OxyPages

How To Get Your reCAPTCHA V3 Keys From Google

How To Get Your reCAPTCHA v3 Keys From Google

Get your reCAPTCHA v3 keys from Google in about five minutes, then paste the Site Key and Secret Key into Form Settings so your contact form starts working.

The OxyPages Team · · 10 min read

Your form looks right, you press Send, and the page answers "Forms Not Active". Nothing you change in the HTML fixes it, because the problem was never in the HTML.

Forms on a static site need a captcha before they will accept anything, and you bring your own. If you picked Google reCAPTCHA v3, that means two strings out of Google's admin console: a Site Key and a Secret Key. This guide creates your reCAPTCHA v3 keys and puts them where they do their job.

It takes about five minutes, most of that waiting for Google pages to load. There is no code to write and nothing to install. Google issues the pair, you save it on the Form Settings page, and every form on the published site starts accepting submissions.

The parts people get stuck on come later: which domains to register, and why v3 never shows a visitor a puzzle. That second one is worth understanding first.

TL;DR: Google issues your reCAPTCHA v3 keys as a pair, a Site Key that runs in the visitor's browser and a Secret Key that is checked on the server. Register at Google's reCAPTCHA admin console, choose the score-based (v3) type, add your published address, then paste both keys into Form Settings and save. You add nothing to your page: the script, the hidden token field and the honeypot are injected when the page is served. v3 shows no puzzle at all. It scores each visitor from 0.0 to 1.0, and anything under 0.3 is refused for you.

What Your reCAPTCHA v3 Keys Actually Do

Your reCAPTCHA v3 keys are a matched pair, and each half has a different job.

The Site Key is public. It goes into the page, it tells Google which site the visitor is on, and anyone can read it in your source. That is fine and expected.

The Secret Key is private. It never touches the page. It is used server-side on every submission, to ask Google two things: did this token really come from my site, and how did that visitor score? The submission is kept or refused on that answer.

That split is the whole reason a captcha is worth anything. A bot can lift your Site Key out of the page and post straight at your form, skipping every widget on it. What it cannot fake is the server check, because that needs the half of the pair it never sees. So the Site Key is safe to expose and the Secret Key is not: never commit it to a public repo.

Should You Use reCAPTCHA v3 Or Cloudflare Turnstile?

Use Turnstile unless you have a reason to be on Google. That is the honest answer, and it is the one OxyPages gives you: Turnstile is the option marked Recommended in Form Settings.

Google reCAPTCHA v3Cloudflare Turnstile
Account you needA Google account, plus a Cloud billing accountA Cloudflare account
What the visitor seesNothingNothing, or a brief check
How it decidesA score from 0.0 to 1.0Pass or fail
If it judges a real person wronglyNothing to appeal to, the submission is refusedThe widget can run its check again
Cost10,000 assessments a month free, per organisationFree, unlimited challenges
Who sees your visitorsGoogleCloudflare

That cost row changed on 2 April 2026. Google split reCAPTCHA into Essentials, Premium and Enterprise and cut the free allowance from a million assessments a month to 10,000, counted per organisation per calendar month rather than per site. One form submission is one assessment, so a busy form can reach the ceiling on its own, and it shares that ceiling with every other key your organisation runs. Every tier, free Essentials included, now needs an active Google Cloud billing account attached.

Google reCAPTCHA v3 is still the right pick in a few real situations. You already run reCAPTCHA elsewhere and want one console for all of it. Or you want the traffic view Google's console gives you, which earns its keep during a spam wave, when you want to see what scores it is getting.

Turnstile wins the rest of the time. Either way you paste two keys into the same two boxes, so this is not a decision you are stuck with.

How To Get The reCAPTCHA v3 Keys From Google

How To Get The reCAPTCHA v3 Keys From Google - OxyPages

Getting the reCAPTCHA v3 keys is five steps in one browser tab. Open Google's reCAPTCHA admin console and sign in. reCAPTCHA lives in Google Cloud now, so that console is the Cloud Fraud Defense admin console: it creates a Cloud project for you and switches on the APIs it needs. That is the normal path now, not a detour.

