The Captcha Locker Explained: Where to Use It and How to Set One Up

Every other locker takes over the screen. The Captcha locker sits inside your page in a 330 pixel box and waits to be clicked. It is the easiest ToroAds locker to install, the least disruptive one to run, and on mobile it is usually the one that earns the most. Here is what it is, where it belongs, and how to build one.

The Captcha Locker Explained: Where to Use It and How to Set One Up
A
Admin
Published August 10, 2026

Every other locker on ToroAds interrupts the page. The overlay template dims your site and opens on top of it. The full page template covers the screen entirely and hides your content behind it. Both work, and both make the same demand of the visitor: deal with me now, or leave.

The Captcha locker makes no such demand. It renders inside your layout, in a box roughly 330 pixels wide, in the exact spot you put it. Your page stays visible, scrollable and usable the whole time. That sounds like a cosmetic difference. It is not. It changes who stays on the page, and it is the reason this template is the easiest one to install and, on mobile traffic, frequently the one that earns the most.

What the Captcha locker actually is

ToroAds ships eleven locker templates. Ten of them are overlay or full page. The Captcha template is the only inline one: it is injected directly into your own markup, with no iframe anywhere in the flow.

What the visitor sees is a small light box containing a checkbox and a short label. The interaction is deliberately the one that every person on the internet has already performed a thousand times: click the box, wait a moment, carry on. There is no instruction to read and no new interface to learn, which is the whole point. Friction at the first click is where lockers lose most of their traffic, and this template starts with almost none.

Be precise with yourself about what that box is, though. It is a monetisation widget wearing a familiar shape. It does not test the visitor, it does not screen bots, and it is not a security control. Ticking it simply opens the offer panel.

Say what it is on your own page. Label the widget honestly in your surrounding copy: "complete one offer to unlock". Presenting it to visitors as a security check you do not actually run is the kind of thing that costs publishers their traffic sources, and it buys you nothing that plain wording does not.

What a visitor actually does

The full flow, end to end:

  1. They click the checkbox. It shows a brief checking state.
  2. A panel opens anchored underneath the widget, listing a handful of offers filtered to their country and device.
  3. They select one. The Verify button becomes active.
  4. They press Verify. The advertiser's page opens in a new tab, so your page is never navigated away from.
  5. They complete the offer. Meanwhile the widget stays on your page, checking with the platform every ten seconds and showing progress.
  6. The advertiser confirms the conversion. The widget flashes a green tick and then removes itself from your page entirely.

That last step is worth sitting with. On an inline locker, removing the widget is the reveal, because the thing being unlocked is your own page. There is no modal to dismiss and no redirect to wait through. The gate is simply gone.

Two behaviours in that flow matter for your copy. The new tab means a visitor never loses their place on your site. The ten second polling means unlock is not instant: it waits on the advertiser's postback. A page that says "verifying, this can take a moment" keeps far more visitors than one that appears frozen.

Where to put one

The Captcha locker suits any page where you want to charge for something without evicting the visitor from the page while they decide.

  • Download and file pages. Put the widget where the download button would be. The visitor already came for the file, so the intent is there before the widget loads.
  • Mid-article unlocks. A walkthrough, a full parts list, a config file, the second half of a guide. Drop the container inline at the cut point.
  • Online tools and generators. Show the input form, run the calculation, put the widget in front of the result.
  • Mobile-heavy pages. This is the strongest case. Overlays on small screens cover everything, look like popups, and get dismissed by reflex. An inline widget on the same page just sits there.
  • WordPress and other CMS sites. The script tag goes in via any header and footer plugin, and the container div goes into the post body. No theme editing.
  • Sidebars and end of post slots, where an overlay would be wildly disproportionate to what is on offer.

Where it does not work is exactly where no locker works: pages the visitor did not come to with a specific want. Your homepage, category pages, and anything a search engine needs to read. A locker converts existing demand. It does not create any.

Why it out-earns the alternatives

You are paid for an action, not for attention. A banner earns you a few dollars per thousand impressions. A locker conversion is a completed advertiser action, and a page with genuine intent produces those at double digit rates. Display advertising monetises the top of your funnel; a locker monetises the bottom.

Ignoring it costs you nothing. This is the advantage that is unique to the inline template. The Captcha widget never dims your page and never blocks clicks on it, by design. A visitor who is not interested keeps reading, keeps browsing, and often comes back to the widget on the way out. Compare that with an overlay, where "not interested" and "gone" are the same action.

There is nothing to learn. The checkbox pattern is universally understood. Every second a visitor spends working out what an interface wants is a second they can spend closing it instead.

No iframe means no layout fights. The widget mounts into your own markup inside a shadow root, so your CSS and its CSS cannot collide, and it flows with your page instead of floating over it. It is also promoted to the browser's top layer when the offer panel opens, so no parent container with overflow: hidden can clip it.

