reCAPTCHA Settings
Google reCAPTCHA helps protect your contact forms from spam, bots, and unwanted submissions.
The Contact Form with API app supports Google reCAPTCHA v2 – “I’m not a robot” Checkbox. To enable it, you need to create a reCAPTCHA account for your website and add the generated Site Key and Secret Key to the app.
Before You Start
Make sure you have:
- A Google account
- Access to the website where your contact form is being used
- The website domain you want to protect
Step 1: Open the Google reCAPTCHA Console
Go to the Google reCAPTCHA Console.
Sign in with your Google account if Google asks you to log in.
You will be taken to the page where you can register your website for reCAPTCHA.
Step 2: Add a Label
In the Label field, enter a name that helps you identify your website.
For example:
Contact Form Website
The label is only for your reference, so you can use any name that makes sense to you.
Step 3: Select reCAPTCHA v2
Under reCAPTCHA type, select:
reCAPTCHA v2 → “I’m not a robot” Checkbox
This is the reCAPTCHA version supported by the Contact Form with API app.
Important: Do not select reCAPTCHA v3 or another reCAPTCHA type. Use reCAPTCHA v2 – “I’m not a robot” Checkbox.
Step 4: Add Your Website Domain
Enter the domain of the website where you are using the contact form.
For example:
example.com
Do not include:
https://
Example
✅ example.com
✅ www.example.com
❌ https://example.com
Make sure you add the correct domain. Your reCAPTCHA keys will only work on the domains registered with Google.
Step 5: Accept the Terms
Read and accept the reCAPTCHA Terms of Service by selecting the checkbox.
You may also enable email notifications if you want to receive alerts from Google.
Step 6: Submit the Registration
Click Submit.
Google will now create the reCAPTCHA keys for your website.
You will see two keys:
1. Site Key
The Site Key is the key used by your website and contact form to connect with Google reCAPTCHA.
2. Secret Key
The Secret Key is used by the app to securely communicate with Google and verify reCAPTCHA responses.
You need both keys to complete the setup.
Keep your Secret Key private. Do not share it publicly or add it to publicly visible website content.
Step 7: Add the Keys to the Contact Form with API
Now open your Shopify admin and go to:
Apps → Contact Form with API → Settings → reCaptcha Settings
You will see the Google reCAPTCHA Configuration section, as shown below.
In the Site Key field, paste the Site Key you received from Google.
In the Secret Key field, paste the Secret Key you received from Google.
Then click Save.
Once the keys are saved, Google reCAPTCHA can be used with your forms.
Your reCAPTCHA Settings
Your settings page will look similar to this:
Google reCAPTCHA Configuration
- Site Key: Enter the Site Key generated by Google
- Secret Key: Enter the Secret Key generated by Google
- Click Save to save your settings
How to Make Sure reCAPTCHA Works
After saving your keys, open the page where your contact form is displayed and test the form.
When reCAPTCHA is enabled on the form, visitors should see the “I’m not a robot” checkbox.
Complete the checkbox and submit the form to make sure everything is working correctly.
Common Issues to Check
“reCAPTCHA is not working”
Make sure you selected:
reCAPTCHA v2 → “I’m not a robot” Checkbox
The app does not support other reCAPTCHA versions for this integration.
“Invalid domain” or reCAPTCHA errors
Check the domain you entered in the Google reCAPTCHA Console.
Make sure:
- The domain is entered correctly.
- You did not include
https://. - The domain where your form is displayed is registered with Google.
The keys are not working
Make sure you copied the correct:
- Site Key into the Site Key field
- Secret Key into the Secret Key field
Also check that the keys belong to the same reCAPTCHA configuration and website domain.
Protect Your Forms with Google reCAPTCHA
That’s it! Once you have added your Site Key and Secret Key and saved the settings, Google reCAPTCHA is ready to help protect your contact forms from spam and automated submissions.
Make sure you have selected reCAPTCHA v2 – “I’m not a robot” Checkbox and registered the correct website domain in Google’s reCAPTCHA Console. After completing the setup, test your form once to confirm that the reCAPTCHA checkbox appears and submissions are working as expected.
With reCAPTCHA enabled, you can add an extra layer of protection to your forms while keeping the submission experience simple for your visitors.