I'm using google Recaptcha v2.0 for my application.
This is a multitenancy app in which we create a subdomain for each tenants:
- tenant1.myapp.com
- tenant2.myapp.com
- tenant3.myapp.com
Until now, we are registering manually each subdomain in the Google Recaptcha Admin.
I wonder if in terms of security if could be enough (and safe) to just register the main domain:
- app.com
"if you specify the API key pair to yoursite.com, the following table shows whether or not reCAPTCHA will work for the domain and its subdomain variations"
