Captcha providers
A captcha provider makes users solve a captcha at sign-in and before Casdoor sends a verification code, for example at sign-up and on the forgot-password page. Captchas protect the sign-in page against password guessing, and SMS and email providers against bots that request codes.
Supported types
| Type | Service |
|---|---|
Default | The built-in image captcha of Casdoor. See Default captcha |
Cloudflare Turnstile | See Cloudflare Turnstile |
reCAPTCHA, reCAPTCHA v2, reCAPTCHA v3 | Google reCAPTCHA. See reCAPTCHA |
hCaptcha | See hCaptcha |
Aliyun Captcha | See Alibaba Cloud Captcha |
GEETEST | See Geetest |
| Default | Cloudflare Turnstile | reCAPTCHA | hCaptcha | Alibaba Cloud | Geetest |
|---|---|---|---|---|---|
Add a captcha provider
- In the Casdoor admin console, go to Identity > Providers and add a provider.
- Set Category to
Captchaand select the Type. - Fill in the fields of the type, such as the site key and the secret key.
- Click Preview to check the captcha.
- Save the provider.
Add the captcha to an application
-
Open the edit page of the application and add the captcha provider on the Providers tab.
-
Select the Rule that decides when the captcha appears:
Rule The captcha appears NoneNever. The captcha is off DynamicAfter the number of failed sign-ins of the user reaches the Failed signin limit of the application AlwaysAt every sign-in Internet-OnlyFor requests from the public internet, not for requests from private networks 
-
Save the application.
An application can have at most one captcha provider. Casdoor rejects the save if you add a second one. To switch providers, remove the existing one first.
For a captcha provider, the rule None turns the captcha off. For SMS and email providers, the rules have a different meaning. See Provider rules.
To place the captcha in a dialog or directly on the sign-in page, see Change the captcha.