CAPTCHAs vs Arcjet

Looking for a reCAPTCHA, hCaptcha, or Turnstile alternative?

12 min read
In short: Turnstile, reCAPTCHA, and hCaptcha put a challenge widget on a page and verify its token on your server. Arcjet detects bots in your request handlers, with optional browser signals stored in a reusable cookie, and combines them with rate limits and Shield WAF in one decision.

CAPTCHAs vs Arcjet

Cloudflare Turnstile, Google reCAPTCHA, and hCaptcha are CAPTCHAs: each puts a challenge widget on a page, and your server verifies the token that the widget produces. Arcjet takes a different approach: server-side bot detection in your request handlers, optionally layered with advanced client signals collected in the browser without a widget or puzzle.

The key difference is coverage. A CAPTCHA needs a page that can render its widget, and a Turnstile token is valid for 300 seconds and a single use, while Arcjet also covers APIs, rate limits, and the rest of your application in one decision, billed at $5 per million web requests. If you're looking for a reCAPTCHA alternative, an hCaptcha alternative, or a Turnstile alternative that covers more than forms, Arcjet fits. A CAPTCHA still makes sense when you want the user to see an explicit verification step.

Arcjet publishes this comparison. Competitor details come from Cloudflare's, Google's, and hCaptcha's public documentation, reviewed on September 25, 2026. Products change, so check the linked sources before you decide.

How do CAPTCHAs work?

Turnstile, reCAPTCHA, and hCaptcha follow the same pattern: a client-side widget runs a challenge, the form submits a token, and your server calls the provider to verify the token. If verification passes, the server allows the request.

Turnstile offers three widget modes: Managed chooses between a non-interactive challenge and a checkbox based on visitor risk, Non-interactive shows a spinner while challenges run, and Invisible runs in the background. Cloudflare describes Turnstile challenges that include "proof-of-work (computational puzzles), proof-of-space, probing for web APIs," and checks for browser quirks and human behavior.

Turnstile tokens are valid for 300 seconds and are single-use, and server-side validation is mandatory. You can embed Turnstile without routing traffic through Cloudflare.

reCAPTCHA is part of Google Cloud Fraud Defense, the name Google gave the product in April 2026, with existing keys and pricing unchanged. reCAPTCHA v2 is a checkbox or invisible challenge, and v3 runs with no user interaction and returns a score where "1.0 is very likely a good interaction, 0.0 is very likely a bot," which you turn into a policy. hCaptcha offers visible and invisible modes, and its Pro and Enterprise plans add passive modes, with risk scores on Enterprise.

A CAPTCHA needs a client that can render the widget or run the vendor's SDK. reCAPTCHA and hCaptcha publish mobile SDKs, and Turnstile runs in a WebView inside native apps. Server-to-server calls, API clients, and routes with no page to embed a widget on have no place to run a challenge.

How do Arcjet advanced bot signals work?

Arcjet's answer to the same form-spam problem is server-side bot detection in your request handlers, with advanced client signals as an optional layer. Arcjet uses no puzzle and no synchronous verification call on submit.

A small Arcjet script loads a WebAssembly module on a page that leads into a sensitive route. The module collects signals about the browser environment and sends them to Arcjet, which returns a continue token that the browser stores in the aj_signals cookie. On the next server-side request, the detectBot rule reads that cookie alongside user agent classification and IP reputation. The cookie stays valid for a period of time, so later requests reuse it instead of collecting signals again on every page load.

The Arcjet signals design has the following consequences:

  • One bot decision: Arcjet can deny a request because the signals look automated, because the user agent matches a known scraper, or because the IP has a poor reputation.
  • A missing cookie is a signal: a filter rule can deny clients that never loaded the script.
  • Inspectable results: a denial from signals carries ARCJET_SIGNALS as the reason, so your response can differ by failure mode.
  • Safe rollout: live or dry run applies to signals, bot detection, and the missing-cookie filter. Operational HTTP rules for bots, Shield, filters, and rate limits change in the Arcjet Console, CLI, or MCP server without a redeploy.
  • Usage-based pricing: each protect() call counts as a web request, billed at $5 per million on Arcjet's pricing.

