PrivCaptcha
.com
Use cases
Docs
Features
Bots and scraping
Bot protection
Scripted traffic pays per attempt, humans pay once
Scraping
One challenge per page, and no way to reuse it
Click fraud
Count the conversions a person actually completed
Accounts and access
Credential stuffing
The pairs that miss cost as much as the ones that hit
Account takeover
Make password reset and resend cost more than a click
Fake signups
Bulk registration stops being a one-request job
Commerce and abuse
Card testing
Every card tested pays for its own challenge
Ticket scalping
A fresh token per claim, none banked before the drop
Giveaway abuse
Each entry costs a fresh challenge, not a POST
Spam comments
A link posted 500 times needs 500 fresh challenges
Overview
All use cases
One integration, every abuse type on this list.
Getting started
Introduction
What it is and how it decides.
Quickstart
From nothing to a verified token.
Sites and domains
Sitekeys, secrets, allowlist.
Widget
Installation
The script tag and the container.
JavaScript API
render, getResponse, callbacks.
Accessibility
The non-visual challenge path.
API
Overview
Endpoints, auth, rate limits.
Verify a token
The server-to-server call.
Error codes
Every code and what causes it.
Server SDKs
Python
Django, Flask, or plain requests.
Node
Express, Fastify, or fetch.
PHP
Laravel, Symfony, or plain PHP.
Go
One call from net/http.
Migrate
From reCAPTCHA
Two URL changes.
From hCaptcha
Two URL changes.
From Turnstile
Three: no shim for it.
Privacy first
Privacy and GDPR
No IP addresses stored, ever.
No Google dependency
Works on hardened networks.
Per-site dashboard
Four counters. Nothing personal.
How it works
Risk scoring
Signals from the request, not a profile.
Proof-of-work
Cheap once, expensive at scale.
Accessible challenge
Non-visual, keyboard, no audio.
Drop-in migration
Two lines from reCAPTCHA or hCaptcha.
Report a Bug
Suggest a Feature
About us
Contact
Docs
Cookie settings
Feedback
Sign in
Help us improve