Glossary

What is a CAPTCHA?

A CAPTCHA is a challenge a website shows to tell human visitors from bots, such as typing distorted letters, picking the images with traffic lights, or ticking a box. The name stands for Completely Automated Public Turing test to tell Computers and Humans Apart. Today many bots pass them, while real users pay the friction.

How CAPTCHAs work

The idea, from the early 2000s, was simple: find a task that is easy for people and hard for computers, and put it in front of anything worth protecting, like a signup or comment form. If the visitor solves it, they are probably human.

CAPTCHAs have gone through several generations. Distorted text came first. Image selection followed, asking users to pick crosswalks or buses. Checkbox CAPTCHAs moved most of the work out of sight, scoring the visitor's browser and behavior and showing a puzzle only when unsure. Newer versions score every visitor silently and never show a puzzle at all, which is closer to an invisible challenge than to the original idea.

Why CAPTCHAs no longer stop determined bots

  • Solving services

    Paid services forward puzzles to human workers or to models and return the answer in seconds, for a small fee per solve.

  • Machine learning

    Image and text recognition models now solve many classic puzzles as well as, or better than, people.

  • Token reuse

    Some attacks solve the challenge once in a real browser and replay or pass the resulting token to automated sessions.

  • Friction for real users

    Every puzzle costs real customers time. People with visual or motor impairments, older users and mobile users suffer most.

CAPTCHA vs invisible challenge

Visible CAPTCHAInvisible challenge
Who sees itEvery visitor, or everyone who looks unsureNobody; it runs in the background
What it testsWhether someone can solve a puzzleWhether the browser, device and behavior are real and consistent
Bots with solving servicesPassStill exposed by automation and tampering signals
Impact on conversionMeasurable drop on signup and checkoutNone for real users

What to use instead

The question a CAPTCHA asks, can this visitor solve a puzzle, is no longer the useful one. The useful question is whether this is a real browser on a real device, driven by a person, and whether it is linked to other suspicious activity. That can be answered without asking the visitor to do anything.

CAPTCHAs still have a place as one tool among several: a last-resort step for a small slice of uncertain traffic, not a gate every customer has to pass. Used that way, the friction lands only where evidence is genuinely mixed.

Kavra never shows CAPTCHA puzzles or any other challenge. It checks the network, device, browser integrity and behavior of every visit, and flags automation frameworks like Playwright and Puppeteer even when they try to hide. When evidence is not conclusive, Kavra runs more background checks instead of showing the visitor anything to solve. Learn how headless browsers and automation are caught, and how this protects signups against fake account creation.

FAQ

Frequently asked questions

Something else? Talk to our team.

Can bots solve CAPTCHAs?

Yes. Paid solving services use human workers and machine learning models to solve image and text puzzles within seconds, for a small fee each. Browser automation tools integrate those services directly. That is why CAPTCHAs now mostly filter out unsophisticated bots, while organized attacks pass them as a routine cost of doing business.

Do CAPTCHAs hurt conversion?

They add friction exactly where you want the least: signup, login and checkout. Every puzzle takes time, some users fail on the first try, and some give up. The effect is larger on mobile and for people with disabilities. Showing puzzles only to risky traffic, or replacing them with invisible checks, removes most of that cost.

Are CAPTCHAs accessible?

Often not. Visual puzzles exclude people with low vision, and audio alternatives are hard to use and have been solved by speech recognition. Accessibility guidelines ask sites to offer alternatives. Checks that run in the background, without asking the visitor to do anything, avoid the problem for most users.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.