Skip to content

CAPTCHA and self-registration

Two related features control how new customer accounts appear on your platform:

  • Self-registration: visitors who are not logged in can open the register page and create their own account, instead of waiting for you to create it.
  • CAPTCHA: a prove-you-are-human challenge on the login and registration forms that blocks automated sign-up scripts.

Both are off by default. Both live on the same settings tab.

In the admin panel go to System > Settings and open the Security tab. The User Registration and Bot Protection (CAPTCHA) sections hold everything on this page.

Settings, Security tab

  1. In the User Registration section, turn the switch on.
  2. Save.

While self-registration is off, visitors who open the register page are redirected away, and the login form shows no sign-up link. You can still create customers yourself under Customers > Users. While it is on, the public form is reachable, so also turn on CAPTCHA protection for the registration form (below).

Every self-registered account must verify its email address before it can deploy anything: the panel sends a signed link, and the account waits on the verify page until the visitor clicks it. Email verification is mandatory and cannot be turned off; it raises the cost of throw-away sign-ups. New customers land on their dashboard with a nudge to add credit before deploying.

  1. In the Bot Protection (CAPTCHA) section, turn the switch on.
  2. Pick one Provider:

Providers

Provider What the visitor sees Where you get the keys
Cloudflare Turnstile A small verifying pill that usually resolves on its own Cloudflare dashboard, Turnstile
Google reCAPTCHA v2 The classic checkbox, sometimes followed by an image grid Google reCAPTCHA admin console
Google reCAPTCHA v3 Nothing visible; the provider scores the visitor from 0.0 (bot) to 1.0 (human) Google reCAPTCHA admin console

You cannot mix providers. The one you pick protects every form where CAPTCHA is turned on.

  1. Paste the Site Key (public, embedded in the page) and the Secret Key (private, used server-side to verify). Never swap the two. The secret key is stored encrypted; leaving it masked on save keeps the current value.
  2. For reCAPTCHA v3 only, set the Score threshold: the minimum score the panel accepts, between 0.0 and 1.0. Default is 0.5. Raise it if you see bot traffic, lower it if real users are blocked.
  3. Under Apply on, choose the Login form, the Registration form, or both.
  4. Save.

Click Test Connection in the CAPTCHA section. It runs a one-shot server-side check against your secret key and shows the provider’s reply. A success message means real visitors who pass the challenge will be accepted. An explicit provider error usually means a wrong or mistyped secret key, or that the management server cannot reach the provider over the internet. The test never blocks real visitors; it is a sanity check only.

Self-registered customers appear under Customers > Users like any other customer. Accounts that have not clicked the verification link yet are marked unverified and cannot deploy until they verify. From a customer’s page you can resend the verification email or flip the status by hand when the email never arrives. See Manage users.

  • Every sign-up fails verification. Click Test Connection. The usual causes are a secret key pasted with a leading or trailing space, a mismatched site key and secret pair, or a domain not registered with the provider.
  • The verification email never arrives. Confirm outgoing mail works under System > Settings on the Mail tab, ask the visitor to check spam, and use Resend verification email on their user page. Brand-new sender domains are often flagged at first.
  • reCAPTCHA v3 rejects real users. Lower the score threshold by 0.1 at a time. Fresh deployments with little traffic history score legitimate first-time visitors low.
  • Self-registration is on but the register page still redirects away. Settings are cached briefly after you save. Hard-reload the page and confirm the switch reads enabled in the User Registration section.