Where would be the best place to put the captcha token in a REST API

Viewed 2354

I'm designing a REST api that allow client side to POST (create) a resource. Let's call my resource is Subscription and my REST api accepts a Dto called Subscription The POST request needs to be sent together with a captcha token that will be verified on server side.

My question is where would be the best place to put the captcha token, there're some options that I'm thinking about:

  1. Directly inside Subscription
  2. As a parameter in URL, e.g: /subscriptions?captcha_token=abcd1234
  3. As a HTTP header
  4. Create a new Dto that wraps Subscription and carry field captchaToken

Any other suggestion are welcome.

Thank you.

2 Answers
Related