Site-owner opt-out API
More
Site owners asking for their domain to be excluded: public, with no key or session. Staff check and decide each request by hand.
Every operation of the API reference is generated from the contract the API serves, version 0.1.0. Replace YOUR_API_KEY in the samples with your key.
Ask to opt a domain out
POST/v1/opt-out-requests
Asks for a domain, and everything under it, to be excluded: tasks against it refused. The request is stored and sent to our staff, who check that you speak for the domain and answer you by email; nothing changes until they decide. It needs no key or session. A browser's request must send no Sec-Fetch-Site but same-origin or none (csrf_rejected). Requests have a budget per client address, then per domain.
Authentication: None: anyone may call it, within a budget per client address where the description says so.
Request body
JSON: NewOptOutRequest.
| Field | Type | Description |
|---|---|---|
domain required | string | The domain to exclude, such as |
email required | string (email) | Where staff answer you. |
message | string | Anything staff should know, such as how they can confirm you run the site: up to 2,000 characters. |
Responses
| Status | Meaning | Body |
|---|---|---|
| 202 Accepted | Received: staff will answer by email. | OptOutReceipt (application/json) |
| 403 Forbidden | A browser's request from another site ( | Problem (application/problem+json) |
| 422 Unprocessable Content | Not a domain, not an email address, or a message over 2,000 characters ( | Problem (application/problem+json) |
| 429 Too Many Requests | Too many requests from this address, or for this domain ( | Problem (application/problem+json) |
| 503 Service Unavailable | The request cannot be stored now ( | Problem (application/problem+json) |
| Any other status | An error, as RFC 9457 problem details. | Problem (application/problem+json) |
Error codes
csrf_rejected, validation_failed, rate_limited, service_unavailable. The errors reference says what each means, whether a retry helps and what it costs.
Sample
curl -X POST https://api.zerocaptcha.io/v1/opt-out-requests \ -H "Content-Type: application/json" \ -d '{ "domain": "example.com", "email": "owner@example.com"}'const response = await fetch("https://api.zerocaptcha.io/v1/opt-out-requests", { method: "POST", headers: { "Content-Type": "application/json", }, body: JSON.stringify({ "domain": "example.com", "email": "owner@example.com" }),});console.log(response.status, await response.text());import requests
response = requests.post( "https://api.zerocaptcha.io/v1/opt-out-requests", json={ "domain": "example.com", "email": "owner@example.com", }, timeout=30,)print(response.status_code, response.text)