# Site-owner opt-out API

> Site owners asking for their domain to be excluded: public, with no key or session. Staff check and decide each request by hand.

Source: https://zerocaptcha.io/docs/reference/api/opt-out

## Ask to opt a domain out

`POST /v1/opt-out-requests` (`requestOptOut`)

Asks for a domain, and everything under it, to be excluded: tasks against
it refused. The request is stored and sent to our staff, who check that
you speak for the domain and answer you by email; nothing changes until
they decide. It needs no key or session. A browser's request must send no
`Sec-Fetch-Site` but `same-origin` or `none` (`csrf_rejected`). Requests
have a budget per client address, then per domain.

Body fields:

| Field | Type | Required | What it is |
| --- | --- | --- | --- |
| `domain` | string | yes | The domain to exclude, such as `example.com`; everything under it is excluded with it. An internationalized one is kept in ASCII. |
| `email` | string (email) | yes | Where staff answer you. |
| `message` | string | no | Anything staff should know, such as how they can confirm you run the site: up to 2,000 characters. |

Responses:

- 202 Accepted: Received: staff will answer by email.
- 403 Forbidden: A browser's request from another site (`csrf_rejected`).
- 422 Unprocessable Content: Not a domain, not an email address, or a message over 2,000 characters (`validation_failed`).
- 429 Too Many Requests: Too many requests from this address, or for this domain (`rate_limited`).
- 503 Service Unavailable: The request cannot be stored now (`service_unavailable`). Retry shortly.
- Any other status: An error, as RFC 9457 problem details.

```bash
curl -X POST https://api.zerocaptcha.io/v1/opt-out-requests \
  -H "Content-Type: application/json" \
  -d '{
  "domain": "example.com",
  "email": "owner@example.com"
}'
```

```js
const response = await fetch("https://api.zerocaptcha.io/v1/opt-out-requests", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "domain": "example.com",
    "email": "owner@example.com"
  }),
});
console.log(response.status, await response.text());
```

```python
import requests

response = requests.post(
    "https://api.zerocaptcha.io/v1/opt-out-requests",
    json={
        "domain": "example.com",
        "email": "owner@example.com",
    },
    timeout=30,
)
print(response.status_code, response.text)
```
