Acquia Documents CAPTCHA Controls for Experimental Drupal Canvas Forms

Monitor Mode Before CAPTCHA Enforcement
A wide turquoise Discover Drupal graphic pairs a browser and shield icon with a summary of CAPTCHA controls for experimental Drupal Canvas Forms. Text reads "DISCOVER DRUPAL. Drupal Canvas Forms. CAPTCHA controls for experimental forms. Acquia documents site wide provider settings staged enforcement honeypot protection signed tokens and rate limits. Follow us on. LinkedIn. Facebook. Reddit. X. https www.thedroptimes.com. THE DROP TIMES."

Source CMS administrators can configure a site-wide CAPTCHA layer for Drupal Canvas Forms. Acquia says in its product documentation that one provider and one enforcement mode apply to every Canvas form, with server-side CAPTCHA verification running after built-in spam controls. Acquia introduced Drupal Canvas Forms as an experimental feature on 16 July 2026.

The Monitor and Enforce modes let teams verify form setup before failed checks begin blocking submissions. Monitor logs verification results without rejecting requests, while Enforce rejects failed checks and submissions that omit the CAPTCHA token. Acquia says disabled or misconfigured CAPTCHA and provider outages do not block submissions on the CAPTCHA signal, while honeypot, rate-limit, and signed challenge-token protections continue to apply.

Acquia lists Cloudflare Turnstile, hCAPTCHA, Friendly CAPTCHA, and Google reCAPTCHA v3 as supported providers. For unauthenticated endpoints, Canvas Forms also uses a hidden honeypot, a single-use signed challenge token, and rate limiting, with a default of ten submissions per IP address every ten minutes. Generated starter code includes the CAPTCHA widget when protection is enabled. Hand-authored form components must import and render CanvasFormCaptcha.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Related Drupal Initiatives

Related Organizations

Upcoming Events