# Abuse reports API

> Reporting a site ZeroCaptcha was used against: public, with no key or session. Staff look into each report and act by hand.

Source: https://zerocaptcha.io/docs/reference/api/abuse-reports

## Report abuse

`POST /v1/abuse-reports` (`reportAbuse`)

Reports a site that ZeroCaptcha was used against without permission. The
report is stored and sent to our staff, who look into it and act by hand:
suspending the customer, or refusing tasks for the site. Nothing changes
automatically. It needs no key or session. A browser's request must send
no `Sec-Fetch-Site` but `same-origin` or `none` (`csrf_rejected`).
Reports have a budget per client address.

Body fields:

| Field | Type | Required | What it is |
| --- | --- | --- | --- |
| `site` | string | yes | The site ZeroCaptcha was used against: its domain, such as `shop.example.com`, or an address on it. |
| `what` | string | yes | What happened: 1 to 5,000 characters. |
| `email` | string (email) | no | Where staff may answer you, if you want an answer. |
| `evidenceUrl` | string (uri) | no | A link to evidence, such as logs or a screenshot: `http` or `https`, up to 2,048 characters. |

Responses:

- 202 Accepted: Received: staff will look into it.
- 403 Forbidden: A browser's request from another site (`csrf_rejected`).
- 422 Unprocessable Content: Not a site, nothing said, an evidence link that is not http or https, or not an email address (`validation_failed`).
- 429 Too Many Requests: Too many reports from this address (`rate_limited`).
- 503 Service Unavailable: The report cannot be stored now (`service_unavailable`). Retry shortly.
- Any other status: An error, as RFC 9457 problem details.

```bash
curl -X POST https://api.zerocaptcha.io/v1/abuse-reports \
  -H "Content-Type: application/json" \
  -d '{
  "site": "shop.example.com",
  "what": "what"
}'
```

```js
const response = await fetch("https://api.zerocaptcha.io/v1/abuse-reports", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "site": "shop.example.com",
    "what": "what"
  }),
});
console.log(response.status, await response.text());
```

```python
import requests

response = requests.post(
    "https://api.zerocaptcha.io/v1/abuse-reports",
    json={
        "site": "shop.example.com",
        "what": "what",
    },
    timeout=30,
)
print(response.status_code, response.text)
```
