POST /otp/sendBlockedScripted OTP requests to premium numbers
- Headless browser automation
- 40 numbers from one device
- Datacenter network
Comparison
Arkose Labs scores traffic with its Bot Manager and sends suspicious sessions to challenges, including MatchKey puzzles built to resist AI solvers. Kavra takes a different path: it explains each visit with evidence across network, device, browser and behavior, links repeat actors and steps up with invisible checks instead of puzzles.
POST /otp/sendBlockedScripted OTP requests to premium numbers
Arkose Labs sells a set of products on one platform it calls Arkose Titan, which it describes as built to stop bots, AI agents and human fraud networks. The products listed on its site include Bot Manager, Agent Trust Manager for classifying AI agent traffic, Email Intelligence, Device ID and Phishing Protection. Arkose serves banking and fintech, gaming and iGaming, travel, e-commerce and technology and telco companies.
Arkose Bot Manager uses what Arkose calls 225+ risk signals and its Global Intelligence Network, and deploys dynamic challenges that evolve in real time. Arkose says the aim is to tell good users from malicious bots without friction and to drain attacker return on investment until attacks stop paying. It supports web and mobile SDKs.
The challenges are the part most people know. MatchKey is Arkose's challenge-response system designed to resist AI-powered solving. In a May 2026 post, Arkose describes it as relying on a wide, varied solving space (spatial reasoning, counting, orientation matching, object detection and abstract patterns), behavioral detection inside the challenge itself, and making automated solving too expensive to be worth it. Arkose also offers a $1 million warranty against SMS toll fraud for customers using its platform.
Both products score traffic before deciding what to do. The difference is what happens when the evidence points to risk. Arkose's answer centers on its challenges: suspicious traffic meets a puzzle that is meant to cost the attacker time and money. Kavra's answer is evidence first. It runs invisibly, looks for contradictions between network, device, browser integrity, behavior and history, and returns a recommendation your backend acts on: allow, verify or block. When the case is unclear, Kavra runs more background checks and leaves any step-up to your rules.
That leaves the choice of friction with you. For a gray-zone login, you might ask for a one-time code the user already understands. For a clear SMS pumping script, you simply refuse to send the message. For a person running a ring of accounts, the useful outcome is not a harder puzzle but the link between the accounts, which Kavra shows in the console with the findings behind it.
Arkose details come from its public website, blog and accessibility conformance report.
| Kavra | Arkose Labs | |
|---|---|---|
| Core approach | Invisible detection and explained decisions | Risk assessment plus adaptive challenges for suspicious traffic |
| Signals | 3,000+ data points per visit across network, device, browser, behavior and history | 225+ risk signals and a Global Intelligence Network, per Arkose |
| Challenges | No puzzles or visible challenges; checks run in the background | MatchKey challenges designed to resist AI solvers; audio alternative |
| What you get back | Headline, findings, risk by domain, network context, recommended action | Not publicly documented in detail |
| Repeat actors and account linking | Devices recognized, fingerprint rotation kept as one actor, accounts linked | Device ID offered as a separate product |
| AI agents | Verified agents recognized by signatures and operator IP ranges; you choose allow, check or block | Agent Trust Manager classifies AI agent traffic |
| Accessibility | No visual task for most visitors | Enforcement Challenge conforms to WCAG 2.0, 2.1 and 2.2 Level A and AA, per its report |
| Rollout | Observe-only mode; presets cautious, balanced, strict | Not publicly documented |
Kavra recommends; your backend decides whether to step up with a code, delay, or block. Real customers never face puzzles.
Many costly attacks are run by people using antidetect browsers and proxies. They can solve any puzzle, but they leave contradictions between layers.
Accounts that share a real device or network are linked, so a fraud ring shows up as one actor.
Analysts see the findings behind each assessment, which makes reviews and appeals faster and false positives easier to spot.
The fairest test is your own traffic, side by side, before any user-facing change.
Add one async script and one server call on login, signup, one-time-password and checkout flows. Nothing changes for users yet.
Look at the sessions Arkose challenged and the ones Kavra would verify or block. Read Kavra's findings to see why each was flagged.
Count how many real customers met a puzzle under the current setup and how many would meet any step-up with Kavra's recommended actions.
Switch one flow at a time using a cautious, balanced or strict preset, and keep a challenge wherever it still earns its place.
Arkose is a reasonable choice in several situations:
If your priority is keeping every real customer free of puzzles, understanding why each decision was made, and linking the accounts behind multi-accounting or bonus abuse, Kavra's evidence-first model fits better. The approaches can also coexist: Kavra's recommendation can decide when a challenge is worth showing at all.
Arkose Labs, Arkose Titan and MatchKey are trademarks of their respective owner. This comparison is based on public information as of September 2026 and may change. Kavra Lab is not affiliated with Arkose Labs.
How Kavra helps
One script tag and one server call, results the same day.
A disguise that fools one layer rarely fools all of them. Kavra checks them against each other.
Kavra sees the real connection, not only what the browser claims.
Signed, short-lived tokens bound to the action. Replays are refused and reported.
Observe-only mode and policy presets let you roll out without surprises.
Legal basis per visitor region, no names or emails required, opaque visitor IDs, strict tenant isolation.
FAQ
Something else? Talk to our team.
MatchKey is Arkose Labs' challenge-response system designed to resist AI-powered solving. Arkose describes it as using a wide variety of tasks, such as spatial reasoning, counting, orientation matching and abstract patterns, together with behavioral detection inside the challenge, so that automated solving becomes too expensive to be worth it.
Arkose says Bot Manager tells good users from bots without friction and deploys dynamic challenges to counter attacks, so challenges are aimed at traffic it flags. How often real users see one is not publicly documented. With Kavra, real customers never see a puzzle, and your backend chooses the step-up.
Arkose publishes an accessibility conformance report stating that its Enforcement Challenge conforms to WCAG 2.0, 2.1 and 2.2 at Level A and AA, with an audio challenge that does not require vision and keyboard operation. Level AAA is listed as not supported.
For teams that want invisible detection, explained decisions and account linking, yes. Kavra covers bots, automation, proxies, antidetect browsers, multi-accounting, account takeover and SMS pumping, and recommends allow, verify or block. Start in observe-only mode on the same traffic to compare outcomes before switching.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.