- Requesting an email or SMS OTP: captcha is required when the code is sent, covering both signup and login flows.
- Creating a new account (sub-organization): captcha is required during signup via passkey, OAuth / social login, or external wallet.
Enabling Captcha
Captcha protection is configured at the organization level in the Turnkey Dashboard. Once enabled, it is automatically enforced for the protected flows.1
Open your Embedded Wallets Configuration
Log in to the Turnkey Dashboard and navigate to Configuration for Embedded Wallets.
2
Find the Captcha toggle
Locate the Captcha setting in the Auth Proxy section.

3
Enable Captcha
Toggle the setting on and save your changes. Captcha protection is now active for your organization.
Changes take effect immediately. Protected flows initiated through
@turnkey/react-wallet-kit will display the Turnstile widget.Integration guides
How much work Captcha takes depends on which SDK renders your auth UI:
In every case the mechanics are the same: Turnstile runs its challenge when a user initiates a protected flow, issues a token on success, and Turnkey verifies that token before creating any auth activity. Requests that fail the challenge are rejected outright.