All Products
Search
Document Center

Captcha:Custom policy

Last Updated:Jul 22, 2026

After adding a verification scenario, you can configure a custom policy to meet your business requirements.

Prerequisites

Enable a custom policy

  1. Log on to the Captcha V2.0 console..

  2. In the navigation pane on the left, click Overview.On the version card on the right, find Feature > Custom Policy and turn on the switch.

Configure a custom policy

  1. Log in to the Captcha 2.0 console. In the left-side navigation pane, choose Security Management > Custom Policy.

  2. On the Custom Policy page, find the target scenario and click Modify in the Actions column.

  3. In the Configure Custom Policy panel, configure the parameters and click OK.

    Parameter

    Description

    Mode

    • Basic Mode (Default): Provides foundational security. Recommended when the volume of malicious requests is low to balance security and user experience.

    • Attack and Defense Mode: Provides an enhanced risk control policy. Recommended when you observe a spike in malicious requests. This mode strictly blocks malicious requests but may introduce a small number of false positives.

    URL Verification

    Verifies the URL of the page where the CAPTCHA is invoked. By default, this field is empty, and no verification is performed. The CAPTCHA is passed if the configured URL is a substring of the actual page URL. For example, a value of www.abc.com matches pages such as www.abc.com/a, www.abc.com/a/xxxx, and www.abc.com/b.

    IP Address Access Frequency Limit

    • Hourly limit per IP:

      • Enter an integer from 1 to 999,999,999. Default value: 4,000.

    • Daily limit per IP:

      • Enter an integer from 1 to 999,999,999. Default value: 10,000.

    Device Access Frequency Limit

    • Hourly limit per device:

      • Enter an integer from 1 to 999,999,999. Default value: 150.

    • Daily limit per device:

      • Enter an integer from 1 to 999,999,999. Default value: 400.

    Intercept Simulated Devices

    Blocks traffic from virtual machines (such as VMware, VirtualBox, Hyper-V, and Parallels), emulators (such as AVD, BlueStacks, and VBox/Hyper-V), and desktop browsers that simulate mobile devices.

    Intercept Simulated Click Behavior

    Blocks script-simulated operations such as clicks and swipes.

    Important

    For Vue applications that use touch-emulator to simulate touch events on desktops, these simulated behaviors are part of the normal application logic. Enabling this option may interfere with your application's functionality. Evaluate the impact carefully before you proceed.

    After you save the configuration, the Policy Type changes from Default to Custom.

Disable custom policy

  1. Log in to the Captcha 2.0 console.

  2. In the left-side navigation pane, click Overview. On the version card in the upper-right corner, click Expand and disable the Custom Policy switch.

    Important

    If you cannot disable the custom policy, navigate to the Custom Policy page. In the Actions column, click Restore to Default to revert all custom settings. Then, try disabling the policy again.

References

For billing details, see Billing.