Requires the Starter plan or above.
When to use which
Managed
You want protection turned on today, don’t care which specific provider handles it, and don’t want an account with a third party.
Bring your own keys
You already use Turnstile/hCaptcha/reCAPTCHA elsewhere, want your own provider-side analytics/dashboard for this form’s traffic, or need a specific provider for compliance reasons.
Setting it up
1
Open Spam Protection settings
From your form’s settings, find Spam Protection.
2
Turn on CAPTCHA
Toggle it on. Don’t select or connect a provider — leaving it unconnected is what makes this Managed rather than bring-your-own-keys.
3
Choose a widget mode (optional)
Same
invisible/checkbox choice described on the Turnstile page — invisible by default.submit.js acquire a token exactly the same way they would for a self-managed hCaptcha integration; from your integration’s perspective, Managed and bring-your-own-keys hCaptcha are indistinguishable.