A Practical Guide to CAPTCHA Alternatives
Ways to stop automated abuse without forcing people to solve puzzles.
The key figures
- Accessibility
- visual puzzles exclude people with disabilities
- WCAG 2.2
- expects alternatives to cognitive function tests in authentication
- Alternatives
- rate limiting, honeypots and risk scoring reduce abuse
- Invisible checks
- background risk assessment avoids user effort
Why this is worth getting right
CAPTCHAs exclude people with disabilities and frustrate everyone, and WCAG 2.2 discourages cognitive tests in authentication.
Do this, not that
Do
- Use rate limiting and server-side checks first
- Add honeypot fields invisible to users
- Use risk-based challenges only when needed
- Provide an accessible alternative to any challenge
- Monitor false positives
Don’t
- Image puzzles as the only protection
- Audio CAPTCHAs as the accessible fallback alone
- Challenges on every submission
- Blocking users with no route forward
When to bring in help
Our advice Bring in help when spam protection blocks real users.
Where this comes from
- W3C Web Accessibility Initiative — Inaccessibility of CAPTCHA
- OWASP — Automated Threats to Web Applications
The figures and practices above come from the sources listed.
Working on something like this?
We take on Performance & Accessibility work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.