How CAPTCHAs work
The idea, from the early 2000s, was simple: find a task that is easy for people and hard for computers, and put it in front of anything worth protecting, like a signup or comment form. If the visitor solves it, they are probably human.
CAPTCHAs have gone through several generations. Distorted text came first. Image selection followed, asking users to pick crosswalks or buses. Checkbox CAPTCHAs moved most of the work out of sight, scoring the visitor's browser and behavior and showing a puzzle only when unsure. Newer versions score every visitor silently and never show a puzzle at all, which is closer to an invisible challenge than to the original idea.
Why CAPTCHAs no longer stop determined bots
Solving services
Paid services forward puzzles to human workers or to models and return the answer in seconds, for a small fee per solve.
Machine learning
Image and text recognition models now solve many classic puzzles as well as, or better than, people.
Token reuse
Some attacks solve the challenge once in a real browser and replay or pass the resulting token to automated sessions.
Friction for real users
Every puzzle costs real customers time. People with visual or motor impairments, older users and mobile users suffer most.
CAPTCHA vs invisible challenge
| Visible CAPTCHA | Invisible challenge | |
|---|---|---|
| Who sees it | Every visitor, or everyone who looks unsure | Nobody; it runs in the background |
| What it tests | Whether someone can solve a puzzle | Whether the browser, device and behavior are real and consistent |
| Bots with solving services | Pass | Still exposed by automation and tampering signals |
| Impact on conversion | Measurable drop on signup and checkout | None for real users |
What to use instead
The question a CAPTCHA asks, can this visitor solve a puzzle, is no longer the useful one. The useful question is whether this is a real browser on a real device, driven by a person, and whether it is linked to other suspicious activity. That can be answered without asking the visitor to do anything.
CAPTCHAs still have a place as one tool among several: a last-resort step for a small slice of uncertain traffic, not a gate every customer has to pass. Used that way, the friction lands only where evidence is genuinely mixed.
Kavra never shows CAPTCHA puzzles or any other challenge. It checks the network, device, browser integrity and behavior of every visit, and flags automation frameworks like Playwright and Puppeteer even when they try to hide. When evidence is not conclusive, Kavra runs more background checks instead of showing the visitor anything to solve. Learn how headless browsers and automation are caught, and how this protects signups against fake account creation.