# hCaptcha

**Canonical:** https://apis.io/providers/hcaptcha/  
**Website:** https://www.hcaptcha.com/  
**APIs profiled:** 6

hCaptcha, operated by Intuition Machines, is a privacy-focused CAPTCHA and bot-defense platform used as a drop-in replacement for Google reCAPTCHA. The free Publisher and Pro tiers offer a JavaScript widget and a server-side /siteverify endpoint that issue and verify single-use tokens. The Enterprise tier (hCaptcha Enterprise) adds advanced bot detection, account defense, MFA, machine-learning fraud signals, and management APIs. hCaptcha is broadly integrated into web frameworks and CMS platforms (React, Vue, Angular, Node/Express, WordPress, Magento) and ships first-party mobile SDKs for iOS and Android.

## Kin Score — 40.5 / 100 (developing)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 40.5).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 52.4 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 23.7 |
| Developer Ergonomics | 21.4 |
| Commercial Clarity | 63.2 |
| Access Clarity | 63.2 |

## Agent readiness — 19.8 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Free · Self-serve signup — onboarding: self-serve, pricing: free, trial: no (confidence: high).

## APIs (6)

- **hCaptcha Siteverify API** — The /siteverify endpoint validates an hCaptcha response token submitted by a browser. The server POSTs the token, secret key, and optional remote IP, and receives a JSON respons...
- **hCaptcha JavaScript Widget** — The hCaptcha JS widget renders the visible or invisible challenge on a page and produces a response token on success. Developers include a script tag pointing at js.hcaptcha.com...
- **hCaptcha Invisible** — Invisible hCaptcha runs the challenge in the background and only surfaces a visible puzzle when risk requires it. It is configured via the same widget script and an additional d...
- **hCaptcha Mobile SDKs** — hCaptcha publishes native iOS and Android SDKs (with React Native and Flutter wrappers) so mobile apps can present the same risk-based challenges as the web widget and obtain re...
- **hCaptcha Enterprise** — hCaptcha Enterprise extends the core challenge with advanced bot detection, account defense (ATO and fake-account protection), MFA and pull-based SMS, fraud signals, and managem...
- **hCaptcha Siteverify API** — The Siteverify API from hCaptcha — 1 operation(s) for siteverify.

## Agentic access (1)

- **Hcaptcha Agentic Access** — 1 operation · 1 acting

## Security (2)

- **Hcaptcha Authentication** — apiKey · 1 scheme
- **Hcaptcha Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Plans (1)

- **Hcaptcha Plans Pricing**

## Tags

CAPTCHA, Bot Defense, Privacy, hCaptcha, Intuition Machines, Account Defense, Enterprise Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/hcaptcha/). Scores are computed from the provider's own public artifacts under a published rubric.
