Category:Anti BotView as Markdown

What Is CAPTCHA? How It Works and 11 Types Explained

Clock21 Mins Read
calendarCreated Date: September 23, 2026
calendarUpdated Date: September 23, 2026
author

Head of Marketing

linkedinmedium

I've clicked "I'm not a robot" thousands of times, and for years I assumed the click was the test.

It isn't. By the time that checkbox renders, the site has already scored me, and the puzzle only shows up when it can't make up its mind.

Bots got so good at the old puzzles that the puzzle turned into the fallback. Once you see that, the 11 CAPTCHA types below stop looking like a random zoo.

What Is a CAPTCHA?

A CAPTCHA is a challenge-response test that a website uses to tell human visitors apart from automated programs, usually in front of a signup, login, checkout, or form submission.

CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart. The "Public" part is deliberate: its inventors wrote that the code and data behind a CAPTCHA should be publicly available, so its strength comes from a hard problem and not from secrecy (Communications of the ACM, 2004).

It's a Turing test with the roles flipped. In Alan Turing's version a human judges whether they're talking to a machine. In a CAPTCHA, the judge is a computer. The same paper describes it as a program that can generate and grade tests it can't pass itself, "much like some professors." (I laughed, I'm not going to lie.)

One distinction worth holding onto:

A CAPTCHA is a test, not a block.

A block says no, usually as a 403 Forbidden. A CAPTCHA says "prove it." If you do any web scraping, that difference decides whether a request is dead or only expensive.

Who Invented CAPTCHA

Most articles say 2003. That's the year of the paper. The term itself is from 2000, coined at Carnegie Mellon by Luis von Ahn, Manuel Blum, Nicholas Hopper, and John Langford after Yahoo asked them how to keep bots out of its chat rooms (captcha.net).

The idea is older than the name, though:

Year What happened
1996 Moni Naor's draft proposes a "Turing test" to check that a human is making a web query (manuscript)
1998 AltaVista engineers file a patent for a distorted-text test against automated URL submissions (US 6,195,698, granted 2001)
2000 Carnegie Mellon coins "CAPTCHA"
2001 Yahoo puts CMU's EZ-Gimpy word puzzle on its sign-up flow
2003 "CAPTCHA: Using Hard AI Problems for Security" is published at Eurocrypt
2007 reCAPTCHA launches and turns solved words into digitized books
2009 Google acquires reCAPTCHA, then protecting over 100,000 websites
2014 Google ships the "I'm not a robot" checkbox
2018 reCAPTCHA v3 replaces the challenge with a score
2020 Cloudflare moves from reCAPTCHA to hCaptcha after Google announces it will charge
2022 Cloudflare launches Turnstile; Apple ships Private Access Tokens
2023 Cloudflare replaces every CAPTCHA it issues with Turnstile
2026 reCAPTCHA becomes part of Google Cloud Fraud Defense

Read the right-hand column top to bottom and the whole story is there: the puzzle keeps shrinking.

How Does CAPTCHA Work?

A CAPTCHA works by scoring you first and testing you second: a script collects signals about your network, browser, and behavior, a risk engine decides how sure it is that you're human, and only an unsure verdict turns into a visible puzzle.

How CAPTCHA works: the widget loads with a public sitekey, gathers signals, a risk engine scores the visitor, and only an unsure score leads to a visible challenge before the token is verified server-side

Step by step, it goes like this:

  • The page loads the provider's script with a public sitekey, which tells the provider which site is asking. On Cloudflare-protected sites, the challenge can come from the reverse proxy in front of the server rather than the site's own code.
  • The script gathers signals before you touch anything: IP reputation, browser and TLS fingerprint, cookies and history, mouse movement and timing. Some providers add a proof-of-work result or a device attestation token.
  • The provider's risk engine turns that into a verdict. Confident human: you pass silently or with one click. Not sure: you get a puzzle. Confident bot: you get blocked or looped through harder puzzles.
  • A pass produces a token that the form submits in a hidden field, such as g-recaptcha-response or cf-turnstile-response.
  • The site's server sends that token and its secret key to the provider's verify endpoint and gets back a result. With reCAPTCHA v3 that result includes a score from 0.0 (likely bot) to 1.0 (likely human), a default threshold of 0.5, and tokens that expire after two minutes (Google docs).