  1. Label: name it after the site, something like oxy-contact-form. It is only for you and appears nowhere public.
  2. reCAPTCHA type: choose Score based (v3). The other option is Challenge (v2), which is a different kind of key.
  3. Domains: add every address visitors will actually use, one per line. No https://, no trailing slash, no path. Google allows up to 250 per key.
  4. Terms: tick the reCAPTCHA Terms of Service box and press Submit.
  5. Copy both keys: the Site Key (it starts with 6L) is shown straight away. The Secret Key is on the key's details page, listed as the legacy secret key for use with a third-party application. That is the one Form Settings wants.

Every site key still gets one of those legacy secrets. If the screen after Submit only offers you an API to call with your own credentials, open the key and copy the secret off its details page.

One thing to be clear about: v2 keys will not work in place of the reCAPTCHA v3 keys. Nothing renders a v2 checkbox on your page, so no token is produced and every submission is refused with "Couldn't Confirm You're Human". If that is the message you are seeing, check the key type first.

Which Domains To Register

Register the addresses the form is really served from:

  • Your free subdomain, in the form yourname.myoxypages.com.
  • Your custom domain, if you have one on a paid plan.
  • The www version too, if visitors reach you that way.

Skip localhost. There is nothing to test locally: forms only submit from the live published site, never from the editor preview and never from a file on your own machine.

If you later move the site to a custom domain, go back into the console and add it. The reCAPTCHA v3 keys are tied to the domains listed against them, so an address you forgot turns into a form that worked yesterday and does not today.

Why v3 Never Shows A Puzzle: The Score Threshold

reCAPTCHA v3 asks the visitor nothing. Instead it watches how the page is used and returns a score between 0.0 and 1.0 when the form is submitted, where 1.0 means "confidently a person" and 0.0 means "confidently a bot".

A score on its own decides nothing. Something has to pick the line, and on OxyPages it is already drawn for you: a submission scoring under 0.3 is refused, and Form Settings has no threshold box to change it.

0.3 is deliberately lenient, and the reason is worth knowing. v3 has no fallback. With a v2 checkbox or with Turnstile, a visitor the system doubts gets handed a check and can prove themselves. With v3 there is nothing to prove. A real customer who scores low just gets refused, gives up, and you never hear about the enquiry you lost.

Low scores land on ordinary people more often than you would think: a visitor on a VPN, a hardened privacy browser, a shared corporate network, or someone who pasted ready text from a clipboard and filled the form in three seconds. A strict threshold quietly walls all of them out.

The honeypot picks up the slack instead. A hidden decoy field is added to every form automatically, and a submission that fills it is still saved but marked as Spam, with no notification email. You see what was caught instead of trusting a score you cannot inspect.

Where The Keys Go, And What Your Page Needs

Where The Keys Go, And What Your Page Needs - OxyPages

Your reCAPTCHA v3 keys go on one page. Open the website's Forms page in your dashboard, then Form Settings, and fill three fields in order:

  1. Captcha Provider: select Google reCAPTCHA v3.
  2. Site Key: paste the key starting 6L.
  3. Secret Key: paste the secret. Form Settings never shows it again, so if you lose it, fetch it from Google's console.

Press Save Form Settings. From that moment published forms accept submissions. There is no republish step.

Now the page half. A form is wired up when it carries one attribute, and this is the whole file:

<!DOCTYPE html>
<html lang="en">
<head>
  <meta charset="utf-8">
  <meta name="viewport" content="width=device-width, initial-scale=1">
  <title>Contact</title>
</head>
<body>
  <h2>Contact us</h2>

  <form data-oxy-form="contact">
    <label for="name">Name</label>
    <input id="name" name="name" type="text" required>

    <label for="email">Email</label>
    <input id="email" name="email" type="email" required>

    <label for="message">Message</label>
    <textarea id="message" name="message" rows="5" required></textarea>

    <button type="submit">Send</button>
  </form>
</body>
</html>

Look at what is not in there. No reCAPTCHA script tag, no site key in the markup, no hidden token field, no action, no method. All of that is added when the page is served, using the keys you just saved, which is also why swapping providers later needs no edit to the page.

