Captcha OCR

A captcha answer is not a password

2026-01-16 · Captchas

The text matches one image for a minute or two. The API key is the secret you must keep.

The portal checks the text once, against the image it just drew. After that the answer is useless. Do not store captcha images or answers as if they were credentials.

Store the task id, the time, and whether you were charged. The id is what you send to POST /v1/report if the portal rejects a reliable reading.

The API key is the credential. The dashboard shows it once. Only a SHA-256 hash is stored. Send it as a bearer token or X-API-Key. Keep it in an environment variable named CAPTCHA_API_KEY, not in the app binary and not in git.

A revoked key stops working within about 30 seconds, because valid keys are cached that long and invalid keys are not cached.

Ready to call it? Start with the quickstart, the API guide, or pricing.

More in Captchas