Security
Responsible Captcha Automation: Acceptable Use and Opt-outs
When using a captcha solver is appropriate, what ZeroCaptcha's Acceptable Use Policy allows, and how site owners opt out or report abuse, all handled by people.
3 min readPublished Updated
A CAPTCHA exists because a site owner chose to slow down automated traffic. A solving API supplies the token that tells the site “a visitor passed”, so it should only be used where the automation itself is legitimate. This guide explains how ZeroCaptcha draws that line, what the Acceptable Use Policy asks of every customer, and how site owners can opt out or report misuse. Every step described here is handled by people, not by automatic rules.
Legitimate uses
The policy lists what you may do, and it is ordinary engineering work:
- Test, monitor or automate sites you own or run.
- Automate sites whose owner allows it, in their terms or in writing, such as a supplier portal without an API.
- Run security or quality tests you are authorized to run.
- Collect public data where the law and the site’s terms let you.
For your own sites, first check whether you need a solver at all. Cloudflare publishes testing sitekeys that always pass in CI: see Test Cloudflare Turnstile in CI.
What is not acceptable
The Acceptable Use Policy is the authority. In short, it rules out solving challenges on a site you are not allowed to automate or whose owner has told you to stop; taking over accounts, testing stolen passwords or card numbers, or any fraud; creating accounts, reviews, votes or messages in bulk to deceive a site or its users; getting into systems or data you have no right to; and overloading or disrupting a site. Every account accepts the policy when it signs up, and you are responsible for every task your keys create.
How enforcement works
ZeroCaptcha keeps enforcement simple and human:
- A blocklist, kept by hand. Staff add a domain after a report, after a check of the logs, or
when its owner opts out. Tasks for a domain on the blocklist are refused before any solving, at
no charge, with
ERROR_DOMAIN_BLOCKED. - Account suspension, by a person. When an account breaks the policy, staff may suspend it.
A suspended account’s keys are refused, with
ERROR_ACCOUNT_SUSPENDED, and it cannot create tasks, keys or top-ups. Each action is recorded with its reason. - No automatic category rules. No kind of site is blocked on its own; each block is a decision a person made about a specific domain.
For site owners: opting out
If you run a site and do not want ZeroCaptcha used against it, send a request from the opt-out page: your domain, an address where we can reach you, and anything we should know. A person checks that you speak for the domain, usually by writing to you, then adds it to the blocklist by hand, or tells you why not. There is no account to create and nothing to pay.
For anyone: reporting abuse
If you believe ZeroCaptcha was used against a site in breach of the policy, use the abuse report form: the site, what happened, and a link to evidence if you have one. An address is optional, if you would like an answer. Staff read every report, and may block the site or suspend an account as a result.
For customers: staying on the right side
- Know the site’s terms before you automate it, and keep a record of the permission you rely on.
- Pace your traffic as a courteous visitor would: see Scraping a site with Cloudflare Turnstile.
- Protect your keys, so nobody else can send tasks in your name: see Secure your captcha API keys.
- Treat
ERROR_DOMAIN_BLOCKEDas final. Stop sending tasks for that site. The refused task costs nothing, and retrying it cannot succeed.
Questions
Write to us from the contact page with anything the policy does not answer. To see what the API does for legitimate automation, start at the Cloudflare Turnstile solver page, or read more about ZeroCaptcha.