Two rules for the fields themselves. Every input, select and textarea needs a name attribute or its value is not captured. And file uploads are not supported: the contents are discarded and only the filename is recorded. Full detail is in adding a form.

Do not paste Google's own snippet on top of this. The injected script already loads Google's library and keeps a fresh token in the hidden field, because a token expires after about two minutes and forms sit open far longer. A second copy only gives the two something to argue about.

What To Check If Submissions Still Fail

Work down this list in order. The first two cover most cases:

  • "Forms Not Active": no keys are saved yet, or Turn Forms Off was pressed. Save the pair again.
  • "Couldn't Confirm You're Human" with JavaScript on: the address the form is served from is not registered with Google, or the saved keys belong to the other provider.
  • "Too Many Submissions": you have hit the hourly limit for one visitor, and testing your own form eats it fast. Wait, or test from another connection.
  • Nothing happens at all: the site is not published yet. Preview does not submit.
  • Entries arrive but no email: the entries are safe on the Forms page. That is a notification question, not a captcha one.

There is a fuller list in why a form is not working, and the daily submission caps for each plan are on the pricing page.

Let AI Do It For You

Google only hands the keys to a signed-in human, so that half stays manual. The page half does not. Paste this into the Code Editor AI, or any agent working on your files:

Add a working contact form to this page.

1. Insert an HTML form carrying the attribute data-oxy-form="contact".
2. Give every input, select and textarea a name attribute. Use name, email
   and message as a starting point.
3. Do NOT add any reCAPTCHA or Turnstile script tag, site key, hidden token
   field or honeypot field. The host injects all of that when the page is
   served, and a second copy of the library breaks it.
4. Do NOT set an action or a method on the form tag. Leave both off so the
   host can point the form at its own endpoint.
5. Do not add a file input. File uploads are not supported.
6. Match the styling of the rest of the page and keep the labels tied to
   their inputs with for and id.

Then remind me that the form stays inactive until I save a Site Key and a
Secret Key on the Form Settings page.

Then do the five-minute Google half yourself, save the pair, and load the live page to send yourself a test message. If it lands on your Forms page, you are done: nothing about your reCAPTCHA v3 keys needs touching again unless you add a domain.

FAQ

Do I Need A Google Account To Get The reCAPTCHA v3 Keys?

Yes. The reCAPTCHA admin console requires a signed-in Google account, with no way around it. A personal one works, though it now needs a Google Cloud billing account attached, and a shared team account is easier if more than one person will manage the site later.

Do The reCAPTCHA v3 Keys Cost Anything?

Up to a point, and the point moved on 2 April 2026. Free Essentials covers 10,000 assessments a month per organisation, not per site, and one submission is one assessment. Past that, Premium is about $8 a month up to 100,000 assessments.

Can I Change The Score Threshold?

No. The cutoff is fixed at 0.3 and Form Settings has no box for it, on purpose: v3 gives a wrongly judged visitor no way to appeal, so a lenient line plus a honeypot loses less real mail than a strict one does.

Can I Switch To Turnstile Later?

Yes, and it takes a minute. Pick Cloudflare Turnstile in Form Settings, paste its two keys and save. The new pair replaces your reCAPTCHA v3 keys, the page itself needs no edit at all, and every entry you have already collected stays exactly where it is.

Try It Now

Still Here? Drop It In.

The whole pitch fits in one sentence: your HTML, on a link, in seconds.

Drag and drop your HTML file(s), folders, or ZIP file

or ·

No account needed. Your unclaimed website stays live for 30 minutes on a free subdomain. Claim it to your account to keep it permanently.

  • No Account Needed
  • Free SSL
  • 30-Minute Unclaimed Link, Claim To Keep It