POST /signupVerifyUnclear case, invisible check first
- New device, no history
- Hosting network, not a home ISP
- Human-like typing and pointer
Comparison
The main CAPTCHA alternatives are invisible challenges that test the browser instead of the person, proof-of-work that makes each request cost compute, device and behavior intelligence that scores every visit, and risk-based step-up that adds friction only for the risky few. Kavra combines these into one explained risk assessment per visit.
POST /signupVerifyUnclear case, invisible check first
A CAPTCHA asks the visitor to prove they are human. Every alternative flips that around: it asks the traffic to prove itself, quietly, and only involves the person when the evidence is unclear. In practice there are four families of alternatives, and most serious setups combine at least two of them.
Invisible challenges run small tests in the background that a real browser passes without the visitor noticing. Proof-of-work makes the browser spend a little compute before a form submits, which is trivial for one person and expensive for a bot sending thousands of requests. Device and behavior intelligence scores the whole visit: the network, the device, the browser, how the pointer and keyboard move, and what history this device has. Risk-based step-up uses that score to decide who sees friction at all, such as an email code, a one-time password or a short behavioral check.
Puzzles were designed for a time when computers could not read warped text or recognize a bus. That time is over. The cost of a puzzle now falls mostly on the people you want to keep.
The last point matters most for fraud teams. Many costly attacks, such as multi-accounting and bonus abuse, are run by humans with tools, not by bots that fail puzzles. A human will always pass a CAPTCHA.
Background tests check that the browser behaves like the real browser it claims to be. Real users see nothing. See invisible challenge.
The browser solves a small computation before submitting. It raises the cost of volume attacks but does not tell a person from a well-funded script.
Checks whether the device is real or an emulator, virtual machine or spoofed profile, and whether it has been seen before under other accounts.
Looks at timing, pointer paths, typing rhythm and navigation. Scripted flows are too regular or too fast; replayed human input has its own tells.
Separates home and mobile connections from datacenters, VPNs, Tor and residential proxies that borrow real home IPs.
Only visits with mixed evidence get friction, such as a one-time code. Everyone else passes. See step-up authentication.
No single approach covers everything. The table shows the trade-offs in plain terms.
| Approach | Visitor friction | Accessibility | Stops well | Can miss | AI solvers |
|---|---|---|---|---|---|
| Visible puzzle CAPTCHA | High for everyone who gets one | Visual tasks exclude some users | Simple scripts | Solving services, humans with tools | Many puzzles solvable by models |
| Invisible score or challenge | None for most visitors | Good, nothing to solve | Automation and fake browsers | Real browsers driven by people | Not relevant, no puzzle to solve |
| Proof-of-work | Small delay, no task | Good | Cheap high-volume floods | Low-volume, high-value abuse | Not relevant |
| Device and behavior intelligence | None | Good | Spoofed devices, automation, repeat actors | Needs tuning for shared devices | Agents show up as automation or declared bots |
| Risk-based step-up | Only for the risky few | Depends on the step chosen | Unclear cases at key actions | Depends on the signal feeding it | Step can be a code, not a puzzle |
The best-known products have moved far beyond the original puzzle. Here is where each one sits, based on its own public documentation.
| Product | How it works | Compare with Kavra |
|---|---|---|
| Google reCAPTCHA | Score-based keys return a score with no challenge; checkbox and policy-based keys show image challenges. Now part of Google Cloud Fraud Defense. | Kavra vs reCAPTCHA |
| hCaptcha | Widget with visible and invisible modes. Pro and Enterprise add passive, mostly challenge-free modes and bot scores. | Kavra vs hCaptcha |
| Cloudflare Turnstile | Managed, non-interactive and invisible widget modes built on browser checks such as proof-of-work. Works on any site. | Kavra vs Turnstile |
| Arkose Labs | Bot Manager scores traffic and sends suspicious sessions to MatchKey challenges built to resist AI solvers. | Kavra vs Arkose Labs |
Keep the CAPTCHA while the new signal scores the same traffic. Compare what each would have blocked before you change anything.
Verify every token on your backend, bind it to the action (signup, login, checkout) and refuse reused tokens.
Allow clear humans, block clear abuse, and step up the unclear middle. That middle band is where most of the tuning happens.
Signup, login, promo claim, checkout and one-time-password endpoints matter more than a contact form.
Link devices and accounts so that a person who passes every challenge but runs twenty accounts still shows up.
A full risk platform is not always worth it. A plain CAPTCHA, or a free invisible widget, is often enough when:
Once a form grants something of value, such as a bonus, a free trial, credits, a discount or access to an account, the question stops being "is this a bot?" and becomes "who is this, and have we seen them before?". That is where a CAPTCHA runs out.
reCAPTCHA is a trademark of Google LLC. Cloudflare and Turnstile are trademarks of Cloudflare, Inc. hCaptcha, Arkose Labs, MatchKey and other names are trademarks of their respective owners. This guide is based on public information as of September 2026 and may change. Kavra Lab is not affiliated with any of these companies.
How Kavra helps
Kavra is a detection and decision service, not a challenge widget. It can replace a CAPTCHA or sit next to one.
3,000+ data points across network, device, browser integrity, behavior and history, weighed by an AI/ML risk engine that looks for contradictions between layers.
Invisible to real customers. More background checks run when evidence is unclear, with nothing for the visitor to solve.
Each verdict comes with a plain-language headline, the findings behind it and a recommended action: allow, verify or block.
Returning devices are recognized and one actor behind many accounts is linked, even when the fingerprint rotates.
An async script under 64 KB plus one server call. Observe-only mode shows results before you block anything.
FAQ
Something else? Talk to our team.
For most sites it is an invisible check that scores the visit from network, device, browser and behavior signals, combined with a step-up for unclear cases. That keeps friction off real users while still stopping automation. For forms that pay out value, add device and account linking so repeat actors are caught even when they pass every challenge.
Many classic image and text puzzles can be solved by current vision models, and solving services cover the rest with human workers. That is why newer products lean on invisible browser checks and risk scores rather than harder puzzles, and why some vendors design challenges specifically to resist automated solvers.
Usually yes, because most visitors never see a task. Accessibility still matters for the fallback: if an invisible check is unsure and shows a visual puzzle, people with low vision or motor impairments can struggle. Check which fallback a product uses and whether it offers audio, text or code-based alternatives.
Proof-of-work raises the cost of high-volume attacks like spam floods, because every request needs compute. It does little against low-volume, high-value abuse such as account takeover or bonus farming, where an attacker happily spends a second of CPU per attempt. Treat it as one signal, not a full defense.
Yes. Some teams keep an existing widget and add Kavra's server-side assessment for the actions that matter, then lower or remove the widget once observe-only results show the new signal is reliable. Kavra recommends an action and your backend decides, so you control when any challenge appears.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.