Keep bots out. Let people through.

WAU Captcha puts a short human check in front of your sign-ups, logins and forms. Your page shows the challenge, your server redeems a one-time token, and the dashboard shows who is getting through.

How it works

  1. 1

    Show a challenge

    Your page asks for a challenge with the public site key and shows it, or drops in the ready-made widget.

  2. 2

    The person answers

    A correct answer returns a one-time token, valid for two minutes. A wrong one simply gets a new challenge.

  3. 3

    Your server verifies

    Your backend redeems the token with the secret key. Each token works once, and only for your key.

Two kinds of challenge

Pick per request. Both are generated fresh every time, so there is nothing to collect and replay.

Distorted text

image_distort

Five characters, rotated, warped, crossed with curves and speckled with noise. Quick for people, costly for OCR.

Moving dots

motion_noise

A looping animation of random dots. Any single frame is pure noise: the characters only appear through their motion.

Built for production

  • One-time tokens

    Signed, short-lived, and tied to one API key, so a token cannot be reused or taken to another site.

  • Allowed IP addresses

    Limit a key to the addresses and networks you list; everything else is refused.

  • Secret key rotation

    Reset a secret without downtime: the previous one keeps working for 24 hours, or until you revoke it.

  • Scraping protection

    Keys that collect challenges without answering them are suspended automatically.

  • Usage and quotas

    Daily charts per key and per challenge type, and a quota meter for your plan.

  • SDKs

    A browser widget and client, a React component, plus server SDKs for Node.js and Java.

Integrate in minutes

Install the SDK for your stack, then follow the docs for the full flow.

Read the docs
bash
npm install @wau-captcha/client

Protect your first form today

Create an API key in the dashboard; every captcha type is free for now.

Create an API key