption. The live captcha for testing is there too.
Embed the script
One tag per page. The captcha opens in a frame and calls your handler with the token on solve.
Verify the token
Your site server calls /api/v1/verify with the secret key and gets the verdict.
1. Markup and embedding
<div id="captcha"></div>
<script>
function onCaptchaSolved(token) {
// send the token to your server for verification
fetch('/my-backend/verify', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ token })
});
}
</script>
<script src="http://jkcaptcha.we4.online/js/captcha/widget.js"
data-key='jcv4w_WIDGET_KEY'
data-target="#captcha"
data-callback="onCaptchaSolved"></script>
Attributes: data-key — the public widget key (from the panel), data-target — the container selector, data-callback — the name of the global function that receives the token. If the callback is omitted, a jvc4-solved event with detail.token is dispatched on the container.
2. Server-side token verification
C# / ASP.NET
using var http = new HttpClient();
http.DefaultRequestHeaders.Add("X-Api-Key", "jcv4_YOUR_SECRET_KEY");
var r = await http.GetFromJsonAsync<VerifyResponse>(
"http://jkcaptcha.we4.online/api/v1/verify?token=" + Uri.EscapeDataString(token));
if (r is { valid: true }) { /* human */ }
record VerifyResponse(bool valid);
Node.js
const r = await fetch(
"http://jkcaptcha.we4.online/api/v1/verify?token=" + encodeURIComponent(token),
{ headers: { "X-Api-Key": "jcv4_YOUR_SECRET_KEY" } }
);
const { valid } = await r.json();
if (valid) { /* human */ }
PHP
$ch = curl_init("http://jkcaptcha.we4.online/api/v1/verify?token=" . urlencode($token));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["X-Api-Key: jcv4_YOUR_SECRET_KEY"]);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$res = json_decode(curl_exec($ch), true);
if (!empty($res["valid"])) { /* human */ }
3. Passive check without a captcha
If you do not want to show the captcha to everyone, ask the service for a verdict based on passive page signals:
POST http://jkcaptcha.we4.online/api/v1/risk
X-Api-Key: jcv4_YOUR_SECRET_KEY
{ "webDriver": false, "hw": 8, "screenW": 1920, "lang": "ru", "elapsedMs": 4000, "moves": 120 }
→ { "score": 0, "verdict": "human", "flags": [] }
Verdicts: human (the captcha may be skipped), suspicious, bot. See the API reference for details.
Limits and timings
- Frames: up to 40 requests/sec (the client polls ~30/sec; 204 is returned when nothing changed).
- Input: up to 40/sec; solve attempt (release) — at most once per second.
- Captcha = session: you have 30 to 60 seconds to solve it, then the session ends and the client creates a new one automatically.
- A page keeps the same captcha until it is solved. When the wait timeout expires (300 seconds) the server forcibly closes the page sessions and responds with
410— the client shows “The session was forcibly terminated, please try again” and stops. - The token after solving is valid for 300 seconds.