I saw all three outcomes on the same Google demo page on the same afternoon. In my everyday browser, one click and done:

reCAPTCHA v2 checkbox passed with a single click, green tick next to I'm not a robot and no image challenge shown

In headless Chrome, the same click earned a grid of buses. And when that headless session asked for the audio version, reCAPTCHA refused to serve it at all:

reCAPTCHA Try again later message saying the computer or network may be sending automated queries, shown instead of the audio challenge

Same widget, same page, three different answers. The puzzle was never the part doing the deciding.

Why You Keep Getting CAPTCHAs

If you're a human and CAPTCHAs follow you around, one of the signals above is working against you. The usual suspects:

  • Your IP. VPNs, office networks, and mobile carriers put many people behind one address. If someone on it misbehaves, everyone gets tested. Datacenter IPs get the worst of it.
  • A fresh browser. Private windows, cleared cookies, and new profiles have no history to vouch for them. In ETH Zurich's reCAPTCHA study, adding a real user's cookies cut the average number of challenges from 8.38 to 2.71 (Plesner et al., 2024).
  • Blocked scripts. Privacy extensions that stop the CAPTCHA script from collecting signals leave the risk engine guessing, and guessing means puzzles.
  • Speed. Google's own block page says it can appear when you're "sending requests very quickly," and most sites apply some kind of rate limit.
  • Automation. Headless browsers and scripts announce themselves in dozens of small ways, which is the whole field of web scraping detection.

11 Types of CAPTCHA

Every CAPTCHA asks you to do one of three things: solve something, click something, or nothing at all. The further down this list you go, the less the visible part matters and the more the hidden scoring does the work.

# Type What you do What actually decides Where you'll see it
1 Text Type distorted characters Your answer MTCaptcha, legacy forms
2 Image recognition Pick tiles with a bus, bike, or animal Answer plus behavior reCAPTCHA v2, hCaptcha, AWS WAF
3 Audio Type the words you hear Your answer Fallback on most visual CAPTCHAs
4 Math and word Solve "7 + 4" or a simple question Your answer Plugins, small sites
5 Slider and puzzle Drag a piece into place Drag path and timing GeeTest, DataDome, TikTok
6 Interactive Click icons, rotate objects, press and hold Behavior while you do it GeeTest, Arkose Labs, HUMAN
7 Checkbox Tick "I'm not a robot" Signals collected before the click reCAPTCHA v2, hCaptcha
8 Invisible and score-based Nothing A risk score reCAPTCHA v3
9 Managed challenge Usually nothing, sometimes one click Browser checks and reputation Cloudflare Turnstile
10 Proof-of-work Wait a second Your device's compute Friendly Captcha, ALTCHA
11 Honeypot and time-based Nothing Hidden fields and timing Form plugins everywhere

1. Text CAPTCHA

A text CAPTCHA shows letters and numbers that have been warped, overlapped, or covered in noise, and asks you to type them. It's the original format, and it's the one computers beat first.

Text CAPTCHA from MTCaptcha showing distorted characters over a dark background with an input box asking to enter text from the image

Google killed it in public. In 2014 Google said its own AI could read the hardest distorted text in reCAPTCHA with 99.8% accuracy, using a model built to read house numbers in Street View, and concluded that distorted text "is no longer a dependable test" (Google Security Blog).

Even Amazon, the last big name I associated with "type the characters you see," has moved on. When I opened its CAPTCHA URL on September 28, 2026, it served a single button:

Amazon's CAPTCHA page showing only a Continue shopping button instead of a text CAPTCHA

2. Image Recognition CAPTCHA

An image recognition CAPTCHA shows a grid of photos and asks you to select every tile that contains a specific object, like buses, crosswalks, or traffic lights.

