Configure CAPTCHA
Use CAPTCHA to reduce automated registrations and large volumes of authentication requests. Enable it separately for login, signup and password recovery.
Before you begin
- Required permission: administrator
- Available only with built-in login authentication.
- Prepare a site key and secret key for Google reCAPTCHA v2 checkbox or Cloudflare Turnstile. reCAPTCHA v3 keys are unsupported.
- Add the hostname used to access your space to the key's allowed domains.
Configure keys and target screens
- Select
User Management>Account & Security. - Expand
Robot check (CAPTCHA). - Select
Google reCAPTCHAorCloudflare Turnstileas the provider. - For reCAPTCHA, check the script domain. Select
www.recaptcha.netifwww.google.comis inaccessible. - Enter the site key and secret key.
- Enable the screens where verification is required.

| Screen | When verification occurs |
|---|---|
| Login | On every login. |
| Signup | When requesting signup; with email verification, when requesting the verification email. |
| Password recovery | When requesting an email with a verification code. |
Verify and apply new keys
- Open the verification widget under the key verification section.
- Pass the displayed challenge.
- Check the success message and select
Update. - Check the provider and enabled screens in the collapsed summary.
New keys must pass widget verification before being applied to a target screen. Repeat verification if the token expires or is rejected. For site key errors, check allowed domains. For secret key errors, check that the secret matches the site key.
Saved secret keys are not displayed again. Leave the field empty to keep the saved secret for the same provider; enter a value only to replace it.
Stop requiring verification
- Disable all target screens and save to retain the keys without requiring verification. No widget verification is needed when no screens are enabled.
- Select the disabled provider option and save to remove the registered keys as well.