Branded website addresses
Websites on the platform’s default address or your workspace’s branded website subdomain use managed protection. You do not need to create a key for each website. Custom domains need their own keys.Create your keys
- Open the Google reCAPTCHA admin console and sign in.
- Enter a label you recognize, such as your business name.
- Select Score based (v3). Do not select the v2 checkbox option.
- Add your website’s domain without
https://, a path or*.. For example,example.comalso coverswww.example.comand its other subdomains. - Select or create the Google Cloud project requested by the console and complete Google’s registration steps.
- Copy the site key and secret key. If your Google Cloud key page does not show a secret, open the key’s integration/legacy-secret settings. This connection uses the v3 site key and legacy secret, not a Google Cloud API key.
Connect the website
- Open Website Settings → Form Settings.
- Select Spam Protection and find the custom-domain reCAPTCHA fields.
- Paste the site key and secret key, then save.
- Submit a test from the website’s actual custom domain. A branded preview address uses managed protection and does not test your custom key.
Troubleshooting
- Setup required: save both keys for the custom domain.
- Invalid domain/site key: check that the Google key is v3 and includes the hostname visitors use.
- Verification failed: refresh and try again. Tokens expire quickly and can only be used once. Browser extensions blocking Google scripts may prevent verification.
- Domain changed: add the new domain in Google before testing it.

