With the captcha on, a visitor proves to be a person once, before the first question, and the admin asks for the same proof before any of its pages. It uses Google reCAPTCHA v2, the checkbox.
- In the Google reCAPTCHA admin console, create a reCAPTCHA v2 key of the “I’m not a robot” checkbox type, with your site’s domain in its list of domains.
- On the Captcha tab of the chat’s admin, paste the Site key and the Secret key.
- Click Save settings. From the next page view on, the chat asks for the captcha.
Both keys are needed. Once saved, the secret key is never shown again; leave its field empty to keep it.
- The first time they open the chat, a box over the window: Confirm that you are not a robot. Tick the box below to start chatting.
- If the proof runs out in the middle of a conversation, their next question waits: Your question is sent as soon as the check passes.
- Cancel closes the box; the question is not sent.
- The proof is kept in a cookie for that browser and that IP address. A visitor whose address changes is asked again.
- A browser that blocks cookies for your site cannot keep the proof, and the chat says so: The check passed, but this browser did not keep it. Allow cookies for this site and ask again.
The reCAPTCHA script is loaded from Google only when the captcha has to be shown, not on every page.
With both keys saved, the admin asks for the captcha before any of its pages opens, and the sign-in form asks for it again. See The admin.
How long a solved captcha lasts before it is asked again, for visitors and for the admin alike.
Empty the Site key field and save. Without a site key there is no captcha, for visitors or for the admin; the saved secret key stays until you replace it.
The captcha was solved for another site.
The domain the visitor is on is missing from the key’s list of domains in the reCAPTCHA admin console: add it, with and without www if your site answers on both. Behind a reverse proxy, the proxy must also pass on the visitor’s host name, as on Add the chat to your pages.
The captcha could not be checked. Please try again.
Your server could not reach Google to check the answer. It needs outbound HTTPS to www.google.com.
The check could not be loaded.
The visitor’s browser could not load reCAPTCHA. If your site sends a Content-Security-Policy, it must allow scripts from https://www.google.com/recaptcha/ and https://www.gstatic.com/recaptcha/, and frames from https://www.google.com/recaptcha/ and https://recaptcha.google.com/.