Arcjet bot detection, filters, and signals are HTTP controls in request handlers. The same SDK also covers rate limiting, Shield WAF, email validation, and checks on agent tool calls and jobs, with SDKs for JavaScript, TypeScript, Python, and Go.

CAPTCHAs and Arcjet at a glance

The following table compares Arcjet with Turnstile, reCAPTCHA, and hCaptcha across 11 areas, from the user challenge to scope beyond the form.

AreaArcjetCAPTCHAs (Turnstile, reCAPTCHA, hCaptcha)
User challengeNone. No widget.

Turnstile: none (Invisible, Non-interactive) or a conditional checkbox (Managed). reCAPTCHA v2: checkbox or image challenge; v3: none (score). hCaptcha: visible challenge or invisible.

What it detects

Known bots by name and category, IP reputation, and optional browser-environment signals from a WebAssembly module.

Proof-of-work and browser probing (Turnstile), risk scores (reCAPTCHA v3, hCaptcha Enterprise), or a human challenge (reCAPTCHA v2, hCaptcha).

Server-side logic

One bot decision in your request handlers, combined with other rules.

The verifier returns pass or fail, or a score, for one token. Other server-side bot logic is yours to write.

Missing token or cookieA filter rule can deny requests without the signals cookie.A missing token fails verification on that submission.
API and non-browser clients

Server-side bot detection, filters, and rate limits work on any HTTP request. Signals add a layer for browser traffic.

Needs a page or app that runs the widget or SDK. reCAPTCHA and hCaptcha have mobile SDKs; Turnstile uses a WebView.

Token lifetimeThe signals cookie is reused across requests.

Turnstile tokens are valid for 300 seconds and single-use, so each protected submission needs a fresh token and a verification call.

RolloutPer-rule live or dry run. Review would-be denials, then promote.

Mode is set per widget or key. Score thresholds are applied in your code.

Decision detail

Structured reason, such as a known bot or ARCJET_SIGNALS.

Pass or fail, or a score from 0.0 to 1.0 that you turn into policy.

AccessibilityNo user interaction.

Cloudflare states that

Turnstile is WCAG 2.2 AA compliant

. reCAPTCHA v2 offers an audio challenge. The W3C documents

accessibility problems with CAPTCHAs

.

Pricing

Individual $25/month, Startup $299/month, Enterprise custom, plus $5 per million web requests.

Turnstile:

free with unlimited challenges

and up to 20 widgets. reCAPTCHA:

Essentials free up to 10,000 assessments a month

; Premium $8 flat for 10,001–100,000, then $1 per 1,000. hCaptcha: free Basic; Pro $99/month billed yearly with 100K evaluations.

Scope beyond the form

Same SDK: rate limiting, Shield WAF, email validation, sensitive information, and agent tool-call policy.

Bot challenges for protected pages and apps. reCAPTCHA adds account and fraud defense features on paid tiers.

Do CAPTCHAs stop AI agents?

Not reliably. Researchers at ETH Zurich reported that an image-recognition model solved 100% of reCAPTCHA v2 image challenges, and AI agents can load pages, store cookies, and submit forms. Google's Fraud Defense launch added an agentic policy engine and a QR-code challenge aimed at AI agents.

A CAPTCHA protects a browser-rendered form, which is inbound bot management: stop automated clients that submit a signup or target /login. Server-side context – rate limits, IP reputation, and the route's own rules – gives you a second layer behind any challenge.

A CAPTCHA isn't a control on the agents that you run. Arcjet bot detection, filters, Shield WAF, email validation, and IP checks run in your request handlers. Arcjet's guard() runs prompt-injection detection, token budgets, sensitive-information checks, and destination threat analysis on tool handlers, MCP servers, and queue consumers, where you pass the input directly. For coding agents such as Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code, Arcjet applies policy from the hooks they already fire.

If the thing that you're protecting is an MCP tool or a background job, a CAPTCHA has no page to run on. If the thing is a public form, signals plus server-side bot detection are the Arcjet alternative to embedding a widget. For more information, see CAPTCHA alternatives and AI agent bot management.

Which fits: a CAPTCHA, Arcjet, or both?

