derekcodes-io/
turnstile-laravel
g4t.io

Cloudflare's Turnstile Captcha for Laravel

by Paul Redmond

The turnstile-laravel package integrates Turnstile's Captcha verification API with Laravel applications.

README from derekcodes-io/turnstile-laravel Open on GitHub →

Cloudflare's Turnstile For Laravel

A Laravel package to facilitate the server side validation of Cloudflare's Turnstile captcha service.

GitHub release GitHub repo size Packagist Downloads

Configuration

First you'll need an account Cloudflare and Turnstile setup for your website.

https://developers.cloudflare.com/turnstile/

Installation

Install via composer

composer require derekcodes/turnstile-laravel 

Adding your secret key in the .env file

TURNSTILE_SITE_KEY="0x4AAAAAAAXXXXXXXXXXXXXX"
TURNSTILE_SECRET_KEY="0x4AAAAAAAXXXXXXXXXXXXXX"

Create a config/turnstile.php

php artisan vendor:publish --tag=turnstile-config

Front-end

Be sure to add the front-end JavaScript from Turnstile: https://developers.cloudflare.com/turnstile/get-started/client-side-rendering/

To save you some time, here's the Turnstile JavaScript necessary for an HTML form. Note that I assume you're using a Blade template, thus the {{ config('turnstile.site_key') }}.

<script src="https://challenges.cloudflare.com/turnstile/v0/api.js?onload=onloadTurnstileCallback" defer></script>

window.onloadTurnstileCallback = function () {
    turnstile.render('#your-form-id', {
        sitekey: '{{ config('turnstile.site_key') }}',
        callback: function(token) {
            console.log(`Challenge Success ${token}`);
        },
    });
};

Usage

Add the use statement at the top of your file

use DerekCodes\TurnstileLaravel\TurnstileLaravel;

Initiate the TursileLaravel object and call the validate method passing the client response Turnstile's JavaScript provides

$turnstile = new TurnstileLaravel;
$response = $turnstile->validate($request->get('cf-turnstile-response'));

Ensure the response is valid

if (get_data($response, 'status', 0) == 1) {
  // TODO: add success code here
}

Responses

Example success response

{
  "status": 1
}

Example error response

{
  "status": 0,
  "turnstile_response": {
    "success": false,
    "error-codes": [
      "invalid-input-response"
    ],
    "messages": []
  }
}

Credits

~ Derek Codes

Derek Codes is a comprehensive collection of tutorials on the most popular languages in the industry. You’ll find videos, guides and downloadable assets to help you learn to code PHP, Laravel, JavaScript, CSS and more. Thanks for watching!

More from the ecosystem

marcreichel/
laya-php
g4t.io
3 53

LayaPHP: Self-Hosted Text Classification for PHP and Laravel

Classify text in PHP without an LLM bill: typed decisions in 100+ languages, self-hosted. Laravel-ready SDK for Laya, a Jev AI alternative.

ai classification decision-engine
marcreichel/laya-php via Laravel News
Josh-Dovey/
postcodes-laravel
g4t.io
5 9

Postcodes for Laravel: GB Postcode Lookup and Geography Data

Postcodes for Laravel adds typed GB postcode lookups, validation, geography data, distance searches, and test fakes through the GB Postcodes API.

Josh-Dovey/postcodes-laravel via Laravel News
RedberryProducts/
mailbox-for-laravel
g4t.io
4 115

Mailbox for Laravel: Preview and Test Rendered Email

Mailbox for Laravel captures outgoing mail in a local dashboard and lets you test rendered HTML, recipients, and attachments with fluent assertions.

RedberryProducts/mailbox-for-laravel via Laravel News