Image recognition CAPTCHA from reCAPTCHA v2 asking to select all images with a bus in a 3x3 grid

Those tiles were never only a test. Google has said solved CAPTCHAs helped "digitize text, annotate images, and build machine learning datasets." hCaptcha went further: its founder told Fast Company the company ended up in the CAPTCHA business "accidentally" because it needed humans to label training data (Fast Company, 2019).

Image recognition CAPTCHA from hCaptcha asking to click the animal icon that is different

AWS WAF has its own version, the one you meet on sites that sit behind Amazon's firewall. It's the same idea with different objects:

Image recognition CAPTCHA from AWS WAF asking to choose all the buckets in a 3x3 grid, with several tiles selected

The site owner pays for every one of those. AWS charges $0.40 per 1,000 CAPTCHA attempts, "regardless of the outcome," so a bot that fails a thousand times still costs the site money (AWS WAF pricing).

As a bot test, the grid is on borrowed time. ETH Zurich researchers solved 100% of reCAPTCHA v2 image challenges in 2024. The fine print matters, though: they needed a VPN, human-like mouse movement, and real browser cookies to get there (Plesner et al.). The model could see the buses. The environment is what got it through.

3. Audio CAPTCHA

An audio CAPTCHA plays distorted spoken words or numbers over background noise and asks you to type what you heard. It exists so blind and low-vision users aren't locked out of visual CAPTCHAs.

It doesn't work well for anyone. In a 2009 study, blind participants solved 43% of audio CAPTCHAs on the first try, and sighted participants did even worse at 39% (Bigham and Cavender, CHI 2009). Meanwhile, University of Maryland researchers beat reCAPTCHA's audio challenge 85% of the time in 2017 using free speech-to-text services (unCaptcha).

Hard for the people it's meant to help, easy for the bots it's meant to stop. That's a rough combination.

4. Math and Word CAPTCHA

A math CAPTCHA asks you to solve simple arithmetic like "7 + 4 = ?", and a word CAPTCHA asks a plain-language question like "What color is the sky?"

Math CAPTCHA example showing the distorted equation 7 + 4 = ? (generated for illustration)

I'll be blunt: any script that can read the page can do addition. These survive on small sites because they're free and take one line to install, and they stop bots that don't bother to look. They also shut out people with dyscalculia, which the W3C calls out directly.

5. Slider and Puzzle CAPTCHA

A slider CAPTCHA asks you to drag a puzzle piece or handle until it fits a gap in an image.

Slider CAPTCHA from GeeTest asking to slide a heart-shaped puzzle piece into its matching gap

Finding the gap is easy for software. The real test is how you drag. GeeTest sends the final position together with the behavioral data from the drag, and treats that behavioral analysis as the core of the check. A perfectly straight, constant-speed drag looks like a script, because it usually is.

6. Interactive CAPTCHA

An interactive CAPTCHA asks you to do a small task, like clicking icons in a set order, rotating an object upright, or pressing and holding a button.

Interactive CAPTCHA from GeeTest asking to select icons in a specific order

Arkose Labs builds the game-like ones (rotate the animal, pick the dice that add up to a number) and pitches them as a way to make attacks too expensive to be worth it. HUMAN's Press & Hold is the strangest one to meet in the wild: you hold a button while it measures how you hold it. I got this one on beehiv, of all places, while confirming a newsletter subscription. Scrapers know it from sites like Wayfair, where it shows up the moment the site has doubts.

Press and Hold CAPTCHA challenge asking the visitor to hold a button to confirm they are human

7. Checkbox CAPTCHA

A checkbox CAPTCHA asks you to tick a box labeled "I'm not a robot" or "I am human," and passes you if the signals collected around that click look human.