Use Arcjet when you need bot protection on APIs as well as forms, with no visible widget, and use a CAPTCHA when you want the user to see an explicit verification step. The following sections describe the fit for each approach.

Use Arcjet if

Use Arcjet if any of the following apply:

  • You need to protect API endpoints as well as forms.
  • You want no visible widget.
  • You want a signal that later requests reuse instead of a single-use token.
  • You want layered detection in one bot decision, with inspectable reasons.
  • You want dry run before enforcement.
  • You also need rate limiting, Shield WAF, and agent tool-call policy in the same SDK.

Use a CAPTCHA if

Use a CAPTCHA if any of the following apply:

  • You need a free, client-side starting point for form spam.
  • You want users to see an explicit verification step, such as on account recovery or a high-value confirmation.
  • Every protected action goes through a browser form or a mobile app with the vendor's SDK.

Use both

A CAPTCHA and Arcjet can run together. A common split is a visible CAPTCHA on account recovery, with Arcjet on APIs, rate limits, signups, and the agent tool path.

What are the alternatives to reCAPTCHA, hCaptcha, and Turnstile?

Each CAPTCHA product has two kinds of alternative: server-side bot detection such as Arcjet, and another widget. The following sections cover the alternatives to each CAPTCHA product, with Arcjet first.

reCAPTCHA alternative

Arcjet replaces the reCAPTCHA v2 checkbox and the v3 score-threshold code with server-side bot detection and optional advanced signals, billed as part of each protect() call. Other reCAPTCHA alternatives include Turnstile and hCaptcha, which keep the widget model.

hCaptcha alternative

Arcjet replaces the hCaptcha widget with bot detection in your request handlers and a signals cookie that later requests reuse. Other hCaptcha alternatives include Turnstile, which is free with unlimited challenges, and Friendly Captcha, which uses proof-of-work and risk signals instead of a visible puzzle.

Turnstile alternative

Arcjet covers routes that Turnstile can't reach without a page – APIs, server-to-server calls, and agent tools – and returns a reusable signal instead of a 300-second single-use token. Other Turnstile alternatives include reCAPTCHA and hCaptcha, and on Vercel, Vercel BotID. For edge bot scoring, see Cloudflare vs Arcjet.

Frequently asked questions

What is a good reCAPTCHA alternative?

Arcjet replaces the reCAPTCHA v2 checkbox and the v3 score-threshold code with bot detection in your request handlers, optionally layered with browser signals collected without a widget, and billed as part of each protect() call. Turnstile and hCaptcha are alternatives that keep the widget model. reCAPTCHA is part of Google Cloud Fraud Defense, with a free Essentials tier up to 10,000 assessments a month.

What is a good hCaptcha or Turnstile alternative?

Arcjet is an alternative to both that also covers API endpoints and server-to-server calls, where a widget can't run. Arcjet returns a signal stored in a cookie that later requests reuse, instead of a single-use token – Turnstile tokens are valid for 300 seconds. Friendly Captcha and reCAPTCHA are other widget-based options.

Can I use a CAPTCHA and Arcjet together?

Yes. You might use a CAPTCHA for an explicit high-value step such as account recovery, and Arcjet for API protection, rate limiting, bot detection on HTTP routes, Shield WAF, and checks on agent tool calls. A CAPTCHA and Arcjet operate independently, so a CAPTCHA token check and an Arcjet decision can both run on the same route without conflict.

Do Arcjet advanced signals replace a CAPTCHA entirely?

For HTTP bot protection without a widget, yes: signals plus server-side bot detection classify automation without a challenge. For a visible, deliberate human checkpoint such as a high-value account action, a CAPTCHA still makes sense as an explicit step the user sees.

What happens if a user has JavaScript disabled?

If JavaScript is disabled, the Arcjet signals script doesn't run and the aj_signals cookie isn't set. A filter rule can block requests missing the cookie, which blocks non-JavaScript clients. Alternatively, don't require the cookie for already-authenticated users. The right policy depends on your audience and risk tolerance.

Bot detection without a widget

Protect your application with Arcjet

Get advanced signals plus server-side bot classification in your request handlers, with no puzzle on submit.