Api.SignInWithEmail and Api.SignInWithPhone only take the identifier and the password, and every password SignIn in Client and StatelessClient goes through them, so there is no way to send a captcha token.
await client.SignIn(email, password);
// POST /token?grant_type=password with only email and password in the body
With CAPTCHA protection on, the server checks this grant too (isIgnoreCaptchaRoute), so password sign-in is rejected. Sign-up has the same gap in #213.
auth-js takes a captcha token on password sign-in, and so do the other SDKs.
Api.SignInWithEmailandApi.SignInWithPhoneonly take the identifier and the password, and every passwordSignIninClientandStatelessClientgoes through them, so there is no way to send a captcha token.With CAPTCHA protection on, the server checks this grant too (
isIgnoreCaptchaRoute), so password sign-in is rejected. Sign-up has the same gap in #213.auth-js takes a captcha token on password sign-in, and so do the other SDKs.