{"repo":"WebDecoy/FCaptcha","free":true,"listed":false,"github":"https://github.com/WebDecoy/FCaptcha","clone":"git clone https://github.com/WebDecoy/FCaptcha.git","description":"Open-source, invisible CAPTCHA that detects AI agents, bots, and headless browsers via 40+ behavioral signals, device & TLS fingerprinting, and SHA-256 proof of work. Self-hosted and privacy-first.","language":"JavaScript","stars":187,"topics":["anti-bot","behavioral-analysis","bot-detection","captcha","fingerprinting","go","headless-browser-detection","nodejs","proof-of-work","python"],"license":"MIT","category":"ai-agents","readme_excerpt":"F Captcha Open source CAPTCHA that blocks bots, vision AI agents, and automation - with a single click or less. Try the Live Demo FCaptcha is a modern CAPTCHA system designed to detect everything: traditional bots, headless browsers, automation frameworks, CAPTCHA farms, and the new generation of AI agents — from vision models that screenshot-and-click to computer-use agents that drive a real browser over the Chrome DevTools Protocol. Features - Drop-in for Turnstile / reCAPTCHA / hCaptcha - Serves the same siteverify contract on the same paths, so migrating an existing backend is a base-URL change; tokens carry a signed hostname and action your app can check - Single click or invisible - Checkbox mode like Turnstile/reCAPTCHA v2, or invisible mode like reCAPTCHA v3 - AI agent detection - Catches vision agents (screenshot→API→click), DOM/CDP-driven agents (Claude in Chrome, Operator-style computer use), and synthetic input that reports isTrusted: true — via input-event forensics and LLM think-time cadence - Declared & verified agents - Flags self-declaring agents (ClaudeBot, GPTBot, ChatGPT-User, PerplexityBot, Bytespider…) and cryptographically verifies Web Bot Auth (RFC 9421) signed requests against the agent's published key directory, surfaced as a distinct category so your app can allow polite/verified agents and block the rest - Proof of Work - Server-verified SHA-256 hashcash with 256-bit HMAC signing, per-challenge nonces, and signal commitment that binds the challenge","default_branch":null,"files":null,"tree":[],"storefront":"/r/WebDecoy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/WebDecoy/FCaptcha/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}