How an invisible challenge works
A visible CAPTCHA asks the visitor to prove they are human. An invisible challenge asks the browser instead. When a page loads, or when a sensitive action like signup or checkout is about to happen, a small script runs a set of tasks in the background and reports the results.
The tasks are ones a real browser completes naturally and consistently, but that automation tools, headless browsers and spoofed environments struggle to get exactly right. Some ask the browser to do work, such as rendering graphics or running code, and check that the result matches the device it claims to be. Others check that the browser's many reported properties agree with each other. Others watch for the small traces that automation frameworks leave behind. Together, the answers either form a coherent picture of a real device or they do not.
Because the test changes and its details are not shown, a bot operator cannot simply look at it and write a solver, the way they can with a puzzle.
Invisible challenge vs CAPTCHA
| Invisible challenge | CAPTCHA | |
|---|---|---|
| What the user does | Nothing | Types text, picks images or ticks a box |
| What is tested | The browser, device and behavior | The ability to solve a puzzle |
| Beaten by solving services | No, there is nothing to hand off | Yes, for a small fee per solve |
| Accessibility | No impact | Hard for users with visual or motor impairments |
| Effect on conversion | None for real users | Some users give up |
Where invisible challenges fit
An invisible challenge is not a verdict on its own. It is one more source of evidence, used when the rest of the picture is unclear. A visitor on a trusted device with years of normal history needs no challenge. A visitor whose network, device and behavior already contradict each other may not need one either, since the answer is clear. The challenge earns its place in the uncertain middle: the new device on a VPN, the signup that looks almost normal.
It also has limits. A fraudster running a real browser by hand on a real device will pass, because nothing is fake. Those cases are caught by other layers: linking to other accounts, history, and step-up authentication when the stakes are high.
How Kavra uses invisible challenges
Kavra never shows CAPTCHA puzzles or any other challenge. When the evidence on a visit is not conclusive, Kavra runs more invisible checks; the visitor is never asked to solve, click or drag anything. Results are bound into a signed, single-use token tied to the action, so a solved challenge cannot be replayed by another session. Learn how this exposes headless browsers and automation and protects the login step in credential stuffing protection.