跳到主内容

Captcha providers

A captcha provider makes users solve a captcha at sign-in and before Casdoor sends a verification code, for example at sign-up and on the forgot-password page. Captchas protect the sign-in page against password guessing, and SMS and email providers against bots that request codes.

Supported types​

TypeService
默认The built-in image captcha of Casdoor. See Default captcha
Cloudflare 旋转门See Cloudflare Turnstile
reCAPTCHA, reCAPTCHA v2, reCAPTCHA v3Google reCAPTCHA. See reCAPTCHA
hCaptchaSee hCaptcha
Aliyun CaptchaSee Alibaba Cloud Captcha
GEETESTSee Geetest
DefaultCloudflare TurnstilereCAPTCHAhCaptcha阿里云Geetest

添加验证码提供商​

  1. In the Casdoor admin console, go to Identity > Providers and add a provider.
  2. Set Category to Captcha and select the Type.
  3. Fill in the fields of the type, such as the site key and the secret key.
  4. Click Preview to check the captcha.
  5. Save the provider.

Add the captcha to an application​

  1. Open the edit page of the application and add the captcha provider on the Providers tab.

  2. Select the Rule that decides when the captcha appears:

    RuleThe captcha appears
    NoneNever. The captcha is off
    DynamicAfter the number of failed sign-ins of the user reaches the Failed signin limit of the application
    AlwaysAt every sign-in
    Internet-OnlyFor requests from the public internet, not for requests from private networks

    Captcha provider with its rule in the application

  3. Save the application.

注意事项

An application can have at most one captcha provider. Casdoor rejects the save if you add a second one. To switch providers, remove the existing one first.

备注

For a captcha provider, the rule None turns the captcha off. For SMS and email providers, the rules have a different meaning. See Provider rules.

To place the captcha in a dialog or directly on the sign-in page, see Change the captcha.

See also​