Skip to content
ZeroCaptcha

Abuse reports API

Reporting a site ZeroCaptcha was used against: public, with no key or session. Staff look into each report and act by hand.

Every operation of the API reference is generated from the contract the API serves, version 0.1.0. Replace YOUR_API_KEY in the samples with your key.

Report abuse

POST/v1/abuse-reports

Reports a site that ZeroCaptcha was used against without permission. The report is stored and sent to our staff, who look into it and act by hand: suspending the customer, or refusing tasks for the site. Nothing changes automatically. It needs no key or session. A browser's request must send no Sec-Fetch-Site but same-origin or none (csrf_rejected). Reports have a budget per client address.

Authentication: None: anyone may call it, within a budget per client address where the description says so.

Request body

JSON: NewAbuseReport.

Fields of the request body
FieldTypeDescription
site requiredstring

The site ZeroCaptcha was used against: its domain, such as shop.example.com, or an address on it.

what requiredstring

What happened: 1 to 5,000 characters.

emailstring (email)

Where staff may answer you, if you want an answer.

evidenceUrlstring (uri)

A link to evidence, such as logs or a screenshot: http or https, up to 2,048 characters.

Responses

Responses of Report abuse
StatusMeaningBody
202 Accepted

Received: staff will look into it.

AbuseReportReceipt (application/json)
403 Forbidden

A browser's request from another site (csrf_rejected).

Problem (application/problem+json)
422 Unprocessable Content

Not a site, nothing said, an evidence link that is not http or https, or not an email address (validation_failed).

Problem (application/problem+json)
429 Too Many Requests

Too many reports from this address (rate_limited).

Problem (application/problem+json)
503 Service Unavailable

The report cannot be stored now (service_unavailable). Retry shortly.

Problem (application/problem+json)
Any other status

An error, as RFC 9457 problem details.

Problem (application/problem+json)

Error codes

csrf_rejected, validation_failed, rate_limited, service_unavailable. The errors reference says what each means, whether a retry helps and what it costs.

Sample

Terminal window
curl -X POST https://api.zerocaptcha.io/v1/abuse-reports \
-H "Content-Type: application/json" \
-d '{
"site": "shop.example.com",
"what": "what"
}'