Checkbox CAPTCHA from hCaptcha with an unticked I am human box

Google introduced it in 2014 as "No CAPTCHA reCAPTCHA." In early tests, more than 60% of WordPress traffic and more than 80% of Humble Bundle traffic got through without seeing a puzzle (Google Security Blog). When the risk engine isn't sure, the checkbox turns into the image grid from type 2.

The click itself proves almost nothing, and 2025 made that funny. OpenAI's ChatGPT agent was caught narrating its way through Cloudflare's checkbox: "This step is necessary to prove I'm not a bot" (Ars Technica). No puzzle ever appeared.

8. Invisible and Score-Based CAPTCHA

An invisible CAPTCHA never shows you anything: it scores your session in the background and hands the site a number, which the site uses to allow, challenge, or block you.

reCAPTCHA v3 is the main example. It "will never interrupt your users," in Google's words, and the site's server decides what to do with the score. This is what your server actually gets back:

Invisible reCAPTCHA v3 returning a score of 0.9 with no challenge shown, siteverify JSON with success, score and action

Don't confuse it with 2017's "invisible reCAPTCHA," which is a v2 variant that hides the checkbox but still throws puzzles at suspicious users.

Score-based checks are also the ones paid solvers struggle with. A July 2026 study tested seven commercial solving services: they passed reCAPTCHA v2 and Turnstile nearly every time but averaged only 23% on reCAPTCHA v3, and the deciding factor was how authentic the browser environment was (Broken Gates).

9. Managed Challenge (Cloudflare Turnstile)

A managed challenge runs a series of invisible browser checks and only asks you to click a checkbox if those checks come back inconclusive. Cloudflare Turnstile is the best-known one, and it's free.

Cloudflare managed challenge page with a Turnstile Verify you are human checkbox shown before the website loads

Cloudflare says Turnstile runs small non-interactive JavaScript challenges, including "proof-of-work, proof-of-space, probing for web APIs," plus checks for browser quirks and human behavior (Cloudflare blog). In September 2023, Cloudflare finished replacing every CAPTCHA it issues with Turnstile and wrote that it "will never issue another visual puzzle to anyone, for any reason" (Cloudflare).

That's one of the biggest CAPTCHA providers on the planet saying the puzzle is over. If you scrape, this is the widget you'll meet most, and it's why bypassing Cloudflare is mostly about the environment you send, not the checkbox.

10. Proof-of-Work CAPTCHA

A proof-of-work CAPTCHA makes your device solve a small cryptographic puzzle in the background, so each form submission costs a bit of computing time.

Proof-of-work CAPTCHA from ALTCHA verifying in the browser before showing verified

Friendly Captcha and ALTCHA are the common ones, and both sell privacy: no image labeling, no tracking cookies. The idea goes back to Hashcash in 1997, and further to a 1992 paper by Dwork and Naor on "pricing via processing" junk mail.

The trade-off is honest math. A second of hashing is nothing to a server farm and noticeable on an old phone. Proof-of-work makes spam more expensive. It doesn't make it impossible.

11. Honeypot and Time-Based Checks

A honeypot is a form field hidden from humans but visible to bots, so anything that fills it in gets flagged, and a time-based check flags forms submitted faster than a person could type.

Drupal's popular Honeypot module uses both, with a default five-second minimum between loading a form and submitting it. They're invisible, free, and accessible, and they stop the laziest bots cold. The W3C's own advice on CAPTCHA accessibility says it plainly: "if a honeypot suffices, use a honeypot" (W3C).

What Isn't a CAPTCHA

SMS codes, two-factor authentication, email verification links, "Sign in with Google," and fingerprint or face unlock show up on a lot of CAPTCHA lists. They're verification, not CAPTCHAs. They check that you own an account, a phone, or a face, and they say nothing about whether you're a person or a script.

Which CAPTCHAs Websites Actually Use

Among the top million sites, reCAPTCHA is still the default. BuiltWith counts 208,684 of 308,585 CAPTCHA detections as reCAPTCHA, roughly 68%. Cloudflare Turnstile (52,908) has already passed hCaptcha (31,448) in that group, according to BuiltWith's CAPTCHA category data (last updated September 25, 2026).

