# POST /websites/:website_id/turnstile

**Resource:** [Websites](./websites.md)  
**MCP tool:** `create_website_turnstile`  
**Scopes:** `websites:write`  
**Write operation:** yes

Set up bot protection (Turnstile) for a website: creates a bot-protection widget scoped to the site's domain and enables verification on its public forms. The website needs a domain or a deployed URL first. Optional mode: managed (default, shows a checkbox when the visitor looks suspicious), non-interactive (near-invisible, no checkbox), invisible (fully invisible).

## Parameters

| Name | In | Type | Required | Description |
|------|----|------|----------|-------------|
| `website_id` | path | string | yes |  |
| `mode` | body | string | no | Widget interaction mode. Defaults to managed. |
| `require_approval` | body | boolean | no | Optional. Set true to route this write into the approval queue for human review instead of executing it immediately (returns 202 + an approval_id). Works even when your key/token has permission to execute directly. |

## Request example

```bash
curl -X POST   "https://api.trustpager.com/functions/v1/api/v1/websites/:website_id/turnstile"   -H "Authorization: Bearer YOUR_API_KEY"   -H "Content-Type: application/json"   -d '{"mode":"..."}'
```

---
Base URL: `https://api.trustpager.com/functions/v1/api/v1` — Auth: `Authorization: Bearer YOUR_API_KEY`