Google reCAPTCHA checks hosted authentication flows before Authdog issues a session or a one-time code. Configure it per environment. If Cloudflare Turnstile is also enabled for the same flow, reCAPTCHA is the one that runs.

## Create the key

1. Create a reCAPTCHA key for every domain that serves your Authdog pages, including any [custom domain](/docs/custom-domains).
2. Pick the version you will select in Authdog. Keys created in Google Cloud are Enterprise.
3. Copy the site key and the secret. For Enterprise, use the legacy secret key from the Integration tab (the siteverify secret).

## Enable the add-on

In the [Authdog console](https://console.authdog.com):

1. Select the project and environment.
2. Open **Authentication > Add-ons**.
3. Select **Google reCAPTCHA**.
4. Enter the **Site key** and the **Secret key**. The secret is write-only. Leave it blank on a later edit to keep the stored value.
5. Set **Version** to the key you created.
6. For v3 or Enterprise, set **Min score**. The default is `0.5`. Scores below it are rejected. v2 ignores this field.
7. Select the flows to protect. Selecting none protects all of them.
8. Enable the add-on and save.

| Version | What the user sees | Which flows |
| --- | --- | --- |
| **v2** | A checkbox | Sign-in, sign-up, waitlist, password reset |
| **v3** | Nothing. A score from `0` to `1` | Those four, plus magic link, one-time code, and MFA verification |
| **Enterprise** | Nothing. A score, same as v3 | Same as v3 |

Magic link, one-time code, and MFA verification have no room for a checkbox. They need **v3** or **Enterprise**. A v2 key on those flows does nothing, and the request continues without a token.

A version mismatch makes Google reject the token. The check then fails closed and the user sees a verification error.

## Roll out

1. Configure development first and complete a real sign-up.
2. Start with sign-up, waitlist, and password reset.
3. Add sign-in, then magic link and one-time codes, once real traffic looks healthy.
4. Repeat in production with production keys. Keys do not copy between environments.

## Related

| Read | To learn how to |
| --- | --- |
| [Bot protection](/docs/bot-protection) | Actions, fail-closed rules, and rollout order |
| [Cloudflare Turnstile](/marketplace/turnstile/setup) | The other add-on. reCAPTCHA wins when both are on |
| [Marketplace](/marketplace/recaptcha) | The listing for this integration |
