Google invisible Recaptcha token and validation endpoints are hosted in different domains

Viewed 282

We are using the Google invisible Recaptcha to detect genuine logins to our application. The "recaptcha.js" hits the https://www.recaptcha.net/recaptcha/api2/userverify endpoint which gives the Recaptcha token. The API to verify the user's response is https://www.google.com/recaptcha/api/siteverify

Questions:

  1. Can there be a possibility that the endpoint https://www.recaptcha.net/recaptcha/api2/userverify (used by the Recaptcha JS script) is available and this endpoint https://www.google.com/recaptcha/api/siteverify is down or vice versa?
  2. Why are the user verification endpoint and the token verification endpoints hosted in different domains?
  3. How do we determine the availability of the recaptcha validation service?
0 Answers
Related