Mobile actually works. Most publishers see mobile as the majority of their locker traffic and the minority of their locker revenue. Removing the overlay is the single biggest thing you can do about that gap.

Setting one up in ToroAds

Go to Content Locker in your dashboard and hit Create. It is a three step wizard.

Step 1: Setup. Name the locker, then pick the Captcha template from the picker. Its type label reads "Inside your page", which is the fastest way to confirm you have the inline one. Then choose an unlock action: Remove locker, which deletes the widget and leaves your page in place, or Redirect, which sends the visitor to a URL you supply. For an inline widget on a page that already holds the content, Remove locker is almost always correct.

Turn on Remember Unlock if you do not want a returning visitor to face the widget again. When it is off, an unlock is only remembered for three minutes, which is just enough to survive a refresh or a dropped connection.

Step 2: Offers. This is where the earnings are decided.

  • Min and max offers, how many cards the panel lists. Defaults are 1 and 4.
  • Conversions required, how many approved conversions unlock the content. Default 1, maximum 10.
  • Access time, how long an unlock lasts when Remember Unlock is on. Default 24 hours, from 60 seconds up to 30 days.
  • Performance strategy, weighted to rotate offers by trailing seven day EPC, or equal to show them evenly.
  • Preferred offer type, set separately for mobile and desktop: all, CPI, CPA or PIN.
  • Load delay, in seconds, if you want the widget to appear a beat after the page. Note that the load method setting does not apply to inline templates: the Captcha widget always mounts itself on DOM ready. Only the delay is honoured.

Step 3: Customize. The Captcha template exposes eight fields, and the live preview beside them updates as you type: accent colour, widget background, headline, progress text, popup header text, a logo URL, a header background image URL, and free-form custom CSS. There is also a page title for the browser tab. Keep the accent colour close to your site's own, then leave the rest alone until you have a week of data.

Then install it. Open the locker and choose your domain at the top of the embed panel. If you have added a custom domain, use it: a hostname your audience recognises converts better than a shared one, and it accumulates only your reputation rather than everybody's.

Copy the script tag onto your page, anywhere:

<script src="https://your-domain.com/cl/js/YOUR_URLCODE"></script>

Then put the container exactly where you want the widget to appear:

<div id="captcha-locker"></div>

That is the whole integration. No toro_load() call is needed, because the widget auto embeds on page load whenever it finds that container. If you would rather use your own element id, call the loader yourself:

<div id="my-locker"></div>
<script>document.addEventListener("DOMContentLoaded", function() { toro_load("#my-locker"); });</script>

And if you do not control the HTML at all, every locker also has a direct link at https://your-domain.com/YOUR_URLCODE that you can send traffic to from a bio, a Telegram channel or a QR code.

The settings that move the number

Show three or four offers, not twenty. The panel scrolls, so you can list a lot. Do not. Twenty options is a decision problem; four is a choice, and choices get made.

Leave conversions required at 1. Asking for two completions roughly halves your unlock rate to double a payout that is not doubled. Raise it only on genuinely high value content, and only with data.

Set a payout threshold if your traffic is strong. It filters out low value offers, which raises revenue per unlock and lowers unlock rate. Whether that trade is worth taking is a per page question.

Use per device offer types. Mobile traffic converts on CPI far better than desktop does. Setting mobile and desktop separately is a two second change that publishers routinely skip.

Judge it on earnings per visitor to the page, not on unlock rate. Total locker revenue divided by everybody who reached the widget, including everybody who ignored it. A locker at 6% on high payout offers can comfortably beat one at 30% on cheap ones, and unlock rate alone will never tell you which you have.

What runs behind the widget

Worth knowing, because it explains the delays you will occasionally see.

The widget can never unlock itself. The reward is not in the payload the browser receives; it is released by the server only after verification, and browser storage is treated as a routing hint and nothing more. Editing the page does not open the gate.

Every locker endpoint is rate limited. Offer clicks pass through a single VPN and proxy check on their way to the advertiser. Conversions arrive by server to server postback and go through a three layer review, so a conversion held for review does not unlock and a rejected one never will. Approved earnings flow through the click, conversion, profit and transaction ledger you can see in your reporting, which is why your statistics and your visitor's experience never disagree about what happened.

Put one live this week

Take your best download or tool page, not your busiest one. Add the script tag, drop the container where the download button sits, match the accent colour to your site, and leave it alone for seven days before you change a single setting.

Create your ToroAds account to build your first one, or read Content Locking Explained for the wider picture on what to lock and what to leave open.

Related Articles

Continue reading from the ToroAds blog.

Ready to put these strategies to work? Start earning with ToroAds