We are using the Google invisible Recaptcha to detect genuine logins to our application. The "recaptcha.js" hits the https://www.recaptcha.net/recaptcha/api2/userverify endpoint which gives the Recaptcha token.
The API to verify the user's response is https://www.google.com/recaptcha/api/siteverify
Questions:
- Can there be a possibility that the endpoint
https://www.recaptcha.net/recaptcha/api2/userverify(used by the Recaptcha JS script) is available and this endpointhttps://www.google.com/recaptcha/api/siteverifyis down or vice versa? - Why are the user verification endpoint and the token verification endpoints hosted in different domains?
- How do we determine the availability of the recaptcha validation service?