Graphic CAPTCHA

Alibaba Cloud Graphic CAPTCHA integration (Slider/Click-word, etc.), with server-side config delivery and secondary validation to prevent bot traffic. Currently connected to the Alibaba Cloud Channel.

/api/captcha_auth/

Service Description

The graphic CAPTCHA service integrates Alibaba Cloud CAPTCHA (slider, click-select and other behavioral challenges) to block bot traffic at entry points such as sign-up, log-in and SMS sending: the frontend first fetches the config to obtain the appId, initializes the SDK and completes the challenge, then hands the verification parameters to your backend, which calls the check API to confirm the challenge was genuinely passed.

To prevent bypassing, the result must be verified again server-side and never trusted from a frontend callback alone.

This channel is entirely open, so both config and verify need no project signature, which makes frontend integration straightforward.

Alibaba Cloud Graphic Authentication

Alibaba Cloud graphic authentication service (Slider/Click-word verification) Available · No Signature

Two-step integration: first call config to get the appId and initialize the frontend SDK, then call verify for server-side secondary validation after the user passes verification.

GET /api/captcha_auth/aliyun/config Total calls: 3

Get Graphic Authentication Config

Returns the graphic authentication appId (captchaId) for H5 frontend SDK initialization. Public Endpoint, no signature required.

  • The response data.app_id is the captchaId required by the frontend initAlicom4({ captchaId: app_id, product: "bind" }, ...).
POST /api/captcha_auth/aliyun/verify Total calls: 1

Secondary Validation

Upload client verification parameters to confirm that the user's current Graphic CAPTCHA verification is valid (anti-bypass).

Required: the serial number returned by the frontend SDK callback after verification passes, a 32-character lowercase hex string

Required: the captchaOutput returned by the frontend SDK callback after verification passes

Required: the passToken returned by the frontend SDK callback after verification passes

Required: the genTime returned by the frontend SDK callback after verification passes

  • The request body is an application/x-www-form-urlencoded form; this is a public Endpoint with no project signature required.
  • A successful request always returns code=10000; determine the business result from data.result:
  • success=verification valid, fail=verification invalid (pass_token expired, serial number already used, etc.); see data.reason for the cause.
XiaoYingAPI · Unified API Aggregation Service