Self-developed CAPTCHA

Self-developed CAPTCHA (character image / arithmetic), rendered locally with Pillow and no third-party dependency; each answer is validated only once.

/api/captcha_self/

Service Description

The self-hosted CAPTCHA depends on no third-party service: the platform draws character images or arithmetic questions locally with Pillow, making it suitable when data must not leave your infrastructure or when you want a zero-cost in-house CAPTCHA.

Integration takes two steps: call the generate API to obtain a captcha_id and a base64 image with a validity period, then call the verify API with the user's answer. Answers are one-time: the challenge is invalidated immediately whether verification succeeds or fails, so a new image must be generated before retrying.

This channel is open and needs no project signature; in production, also throttle verification attempts per IP and per account.

Self-developed CAPTCHA

SpiderServices/Captcha self-developed generation engine (drawn with Pillow) Available · No Signature

Two-step integration: call generate first to obtain a captcha_id and image (base64), then POST the user answer to verify. The answer is single-use: it expires immediately after validation, correct or not, so the frontend must fetch a new image afterwards.

GET /api/captcha_self/generate Total calls: 28

Generate CAPTCHA

Generate one CAPTCHA and return its captcha_id, base64 image and validity period.

Optional: char = character image (digits + uppercase letters); arithmetic = addition / subtraction

Optional: only applies when kind=char; valid range 4-6 (default 4)

  • Request method GET with parameters in the query string; public Endpoint, no project signature required.
  • The returned data.captcha_id must be sent back to verify together with the answer; data.image is a base64 data URI usable directly in <img src>; data.expire_in is the validity period in seconds (default 300).
POST /api/captcha_self/verify Total calls: 3

Validate CAPTCHA

Submit the user answer for validation; the CAPTCHA is consumed on use (invalidated immediately after validation).

Required: the captcha_id (UUID) returned by the generate Endpoint

Required: the answer entered by the user (case-insensitive for characters; enter the computed result for arithmetic)

  • The request body is an application/x-www-form-urlencoded form; this is an open endpoint and needs no project signature.
  • Validation passed: code=10000 with data.passed=true;
  • Not passed (wrong answer / expired / already used / not found): code=20003 with data.passed=false; see msg for the cause;
  • A non-UUID captcha_id returns code=20002; a missing parameter returns code=20001.
  • The answer is single-use: repeated submissions of the same CAPTCHA can succeed only once, so call generate again after a failure.
XiaoYingAPI · Unified API Aggregation Service