Abuse reports API
More
Reporting a site ZeroCaptcha was used against: public, with no key or session. Staff look into each report and act by hand.
Every operation of the API reference is generated from the contract the API serves, version 0.1.0. Replace YOUR_API_KEY in the samples with your key.
Report abuse
POST/v1/abuse-reports
Reports a site that ZeroCaptcha was used against without permission. The report is stored and sent to our staff, who look into it and act by hand: suspending the customer, or refusing tasks for the site. Nothing changes automatically. It needs no key or session. A browser's request must send no Sec-Fetch-Site but same-origin or none (csrf_rejected). Reports have a budget per client address.
Authentication: None: anyone may call it, within a budget per client address where the description says so.
Request body
JSON: NewAbuseReport.
| Field | Type | Description |
|---|---|---|
site required | string | The site ZeroCaptcha was used against: its domain, such as |
what required | string | What happened: 1 to 5,000 characters. |
email | string (email) | Where staff may answer you, if you want an answer. |
evidenceUrl | string (uri) | A link to evidence, such as logs or a screenshot: |
Responses
| Status | Meaning | Body |
|---|---|---|
| 202 Accepted | Received: staff will look into it. | AbuseReportReceipt (application/json) |
| 403 Forbidden | A browser's request from another site ( | Problem (application/problem+json) |
| 422 Unprocessable Content | Not a site, nothing said, an evidence link that is not http or https, or not an email address ( | Problem (application/problem+json) |
| 429 Too Many Requests | Too many reports from this address ( | Problem (application/problem+json) |
| 503 Service Unavailable | The report cannot be stored now ( | Problem (application/problem+json) |
| Any other status | An error, as RFC 9457 problem details. | Problem (application/problem+json) |
Error codes
csrf_rejected, validation_failed, rate_limited, service_unavailable. The errors reference says what each means, whether a retry helps and what it costs.
Sample
curl -X POST https://api.zerocaptcha.io/v1/abuse-reports \ -H "Content-Type: application/json" \ -d '{ "site": "shop.example.com", "what": "what"}'const response = await fetch("https://api.zerocaptcha.io/v1/abuse-reports", { method: "POST", headers: { "Content-Type": "application/json", }, body: JSON.stringify({ "site": "shop.example.com", "what": "what" }),});console.log(response.status, await response.text());import requests
response = requests.post( "https://api.zerocaptcha.io/v1/abuse-reports", json={ "site": "shop.example.com", "what": "what", }, timeout=30,)print(response.status_code, response.text)