Keep bots out. Let people through.
WAU Captcha puts a short human check in front of your sign-ups, logins and forms. Your page shows the challenge, your server redeems a one-time token, and the dashboard shows who is getting through.
How it works
- 1
Show a challenge
Your page asks for a challenge with the public site key and shows it, or drops in the ready-made widget.
- 2
The person answers
A correct answer returns a one-time token, valid for two minutes. A wrong one simply gets a new challenge.
- 3
Your server verifies
Your backend redeems the token with the secret key. Each token works once, and only for your key.
Two kinds of challenge
Pick per request. Both are generated fresh every time, so there is nothing to collect and replay.
Distorted text
image_distortFive characters, rotated, warped, crossed with curves and speckled with noise. Quick for people, costly for OCR.
Moving dots
motion_noiseA looping animation of random dots. Any single frame is pure noise: the characters only appear through their motion.
Built for production
One-time tokens
Signed, short-lived, and tied to one API key, so a token cannot be reused or taken to another site.
Allowed IP addresses
Limit a key to the addresses and networks you list; everything else is refused.
Secret key rotation
Reset a secret without downtime: the previous one keeps working for 24 hours, or until you revoke it.
Scraping protection
Keys that collect challenges without answering them are suspended automatically.
Usage and quotas
Daily charts per key and per challenge type, and a quota meter for your plan.
SDKs
A browser widget and client, a React component, plus server SDKs for Node.js and Java.
Integrate in minutes
Install the SDK for your stack, then follow the docs for the full flow.
Read the docsnpm install @wau-captcha/clientProtect your first form today
Create an API key in the dashboard; every captcha type is free for now.