Use evilCAPTCHA on your site

Keep chatbots out of your forms. No sign-up, no keys: two steps and you are done.

1. Add the snippet to your form

Paste it inside your <form>, where the captcha should appear. Once solved, your form sends a pass token in the field evil-captcha-response.

<div class="evil-captcha">
  <a href="https://evil-captcha.org/widget">Solve the captcha</a>
  <label>and paste your pass token: <input name="evil-captcha-response" required></label>
</div>
<script src="https://evil-captcha.org/embed.js" async></script>

2. Check the pass token on your server

Before you accept the form, send the pass token to us. Accept it only if the answer is "success": true and "site" is your own origin, so tokens solved on other sites are refused.

curl -d "response=$TOKEN" https://evil-captcha.org/siteverify
{"success": true, "site": "https://your-site.example"}

Good to know