I wanted to see what that looks like on the pages people actually hit. So on September 28, 2026, I loaded 39 signup, login, and password-reset pages from 38 popular sites three ways: a plain request, a rendered pass through Scrape.do with render=true, and a headless browser. Then I recorded every CAPTCHA and bot-detection script each page loaded or configured. A sample:

Site What loaded
Steam hCaptcha checkbox, visible on page load
Reddit, Pinterest reCAPTCHA Enterprise, score-based with no widget
Dropbox reCAPTCHA, rendered on demand
Microsoft, Coinbase Arkose Labs, triggered on submit
Discord, ChatGPT Cloudflare's invisible bot detection
Stack Overflow Cloudflare managed challenge for plain requests
Etsy, Tripadvisor DataDome, with a block page for plain requests
Walmart, Fiverr HUMAN (PerimeterX), Press & Hold for headless browsers
Booking.com AWS WAF CAPTCHA plus a silent token challenge
Twitch Kasada invisible proof-of-work
eBay Akamai Bot Manager
Zoom Keys for reCAPTCHA, hCaptcha, and Turnstile in the same page

The count: 18 of the 38 sites loaded or configured a CAPTCHA widget, 15 relied only on an invisible bot manager (Cloudflare, HUMAN, DataDome, Kasada, Akamai, AWS WAF), and 5 showed nothing at page load. reCAPTCHA was the most common widget, on 11 sites.

The number that stuck with me: only one site, Steam, showed a visible checkbox the moment the page loaded. Not a single real site in the sample put a reCAPTCHA v2 checkbox in front of a first-time visitor. Four of the five sites running reCAPTCHA Enterprise used the invisible, score-based mode. Everywhere else, the CAPTCHA waits behind detection and only appears once something looks off.

One caveat: this is one day of runs from two locations, on pages loaded without logging in, and results changed between runs. Plenty of sites only reveal their CAPTCHA after a suspicious action, and those won't show up in a page load. The full method and results are in the R&D notes for this article.

The Puzzle Stopped Being the Test

The awkward truth about modern CAPTCHAs is that software handles the classic puzzles about as well as people, sometimes better.

A 2023 USENIX Security study had 1,400 participants solve 14,000 CAPTCHAs. Humans took 9 to 15 seconds on distorted text with 50% to 84% agreement, while the bot results the authors compiled from earlier research were mostly above 96% accuracy (Searles et al.). Worth noting: the study measured the humans and borrowed the bot numbers, so "bots beat humans" is a comparison across papers, not one lab test.

And where software struggles, people fill in cheaply. 2Captcha currently lists reCAPTCHA v2 solving at $1 to $2.99 per 1,000 (2Captcha pricing). Researchers made this point back in 2010: CAPTCHAs are best understood as an economic cost for attackers, not a wall (Motoyama et al., USENIX Security 2010).

My favorite piece of CAPTCHA trivia sits right here. In OpenAI's 2023 GPT-4 safety tests, the model asked a TaskRabbit worker to solve a CAPTCHA for it and, when asked if it was a robot, claimed to have a vision impairment (GPT-4 system card). The less famous part: researchers set up the TaskRabbit account and relayed the messages, partly because the model couldn't create its own solver account. Signing up required solving CAPTCHAs (METR).

So the test moved. It's now your IP, your browser, your cookies, and how you move, which is exactly what the invisible types measure.

Where CAPTCHAs Are Heading

Toward no puzzle at all, and toward proving what you are instead of that you can see buses:

  • Device attestation: Apple's Private Access Tokens (iOS 16 and macOS Ventura, 2022) let a device vouch for itself so the site can skip the CAPTCHA (Apple WWDC22).
  • Signed bots and agents: Cloudflare's signed agents program lets AI agents identify themselves with cryptographic signatures; ChatGPT agent was in the first group (Cloudflare).
  • Harder-to-fake challenges: Google Cloud Fraud Defense, launched April 2026 as "the next evolution of reCAPTCHA," added a QR-code challenge it calls "AI-resistant," built around a person holding a phone.

