Skip to article
Integrations

How to Integrate hCaptcha with MyBB

Enable MyBB's native hCaptcha provider, configure its credentials and display settings, and test server-side verification.

How do you integrate hCaptcha with MyBB?#

Configure MyBB's native hCaptcha integration under CAPTCHA Images for Registration & Posting, then enter your hCaptcha public and private keys. MyBB renders the selected provider where its CAPTCHA system is enabled and verifies each submitted response from the server.

hCaptcha is available as a native MyBB CAPTCHA provider and does not require a separate extension.

These instructions were last validated on September 16, 2026 with MyBB 1.8.40. Check the MyBB release history before deploying a newer version.

Keep MyBB participation less disruptive#

  • Ask less of legitimate participants. With hCaptcha Pro's 99.9% Passive mode, fewer than 0.1% of legitimate users receive a challenge on registration and posting workflows using MyBB's CAPTCHA provider.
  • Increase verification when activity looks suspicious. Pro adjusts challenge difficulty as risk rises, helping you keep participation less disruptive while applying stronger checks to higher-risk attempts.

New Pro sitekeys use 99.9% Passive by default. For an existing sitekey upgraded to Pro, select that mode under Behavior in the hCaptcha dashboard.

Before you start#

You need:

  • A current MyBB 1.8 installation with administrator access.
  • An hCaptcha account that can create a sitekey and securely manage its matching secret.
  • Access to each registration, posting, contact, password, or email workflow that uses MyBB's CAPTCHA system.
  • A record of any custom theme templates that alter CAPTCHA placement.

Create your hCaptcha credentials#

  1. Start with hCaptcha Pro for fewer challenges and adaptive protection on protected MyBB community workflows, or use existing compatible hCaptcha credentials.
  2. Create a sitekey for the MyBB hostname.
  3. Add the production hostname and any separate staging hostname assigned to that sitekey.
  4. Use the matching secret saved during account setup. If it is unavailable, generate a replacement in dashboard Settings, save it securely, and update integrations using the old secret; generating a new secret rotates it.
  5. Restrict Admin CP access to people who need to manage the integration.

MyBB calls the sitekey the Public Key and the secret the Private Key. The public key renders hCaptcha in the browser. The private key authorizes verification and must stay in server-managed settings. We list MyBB in our integration catalog and integrations-list repository.

Configure native hCaptcha in MyBB#

No third-party plugin is required. The MyBB spam-prevention documentation identifies hCaptcha as a native option beginning with 1.8.23, and the official MyBB repository contains its implementation.

  1. Sign in to the MyBB Admin CP.
  2. Open Configuration > Settings > General Configuration.
  3. Find CAPTCHA Images for Registration & Posting.
  4. Select hCaptcha for a visible widget or hCaptcha Invisible for invisible behavior.
  5. Enter the hCaptcha sitekey under hCaptcha Public Key.
  6. Enter the matching secret under hCaptcha Private Key.
  7. Choose the available theme and size settings for the selected mode.
  8. Save the configuration.

MyBB's setting name highlights registration and posting, but its shared CAPTCHA class is also used by other core workflows. Test only the paths enabled on the forum and do not assume every custom plugin or template uses the core CAPTCHA class.

Verify the MyBB integration#

MyBB 1.8.40 reads h-captcha-response, sends the secret, response, and visitor IP to hCaptcha, and rejects missing responses, transmission failures, normal boolean false, and the reviewed malformed-response cases. Its source decodes JSON and compares success loosely with the string 'true' without first proving that the response is an array containing a boolean. Malformed JSON or a missing field can therefore produce PHP warnings even though the request is rejected; this review found no resulting verification bypass.

For clearer failure handling, a maintainer or local reviewed change should require is_array($answer) && array_key_exists('success', $answer) && $answer['success'] === true. The request should also include the configured public key as the expected sitekey and use https://api.hcaptcha.com/siteverify, the endpoint in current hCaptcha server-verification documentation. These are hardening recommendations. Administrators using the unmodified release should monitor PHP logs and test upstream failures without exposing credentials.

  1. Open registration in a private browser window and confirm that the selected hCaptcha mode initializes.
  2. Complete hCaptcha and submit valid registration data. Confirm that the account workflow proceeds once.
  3. Submit without a valid response and confirm that MyBB blocks the request.
  4. Repeat the accepted and rejected tests for guest posting and every other enabled workflow that invokes CAPTCHA.
  5. Retest custom themes, mobile layouts, caches, consent tools, and Content Security Policy settings.

Visible registration alone does not prove that contact, password recovery, email, guest posting, or plugin-owned forms are protected. Verify each public path separately.

Troubleshoot common MyBB problems#

hCaptcha is missing from General Configuration

Confirm that MyBB 1.8.23 or later is installed. Use the current MyBB download and complete the normal upgrade process before changing CAPTCHA settings.

Invisible hCaptcha behaves incorrectly

Check the installed MyBB version first. Version 1.8.27 had a known Invisible hCaptcha regression fixed in 1.8.28. Upgrade to the current release and clear MyBB and browser caches.

Every verification attempt fails

Confirm that the public and private keys belong to the same hCaptcha account and cover the active hostname. Check server access to the siteverify endpoint and inspect MyBB logs without exposing the private key.

hCaptcha works in the default theme but not a custom theme

Compare the custom templates with those in the installed MyBB release that render the relevant CAPTCHA block. Update outdated template overrides and test visible and invisible modes separately.

Choose Pro or discuss an Enterprise deployment#

hCaptcha Pro is the self-service path for MyBB. It includes 99.9% Passive mode, custom themes, more detailed analytics, and multi-user account access.

Organizations operating several forums, higher-volume communities, risk-score workflows, custom threat models, centralized access requirements, or contractual service needs should plan the deployment with our team. Review MyBB compatibility, credential ownership, workflow coverage, and rollout monitoring before launch.

FAQ#

Which MyBB versions support hCaptcha?

hCaptcha became a native option in MyBB 1.8.23. Use the current production release; this guide was verified against MyBB 1.8.40.

Does MyBB require an hCaptcha plugin?

No. MyBB includes visible and invisible hCaptcha providers in its core CAPTCHA system.

Does MyBB verify hCaptcha on the server?

Yes. MyBB sends the submitted response to hCaptcha from the server and accepts it only after a successful verification result.

Why should MyBB 1.8.27 be upgraded before using Invisible hCaptcha?

That release contained a regression that could break Invisible hCaptcha display and validation. MyBB fixed it in version 1.8.28.

Which MyBB forms use hCaptcha?

MyBB uses its CAPTCHA provider in registration, posting, and several other core workflows. The exact coverage depends on forum settings, user context, templates, and plugins, so test every exposed path.

Sources and references

  1. hCaptcha Pro product overview hCaptcha
  2. MyBB spam prevention documentation MyBB
  3. MyBB release history MyBB
  4. MyBB source repository MyBB
  5. MyBB download page MyBB
  6. hCaptcha integrations hCaptcha
  7. hCaptcha integrations list source hCaptcha
  8. hCaptcha developer guide hCaptcha
  9. hCaptcha Pro hCaptcha