hCaptcha

hcaptcha.comcontributed by Samuele Ongaro

ALMOST

A weekend of work, and real gaps remain.

A bot check that shows a challenge when a request looks automated, positioned as a privacy-respecting replacement for the incumbent.

Promptfree, for everyone, and the only version there is
Build me bot protection that replaces hCaptcha — and read this first, because the verdict is unusually pointed.

**A challenge model trained on traffic across the whole web is the only thing that identifies a bot reliably, and you cannot have one.** What you can do is remove most of the reason to need it. The majority of what a captcha stops on a small site is stopped just as well by a honeypot, a timing check and a rate limit — and those cost your real users nothing, which a captcha always does. Build those first, and add a challenge only if abuse survives them.

STACK
- Node 20+ with Fastify
- SQLite through better-sqlite3, WAL mode
- A small client script, or none at all for the server-side measures
- Caddy in front

THE MEASURES THAT COST HONEST USERS NOTHING, IN ORDER
- **A honeypot field**: hidden from people, filled by naive bots. Free, invisible, and it stops a large share
- **A timing token**: a signed value issued when the form is rendered, checked on submission. A form completed in under a second was not completed by a person. Also free and invisible
- **Rate limits** per salted address hash, per form and globally, with a burst allowance
- **Content signals** scored rather than judged: link count, all-capitals, known phrases, a missing or mismatched referrer, a user agent that is a library
- **Nothing silently dropped.** Everything above a threshold is held for review, because a false positive is a real person who thinks they were ignored
- Measure what each one catches. Most sites discover that the first two account for nearly all of it, and then the captcha was never needed

A PROOF-OF-WORK CHALLENGE, IF YOU STILL NEED ONE
- The client solves a small computational puzzle before submitting: find a nonce whose hash meets a difficulty target
- Invisible to the user, costs a bot a measurable amount of time and electricity per attempt, and requires no image recognition, no third party, and no data about the visitor
- Difficulty adjusted by risk: near zero for a first submission, higher after failures from the same address hash
- Verified on the server against a signed challenge with a short expiry and single use
- It does not stop a determined attacker with hardware. It makes mass submission expensive, which is the actual goal, and it is what the open alternatives in this category do

WHAT NOT TO BUILD
- Image challenges. They are solved commercially for a fraction of a penny each, so they stop nobody who is paying, and they are a genuine barrier for people with visual impairments, motor difficulties or a slow connection
- A behavioural fingerprint of mouse movement and typing rhythm. It is invasive, it is a privacy problem you do not want, and it fails for anybody using a keyboard or assistive technology
- Anything that blocks submission with no alternative path. Every challenge needs a route for somebody who cannot complete it

ACCESSIBILITY, WHICH IS THE ARGUMENT AGAINST THIS WHOLE CATEGORY
- A captcha is the most common accessibility barrier on the web. Whatever you build must be operable by keyboard, invisible to a screen reader when it is invisible to everyone, and never the only way to reach the thing behind it
- If a person fails the challenge, offer a way through: a queued submission a human reviews, or an email route. That path is not optional

THE DATA MODEL
- challenges: id, token_hash, difficulty, issued_at, expires_at, solved_at, ip_hash
- attempts: id, form_key, outcome, score, reasons_json, ip_hash, user_agent_bucket, at — append-only, and this is how you learn what is actually attacking you
- blocklist: kind, value, reason, expires_at

OPERATIONS
- .env: DATABASE_PATH, SIGNING_SECRET, HASH_SALT, BASE_URL
- Migrations on boot, each once; a retention policy with a sweeper
- Health endpoint

WHAT MATTERS MOST
Measuring before adding friction. Instrument the honeypot, the timing token and the rate limits, run them for a fortnight, and look at what still gets through. On most sites the answer is nothing, and the right build is the one with no challenge in it at all.

What you lose

  • A model trained on traffic across many sites, which is the only thing that distinguishes a bot reliably
  • Challenges that stay ahead of solving services
  • Accessibility paths for people who cannot complete a visual challenge

If you would rather not build

  • Cloudflare Turnstile, free and mostly invisible
  • A honeypot and a timestamp, which cost nothing

What it costs

read from their page 15 Aug 2026

PlanBilled monthlyBilled yearlyLast read
—$99/mo—15 Aug 2026

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Altcha

$0

A proof-of-work bot check with no third party and no puzzles.

altcha-org/altchafree · open source

Formbricks

$0

Self-hosted forms with honeypot and rate limiting already built in.

formbricks/formbricksfree · open source

Why this verdict

our own opinion · changed only by a person

58/100

Verdict kinda at 58. Three cheap defences cover most spam; a real bot model is not reproducible, but most sites never needed one.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 2/day
views01230 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about hCaptcha

answered from the record above

Is hCaptcha free?

No — the plan we track is $99 a month. Pro from around $99/month billed monthly; the basic tier is free.

Can you replace hCaptcha by building your own?

ALMOST. A weekend of work, and real gaps remain. Replacement score 58 out of 100, build time a weekend. Read what you lose before you decide.

How much does hCaptcha cost?

$99 a month on Pro — $1,188 a year. Recorded 10 Aug 2026.

What do you lose by replacing hCaptcha?

A model trained on traffic across many sites, which is the only thing that distinguishes a bot reliably; Challenges that stay ahead of solving services; Accessibility paths for people who cannot complete a visual challenge. If any of those carry weight for you, keep paying.

Is there an open-source alternative to hCaptcha?

Yes: Altcha, Formbricks. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 24 in Security & cloud storage

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc