Validate a supplied reCAPTCHA token

Ask Wallkit to verify a client token for the selected resource. The result describes this validation call; it does not create identity, grant content access or certify every anti-abuse condition.

TaskOperationAccess
Verify a supplied client tokenValidateGuest action with required resource context.

Example clients and synthetic values follow response conventions.

Verify the resource’s supplied token

POST /api/v1/integrations/google-recaptcha/validate

Send an existing client token for provider verification. Google receives the token and configured secret; Wallkit logs the provider answer and exception details.

Before you call

Guest ACL permits this action, but a valid resource header is required. No member token is required. The selected resource must have google_recaptcha.active enabled. Resource-specific public/secret keys fall back to server configuration when empty; this operation neither supplies a secret nor acquires a client token. Use the token from your already configured client integration.

Wallkit accepts Google’s success value when it evaluates to true in a boolean check. It has no active score threshold, expected action, hostname or independent expiry check. Do not interpret status:true as proof of those conditions. Provider compatibility and malformed provider-response behavior are unspecified.

Request

JSON body in examples. Nonempty posted form fields take precedence over JSON; choose one representation. The body is cast to an object, so an empty/malformed body is not a reliable separate empty-body error: with active configuration, missing recaptcha_token reaches the missing-token branch.

NameLocationType / requirementMeaning
resourceheaderrequired existing public keySelects resource and its reCAPTCHA configuration; see transport.
recaptcha_tokenJSON / formrequired supplied string; missing or null rejectedSanitized as string before forwarding. Empty string is not locally rejected as missing; it reaches provider verification. No local token length/format guarantee.

Result

HTTP 200 JSON when the provider success value evaluates to true in a boolean check. The provider object is not forwarded.

FieldType / presenceMeaning
statusboolean true; successful resultWallkit accepted this provider verification answer under its success check.
errorstring; handled failureerror_validate_recaptcha for caught action exceptions; shared resource errors differ.
error_descriptionstring; handled failureException message; provider-false result says Recaptcha is not valid.
req_guidstring; errorRequest correlation value; common optional metadata follows response conventions.

Example: Interpret an accepted provider answer

The synthetic token marks an already supplied client value; it is not a usable token. In this scenario Google’s success value evaluates to true and Wallkit accepts it.

curl -X POST "${WALLKIT_API_BASE}/api/v1/integrations/google-recaptcha/validate" \
  -H "Content-Type: application/json" \
  -H "resource: ${RESOURCE_KEY}" \
  --data-raw '{"recaptcha_token": "SYNTHETIC_RECAPTCHA_TOKEN"}'
const response = await fetch(`${process.env.WALLKIT_API_BASE}/api/v1/integrations/google-recaptcha/validate`, {
  method: "POST",
  headers: { "Content-Type": "application/json", "resource": process.env.RESOURCE_KEY },
  body: JSON.stringify({"recaptcha_token": "SYNTHETIC_RECAPTCHA_TOKEN"})
});
console.log(response.status, await response.json());
import os, json
from urllib.request import Request, urlopen
from urllib.error import HTTPError

body = {'recaptcha_token': 'SYNTHETIC_RECAPTCHA_TOKEN'}
request = Request(os.environ["WALLKIT_API_BASE"] + "/api/v1/integrations/google-recaptcha/validate",
    data=json.dumps(body).encode("utf-8"),
    headers={"Content-Type": "application/json", "resource": os.environ["RESOURCE_KEY"]}, method="POST")
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

Synthetic HTTP 200 excerpt:

{
  "status": true
}

Continue only the task whose requirements your application has actually checked; this response carries no user or entitlement.

Consequential alternate

When the provider answer is an array with success false/missing, HTTP 409 excerpt (other response metadata omitted):

{
  "error": "error_validate_recaptcha",
  "error_description": "Recaptcha is not valid"
}

The call did not pass Wallkit validation. Malformed/null provider JSON can fail outside the caught Exception path; no stable JSON/status is promised for that case.

Recovery

HTTP statusAPI code / shapeCauseNext action
404resource_not_existsMissing/unresolved resource key.Check the supplied resource public key with integration owner.
422error_validate_recaptcha; Google Recaptcha is not enabled on current resourceResource configuration inactive.Ask integration owner to inspect the selected resource’s configuration.
422error_validate_recaptcha; Empty google recaptcha tokenToken field missing or null with active configuration.Supply the existing client token in one selected body representation.
409error_validate_recaptcha; Recaptcha is not validProvider answer has false/missing success.Handle rejection and let the configured client flow obtain a fresh token if appropriate; do not treat rejection as identity.
UnspecifiedNo universal JSON/status contractOther provider/transport or malformed-answer failure.Handle unavailable validation separately from a pass; inspect server/provider configuration through integration owner.

Next task

Return to the In-depth integration tasks. reCAPTCHA validation alone does not require an account request or payment.

Full diagram

Use the arrow keys to scroll. Escape closes this view.

Search documentation

Enter at least 2 characters.

    ↑ ↓ move through results · Enter opens · Escape closes