--- title: Web SDK --- # Web SDK Web SDK mendukung semua browser modern dengan berbagai metode integrasi. ::: tip Lihat dalam 30 detik [demo-v1.captcha.la](https://demo-v1.captcha.la) — HTML + PHP murni, lisensi MIT, view-source di setiap halaman. - [popup.html](https://demo-v1.captcha.la/popup.html) — mode popup - [float.html](https://demo-v1.captcha.la/float.html) — widget mengambang - [bind.html](https://demo-v1.captcha.la/bind.html) — ikat ke tombol - [inline.html](https://demo-v1.captcha.la/inline.html) — sematan inline - [server-token.html](https://demo-v1.captcha.la/server-token.html) — token terbitan server (anti-replay) ::: ## Mulai cepat ```html ``` ## Instalasi ### CDN ```html ``` ### NPM ```bash npm install captchala # or framework wrappers npm install @captcha-la/vue npm install @captcha-la/react ``` ```js import Captchala from 'captchala'; import 'captchala/dist/captchala.css'; ``` ## Mode ### Mode Popup ```js Captchala.init({ appKey: 'YOUR_APP_KEY', product: 'popup', action: 'login' }) .bindTo('#login-btn') .onSuccess(res => sendToBackend(res.token)); ``` ### Mode Float ```js Captchala.init({ appKey: 'YOUR_APP_KEY', product: 'float', action: 'browse' }) .appendTo('#captcha-container') .onSuccess(res => sendToBackend(res.token)); ``` ### Mode Bind ```js Captchala.init({ appKey: 'YOUR_APP_KEY', product: 'bind', action: 'login' }) .bindTo('#submit-button') .onSuccess(res => submitForm(res.token)); // fires only after challenge passes ``` ### Mode Embed ```js Captchala.init({ appKey: 'YOUR_APP_KEY', product: 'embed', action: 'register' }) .appendTo('#captcha-container') .onSuccess(res => sendToBackend(res.token)); ``` ## Opsi umum | Parameter | Tipe | Default | Deskripsi | | --- | --- | --- | --- | | `appKey` | string | — | Application Key (wajib) | | `product` | string | `popup` | Mode tampilan: popup | float | embed | bind | | `action` | string | `default` | Scene bisnis (mis. login, register, pay). Server menerapkan kebijakan keamanan yang berbeda per scene. | | `lang` | string | `en` | Bahasa yang didukung: zh-CN / zh-TW / en / ja / ko / ms / vi / id | | `serverToken` | string | — | Token sekali pakai (sct_xxx) yang diterbitkan server Anda. Sangat direkomendasikan di production untuk mencegah penyalahgunaan refresh challenge tanpa batas. | | `onServerTokenExpired` | `() => Promise` | — | Dipanggil saat serverToken kedaluwarsa; kembalikan token baru agar SDK dapat melanjutkan tanpa memutus flow. | | `enableVoice` | boolean | `true` | Tampilkan titik masuk audio captcha (dukungan aksesibilitas bagi pengguna tunanetra). | ## Validasi sisi server After `onSuccess`, send `res.token` (prefix `pt_`) to your own backend, then validate it server-side: ```bash POST https://apiv1.captcha.la/v1/validate X-App-Key: YOUR_APP_KEY X-App-Secret: YOUR_APP_SECRET Content-Type: application/json { "pass_token": "" } ``` Lihat [Referensi API](./api-reference) untuk endpoint validasi lengkap.