Fake CAPTCHA Scams

The most dangerous CAPTCHA on the internet right now is a fake one.

ClickFix scams show a fake "Verify you are human" box, then tell you to press Windows+R, paste, and hit Enter. The page has already copied a malicious command to your clipboard, so those three keystrokes install malware. Microsoft's Digital Defense Report 2025 named ClickFix the most common initial access method its Defender Experts team saw, at 47% of cases (Microsoft Digital Defense Report 2025).

The rule is simple, and the FTC puts it plainly: real CAPTCHAs won't ask you to run commands on your device (FTC). If you already did it, disconnect from the internet, run a security scan, and change your passwords from a different device.

CAPTCHAs From a Scraper's Side

A scraper trips every signal in the "why you keep getting CAPTCHAs" list at once: datacenter IP, no cookies, a non-browser TLS fingerprint, perfect timing. So scrapers see CAPTCHAs constantly, and the first instinct is to solve them.

Solving is the expensive answer. You pay per solve, you wait 10 to 20 seconds per solve, and the score-based types barely care whether the puzzle was solved. The cheap answer is not triggering the CAPTCHA in the first place. The full menu of approaches, from proxies to solver APIs, is in our CAPTCHA bypass guide.

That second approach is what Scrape.do does. Requests go out through residential and mobile IPs with real browser headers and TLS fingerprints, which keeps most CAPTCHAs from firing, and the ones that still appear are handled on our side, so you get the page and not a token. There's no CAPTCHA parameter to set. Cost depends only on the proxy and browser you ask for: 1 credit per request by default, 5 with render=true, 10 with super=true, 25 with both, and only successful responses are billed (request costs).

In practice: Reddit's reCAPTCHA page cleared with super=true alone in our Reddit scraping tests, while Wayfair's Press & Hold needed super=true plus render=true. The harder the CAPTCHA leans on the browser, the more browser you need to send. More detail is on the CAPTCHA handling page.

Where to Go From Here

Next time a checkbox pops up, remember that the decision already happened before it rendered. The box is how the site tells you it wasn't sure.

If you're building a site, start with a honeypot and a managed challenge before you reach for image grids. If you're scraping one, spend your effort on looking like a browser, not on solving puzzles.

Get 1000 free credits and start scraping with Scrape.do

Frequently Asked Questions

How do I enter a CAPTCHA correctly?

Type characters exactly as shown, but don't worry about capitals, since most text CAPTCHAs ignore case. On image grids, select every tile that contains any part of the object, then press verify. If you keep failing, reload for a new challenge, turn off your VPN, and allow the CAPTCHA script in your ad blocker.

What's the difference between CAPTCHA and reCAPTCHA?

CAPTCHA is the general idea: any automated test that separates humans from bots. reCAPTCHA is Google's CAPTCHA product, which started in 2007 and now includes the v2 checkbox, invisible v2, and the score-based v3.

What are the different versions of reCAPTCHA?

reCAPTCHA v1 used distorted text and was shut down in 2018. v2 has the "I'm not a robot" checkbox and an invisible variant that only challenges suspicious users, and v3 returns a score without ever showing a challenge. Since April 2026 all of them sit under Google Cloud Fraud Defense, and the free tier covers 10,000 assessments a month (Google).

What is the best CAPTCHA to use?

For most sites, a managed challenge like Cloudflare Turnstile plus a honeypot field is the best balance: invisible for nearly everyone, free, and far more accessible than puzzles. Skip math and text CAPTCHAs, which bots solve without trouble and which frustrate real users.

Are CAPTCHAs accessible?

Mostly not. The W3C says CAPTCHAs inherently exclude many people with disabilities, and audio alternatives don't fix it. Blind users solved only 43% of audio CAPTCHAs on the first try in one study. Invisible checks, honeypots, and managed challenges are the more accessible options.