You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

咨询:无需引用外部API集成Google reCAPTCHA的可行方案

How to Integrate Google reCAPTCHA "I'm not a robot" Checkbox with Local JS Only

Great question—this is a common pain point for teams with strict content security policies. Let’s break down the compliant options you have, since Google doesn’t officially provide a downloadable reCAPTCHA package:

Option 1: Proxy Google’s reCAPTCHA Script to Your Server

This is the closest approach to the native reCAPTCHA experience, as you’re using Google’s official code but hosting it on your own server. Here’s how to set it up:

  • Regularly fetch the content of Google’s official https://www.google.com/recaptcha/api.js and save it to your server’s static assets (e.g., /js/recaptcha-proxy.js)
  • Important: The main api.js dynamically loads additional dependent scripts (like /recaptcha/api2/anchor or /recaptcha/api2/bundle). You’ll need to either proxy these paths to Google’s corresponding resources or sync these secondary scripts to your server as well
  • Set up an automated sync (e.g., a cron job) to update your local script copies periodically—Google updates reCAPTCHA’s code regularly, so outdated versions will stop working
  • Reference the local script in your page instead of the external one: <script src="/js/recaptcha-proxy.js" async defer></script>
  • Critical reminder: Never modify Google’s script content. This violates their service terms and will almost certainly break the verification flow. Keep the code exactly as you fetch it.

Option 2: Custom Frontend + Server-Side reCAPTCHA API Calls

If proxying scripts doesn’t fit your needs, you can build a custom frontend interaction and handle all verification logic through your backend:

  • Render your own "I’m not a robot" checkbox (you can mimic Google’s styling for familiarity)
  • When the user clicks the checkbox, your frontend calls your backend API
  • Your backend initiates a verification challenge via Google’s reCAPTCHA API (either v2’s siteverify endpoint or the Enterprise API)
  • Pass the challenge details back to the frontend, let the user complete the verification (e.g., image selection), then send the user’s response back to your backend
  • Your backend calls Google’s API again to validate the response, then returns the result to the frontend
  • Note: This method loses Google’s behavioral analysis data (like mouse movement or click patterns), which may increase false positive rates, but it fully complies with your requirement to host all JS locally.

Option 3: reCAPTCHA v3 with Script Proxying

If you don’t want a user-facing checkbox, reCAPTCHA v3’s invisible scoring system is an alternative:

  • Follow the same proxy steps as Option 1 for Google’s v3 script
  • Once the local script loads, reCAPTCHA runs in the background to generate a trust score for the user
  • Pass this score to your backend, which then validates it via Google’s API
  • This method requires no user interaction, but you still need to proxy the script to your server to meet your JS hosting rules.

Key Compliance & Security Tips

  • Always adhere to Google’s reCAPTCHA service terms: Don’t hide the reCAPTCHA branding (for v2), don’t bypass verification steps, and don’t alter the script code
  • Never expose your reCAPTCHA secret key in frontend code—all verification calls to Google must happen from your backend
  • If proxying scripts, test thoroughly to ensure all dependent resources (like iframes or images) load correctly; broken resources will cause verification failures

内容的提问来源于stack exchange,提问作者Matthew Rhoden

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:06:31