October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

reCAPTCHA v2 Callback: Find the Handler and Understand Token Injection

Locate the reCAPTCHA v2 success handler in markup or render options, start an invisible challenge with execute(), and distinguish calling your code from verifying a real response.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Find a reCAPTCHA v2 success handler in the widget’s data-callback attribute or in the callback option passed to grecaptcha.render. Google’s documented API does not let you inject an arbitrary token into the widget and make it count as a successful challenge by manually firing that callback. Calling your own handler can test your application’s client-side flow, but only server-side verification with Google establishes whether a response is valid.

How do I find the reCAPTCHA v2 callback function?

The callback is an application function you configure; it is not a universal function name built into every reCAPTCHA widget. Google documents two common places to find its name: the widget’s HTML attributes and the options supplied when rendering it with JavaScript. See Google’s reCAPTCHA v2 display and API documentation, last updated October 8, 2024.

Automatically rendered widget

Search the page markup for data-callback. For example:

<div class="g-recaptcha" data-sitekey="YOUR_SITE_KEY" data-callback="onCaptchaSuccess"></div>

Here, onCaptchaSuccess is the configured function name. Search the page’s scripts for its definition. If the application uses a framework or wrapper, follow how it registers the callback; the function cannot be identified from the widget alone if its source is unavailable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Explicitly rendered widget

For a widget created with grecaptcha.render, inspect the options passed to that call:

const widgetId = grecaptcha.render('captcha', {
  sitekey: 'YOUR_SITE_KEY',
  callback: onCaptchaSuccess
});

The callback option names the success handler, and grecaptcha.render returns a widget ID. Keep that ID when the page may contain multiple widgets so later API calls target the right one.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

If no success callback is configured

After the user completes a challenge, grecaptcha.getResponse(widgetId) can retrieve that widget’s response. If you omit the ID, Google’s API uses the first widget. With multiple widgets, pass the ID returned by grecaptcha.render rather than relying on the default.

For issues other than success, check data-expired-callback or expired-callback for an expired response, and data-error-callback or error-callback for an error path. An expired challenge needs renewed verification; an error callback is for handling an error such as a connectivity problem.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Can I trigger the callback after injecting a token?

You can call an application function directly if you want to test what your own code does with a supplied string. That does not inject a valid answer into the reCAPTCHA widget, simulate a genuine challenge, or prove that Google will accept the string. The documented widget API provides callbacks for successful widget responses, but no supported method for injecting an arbitrary token and manually triggering the widget’s success callback.

Keep these two operations separate:

  • Testing client-side application logic: call your application’s success-handling function with a test fixture to check downstream UI or request handling. This tests your function only.
  • Verifying a reCAPTCHA response: send the response token and your secret from the server to Google’s siteverify endpoint, then make the application’s decision from Google’s verification response. Never expose the secret in browser code.

Google states that each response token is valid for two minutes and can be verified only once to prevent replay attacks. A manually supplied string does not bypass those checks or become verified merely because application code receives it.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How do I programmatically run an invisible reCAPTCHA v2 challenge?

For an invisible v2 widget, the documented way to start the challenge programmatically is grecaptcha.execute(widgetId). This starts the challenge; it is not a substitute for receiving the completed response or verifying it on your server. The configured success callback receives the response after the challenge succeeds. See Google’s invisible reCAPTCHA documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does a supported explicit-render setup look like?

Define the API onload function before loading Google’s script. Google specifically requires that ordering and recommends async and defer for explicit rendering to avoid a load race.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
<div id="captcha"></div>
<script>
  function onCaptchaSuccess(responseToken) {
    // Send the response to your application server for verification.
    submitResponseForServerVerification(responseToken);
  }

  function onCaptchaExpired() {
    // Ask the user to complete the challenge again.
  }

  function onCaptchaError() {
    // Tell the user to retry when connectivity is restored.
  }

  function onRecaptchaApiLoaded() {
    window.captchaWidgetId = grecaptcha.render('captcha', {
      sitekey: 'YOUR_SITE_KEY',
      callback: onCaptchaSuccess,
      'expired-callback': onCaptchaExpired,
      'error-callback': onCaptchaError
    });
  }
</script>
<script src="https://www.google.com/recaptcha/api.js?onload=onRecaptchaApiLoaded&render=explicit" async defer></script>

After a successful challenge, Google calls onCaptchaSuccess with the response token as its argument. The example’s application-specific submission function must send that response to your server, where verification takes place.

Which rendering approach should I inspect?

Approach Where the success callback is configured Widget ID When it fits
Automatically rendered widget data-callback on the widget markup May be omitted for a single widget; pass the ID when targeting a particular widget or working with multiple widgets. Markup-driven setup without explicit JavaScript rendering.
Explicit JavaScript rendering callback in the options passed to grecaptcha.render grecaptcha.render returns an ID to retain for widget-specific API calls. When the application needs to render or control a widget through JavaScript.
Invisible v2 challenge The configured callback receives the response after success. Pass the widget ID to grecaptcha.execute(widgetId) when starting the challenge programmatically. When the application needs to initiate an invisible challenge in code.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.