Skip to article
Integrations

How to Integrate hCaptcha with Invision Community

Enable Invision Community's native hCaptcha provider, configure its sitekey and secret, and verify registration, guest posting, contact, and dialog workflows.

How do you add hCaptcha to Invision Community?#

Configure Invision Community's native hCaptcha integration under its Spam Prevention settings, then enter the matching sitekey and secret. Invision renders and verifies the native provider on workflows where its CAPTCHA system is enabled.

Native hCaptcha arrived in Invision Community 4.7.0. It replaced the need for the older marketplace hCaptcha Integration plugin still linked by the hCaptcha catalog. Do not install that legacy plugin on a current Invision Community site unless Invision Support explicitly directs you to it.

This guide covers the native hCaptcha provider in Invision Community 4.7 and 5. Invision plans to end version 4 support on December 31, 2026.

These instructions were last validated on September 21, 2026 with Invision Community 4.7.25 and version 5 release documentation.

Make joining and participating in Invision easier#

  • Ask less of legitimate participants. With hCaptcha Pro's 99.9% Passive mode, fewer than 0.1% of legitimate users receive a challenge on registration, guest posting, and contact workflows where CAPTCHA is enabled.
  • Increase verification when activity looks suspicious. Pro adjusts challenge difficulty as risk rises, helping you keep participation less disruptive while applying stronger checks to higher-risk attempts.

New Pro sitekeys use 99.9% Passive by default. For an existing sitekey upgraded to Pro, select that mode under Behavior in the hCaptcha dashboard.

Prepare the community and credentials#

  1. Update to a supported Invision Community release and review installed application and theme compatibility.
  2. Start with hCaptcha Pro for fewer challenges and adaptive protection on protected Invision member and guest workflows, or use existing compatible hCaptcha credentials.
  3. Create a sitekey for the community's production hostname and any separate test hostname.
  4. Retrieve the matching hCaptcha account secret and limit AdminCP access to administrators who manage security settings.
  5. List the public workflows that currently require CAPTCHA, including registration, guest posting, Contact Us, and any application-owned forms.

The sitekey can appear in browser markup. The secret authorizes server-side verification and must remain in Invision's server-managed configuration.

Enable native hCaptcha#

For Invision Community 4.7, the official administration guide uses this path:

  1. Sign in to the AdminCP.
  2. Open Members > Content Moderation > Spam Prevention.
  3. Select the CAPTCHA tab.
  4. Choose hCaptcha as the CAPTCHA service.
  5. Enter the hCaptcha sitekey and secret in the displayed key fields.
  6. Save the settings.

Invision Community 5 retains hCaptcha, but public version 5 administration documentation does not currently provide an equivalent field-by-field page. Use AdminCP search for “CAPTCHA” or “Spam Prevention,” confirm the labels in the installed release, and have an Invision 5 administrator verify this path before deployment.

The CAPTCHA setting controls Invision's core CAPTCHA service. It does not prove that every third-party application, custom controller, theme override, or externally hosted form invokes that service.

Verify each protected workflow#

  1. Open registration in a private browser window and confirm hCaptcha appears and completes.
  2. Submit a valid registration and confirm the account workflow proceeds once.
  3. Submit registration without a valid response and confirm Invision blocks it.
  4. Repeat successful and failed-token tests for guest posts and the Contact Us form when those features are enabled.
  5. Test forms displayed inside dialogs. Invision 5.0.17 included a fix for hCaptcha rendering in dialogs, so older version 5 installations need particular attention.
  6. Repeat the checks with the active theme, mobile layout, consent tooling, caching, and Content Security Policy.

Invision's 4.7 announcement also describes hCaptcha on registration, while its 4.7.0 release notes specifically name Contact Us and guest posts. Treat actual coverage as a property of the installed version, enabled applications, user permissions, and form implementation. Test every exposed path individually.

Troubleshoot common problems#

hCaptcha is not available in the provider list

Confirm that the community is running Invision Community 4.7.0 or later. Upgrade through Invision's supported process. Do not use the old plugin as a substitute for an unsupported core version.

The challenge does not appear in a dialog

Confirm the exact Invision Community 5 release. Version 5.0.17 included a dialog-rendering fix. Update to a patched release, clear applicable caches, and retest the dialog with the active theme.

Every submission fails

Confirm that the sitekey and secret are a matching pair and that the sitekey covers the active hostname. Check outbound connectivity to hCaptcha without logging the secret, submitted token, or complete verification response.

Some forms have no hCaptcha

Confirm that the workflow uses Invision's core CAPTCHA service and that its settings require CAPTCHA for the current user context. Third-party applications and custom forms may need their own supported integration.

Frequently asked questions#

Does current Invision Community require an hCaptcha plugin?

No. hCaptcha has been a native provider since Invision Community 4.7.0. The older marketplace plugin is superseded for current installations.

Does Invision Community 5 still support hCaptcha?

Yes. Current version 5 release information includes hCaptcha maintenance, including a rendering fix in 5.0.17. Confirm the current AdminCP labels in the installed release.

Which Invision workflows can use hCaptcha?

Official Invision material identifies registration, Contact Us, guest posting, and other areas that invoke the core CAPTCHA service. Exact coverage depends on the installed version, settings, applications, permissions, and themes.

Should I keep Invision Community 4?

Invision says version 4 support ends December 31, 2026. Plan the version 5 migration separately and retest every hCaptcha workflow after upgrading.

Can I reuse an hCaptcha response token?

No. hCaptcha response tokens are short-lived and single-use. Each protected submission needs a fresh response that Invision verifies server-side.

Sources and references

  1. hCaptcha Pro product overview hCaptcha
  2. hCaptcha integrations — Invision Community hCaptcha
  3. Legacy hCaptcha Integration marketplace entry Invision Community
  4. Invision Community spam prevention guide Invision Community
  5. Invision Community release notes Invision Community
  6. Invision Community 5 release notes Invision Community
  7. Verify the hCaptcha response server-side hCaptcha
  8. hCaptcha Pro hCaptcha
  9. hCaptcha integrations list source hCaptcha