Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Google reCAPTCHA integration has two parts: the browser obtains a token, then your Spring Boot server sends that token and its secret to Google for verification before processing the protected request. Keep the secret server-side, and treat the verification response—not the presence of a browser token—as the decision point.
How the reCAPTCHA flow works
- The browser loads Google’s reCAPTCHA JavaScript. A v2 form renders a widget; a v3 form requests a token for a named action.
- The browser submits the token with the form or API request. You can call the field
recaptchaTokenin a request DTO. - Spring Boot sends a form URL-encoded POST containing
secretandresponseto Google’s verification endpoint. Theremoteipparameter is optional. - Your application parses the JSON result and permits business processing only if the relevant checks pass.
A client-side token is not proof of a human user by itself. It is an input to the server-side verification step.
Choose v2 or v3 for the form
| Option | Browser experience | Server decision | Recovery |
|---|---|---|---|
| v2 checkbox | Visible “I’m not a robot” checkbox; suspicious traffic may receive a challenge. | Binary verification, including checking success and expected hostname. | Let the user complete or retry the challenge. |
| v2 invisible | Invoked from an existing button or JavaScript callback; a challenge appears only when traffic seems suspicious. | Binary verification, including checking success and expected hostname. | Allow the user to respond to a challenge and retry. |
| v3 | No challenge by default. Execute reCAPTCHA when the protected action occurs, naming that action. | Check success, hostname, expected action, and a score threshold chosen for that endpoint. | Use a proportionate response such as step-up authentication, email verification, moderation, or throttling for low scores. |
Choose a v2 option if an explicit challenge is acceptable and a straightforward pass/fail gate fits the form. Choose v3 when you want a risk signal that lets the application vary its response. Google describes v3 scores from 0.0 (very likely a bot) to 1.0 (very likely a good interaction); 0.5 is an illustrative starting threshold, not a universal cutoff. Tune the threshold against your own traffic and the consequences of abuse.
Register keys and configure hostnames
- Register the site with Google to obtain a site key and secret key. Put the site key in browser-rendered HTML; store the secret in an environment variable or secret manager. Google says the secret authorizes backend verification and must be kept safe. See Google’s key introduction.
- Register the production hostnames that will serve the form. Add
localhostfor local development. Google warns that disabling domain validation creates significant risk; if you disable it, enforce a server-side hostname allowlist. See Google’s domain validation guidance.
Collect a token in the browser
For v2
Render the v2 widget in the form and include its g-recaptcha-response value with the submitted form data. The widget handles the user interaction; your application still must send the resulting token to Google from the backend.
Recommended Free Tools
#1 Best Overall
- KEYBOARD: The keyboard works for Windows with hot keys that enable easy access to Media, My Computer, Mute, Volume up/down, and Calculator
- EASY SETUP: Experience simple installation with the USB wired connection
- VERSATILE COMPATIBILITY: This keyboard is designed to work with multiple Windows versions, including Vista, 7, 8, 10 offering broad compatibility across devices.
- SLEEK DESIGN: The elegant black color of the wired keyboard complements your tech and decor, adding a stylish and cohesive look to any setup without sacrificing function.
- FULL-SIZED CONVENIENCE: The standard QWERTY layout of this keyboard set offers a familiar typing experience, ideal for both professional tasks and personal use.
For v3
Load the API with your site key, then request a token when the user performs the protected action. For example:
<script src="https://www.google.com/recaptcha/api.js?render=SITE_KEY"></script>
<script>
grecaptcha.ready(function () {
grecaptcha.execute('SITE_KEY', { action: 'submit' }).then(function (token) {
// Include token with the form or API request.
});
});
</script>
Replace SITE_KEY with the public site key and send the token immediately with the relevant request. If the script loads asynchronously, wait for grecaptcha.ready() or use an onload callback before calling reCAPTCHA. Google’s v3 setup and response guidance is at the v3 documentation; script loading guidance is at the loading documentation.
Rank #2
- Reliable Plug and Play: The USB receiver provides a reliable wireless connection up to 33 ft (1), so you can forget about drop-outs and delays and you can take it wherever you use your computer
- Type in Comfort: The design of this keyboard creates a comfortable typing experience thanks to the low-profile, quiet keys and standard layout with full-size F-keys, number pad, and arrow keys
- Durable and Resilient: This full-size wireless keyboard features a spill-resistant design (2), durable keys and sturdy tilt legs with adjustable height
- Long Battery Life: MK270 combo features a 36-month keyboard and 12-month mouse battery life (3), along with on/off switches allowing you to go months without the hassle of changing batteries
- Easy to Use: This wireless keyboard and mouse combo features 8 multimedia hotkeys for instant access to the Internet, email, play/pause, and volume so you can easily check out your favorite sites
Verify the token in Spring Boot
1. Validate the incoming request
Add a token field such as recaptchaToken to the request DTO. Reject a missing or blank value before business logic runs. Never log the token or secret.
2. Post to Google from a service
Keep verification in a service called by the controller or application service before persistence or other protected work. Use Spring’s WebClient or RestClient to send a form URL-encoded POST to https://www.google.com/recaptcha/api/siteverify, with secret and response as parameters. You may include remoteip if appropriate. Keep the secret in server configuration rather than hard-coding it. Set short connection and response timeouts, and treat network failure as verification failure or follow a controlled retry path; do not silently skip verification.
Rank #3
- All-day Comfort: The design of this standard keyboard creates a comfortable typing experience thanks to the deep-profile keys and full-size standard layout with F-keys and number pad
- Easy to Set-up and Use: Set-up couldn't be easier, you simply plug in this corded keyboard via USB on your desktop or laptop and start using right away without any software installation
- Compatibility: This full-size keyboard is compatible with Windows 7, 8, 10 or later, plus it's a reliable and durable partner for your desk at home, or at work
- Spill-proof: This durable keyboard features a spill-resistant design (1), anti-fade keys and sturdy tilt legs with adjustable height, meaning this keyboard is built to last
- Plastic parts in K120 include 51% certified post-consumer recycled plastic*
3. Check the response before processing
Google’s verification response contains success and may include fields such as challenge_ts, hostname, score, action, and error codes. The verification documentation, last updated 2024-10-14 UTC, specifies secret and response as required POST parameters and remoteip as optional: Verify the user’s response.
- Require
success=true. - For v2, compare the returned
hostnamewith the hostnames your application permits. - For v3, also require the expected
actionand compare the returned score with a threshold appropriate to that endpoint. - Reject missing or unexpected response values rather than treating them as a pass.
A minimal Java design separates configuration-bound secret storage, a verification service, a response record or DTO, and the controller or service that gates business processing. The exact Spring API differs between WebClient and RestClient; tests should mock the outbound verification boundary rather than depend on live calls to Google.
Rank #4
- 【Lag-free & Efficient】Stable and reliable connection of wireless keyboard and mouse is up to 10m(33ft). This combo share a nano USB receiver, no need to take up additional USB ports (Also the wireless keyboard and mouse can also be used separately). Plug and play, no software needed,convenient and efficient.
- 【Quiet & Type in Comfort】Wireless keyboard come with adjustable height tilt legs to increase comfort and prevent your wrists injury when typing for a long time.Our wireless keyboard adopts a silent structure. Soft membrane keys provide a quiet and comfortable typing experience.The wireless mouse is quiet without any clicking sound also.So whether at home or in the office, you can use this combo as you please without worrying about disturbing others.
- 【Full Size Keyboard】This keyboard saves desktop space while retaining its full size.The full size wireless keyboard with numeric keypad and 12 multimedia shortcut keys, such as play/ pause, volume increase and decrease, and search, to help you improve work efficiency.
- 【Auto Power Saving Function】Wireless keyboard and mouse have a smart auto-sleep mode to save power for long battery life. They will enter sleep mode after stop using a while(Refer to the instructions for details). Unplug the receiver or after the PC shutdown, they will enter sleep mode too.You can press any keys to wake. (battery life may vary based on user and computing conditions)
- 【Comfortable Optical Mouse】This silent wireless mice provides 3 adjustable DPI (800/1200/1600) to meet your different needs in terms of sensitivity.The compact lightweight design of wireless mouse and a hand-friendly contoured shape for all-day comfort, and smooth, precise tracking. Very suitable for office and daily use.
Handle expiry, replay, and failures
Google states that each response token is valid for two minutes and can be verified only once. Generate v3 tokens at submission time, not when the page first loads. If Google returns timeout-or-duplicate, ask the user to retry with a fresh token rather than resubmitting the old one. See Google’s token verification guidance.
Give users a clear form error and a way to retry when verification fails or the verification service is unavailable. A transient outage must not turn into a successful protected operation. Keep the experience accessible and avoid making the user guess whether the form was submitted.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- A plug-and-play USB connection with Low-profile keys give you a quiet, comfortable typing experience
- Simple Wired USB Connection,You will enjoy a comfortable and quiet typing experience
- The keyboard for business and office working is the budget-friendly keyboard that is built for longer use
- Low profile keys for a more comfortable and quiet keystroke, desktop-centric design, splash resistant
Apply the check at the right boundary
Gate the relevant operation consistently at its controller or service boundary—for example, login, registration, password reset, contact, or purchase flows where abuse is a concern. reCAPTCHA is an abuse signal, not a replacement for authentication, authorization, or rate limiting. For v3, a low score can trigger a proportionate additional check instead of an automatic blanket denial.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

