Three open-source CAPTCHAs can replace reCAPTCHA on infrastructure you control. Instead of an image puzzle, each makes the visitor's browser solve a proof of work, but they plug in very differently. ALTCHA is a widget plus a server library that lives inside your existing backend, with risk-based challenges kept for its paid plans. Cap is a Docker server with a dashboard, and its verification endpoint takes the same parameters as Google's. mCaptcha, a Rust server that raises the difficulty as traffic climbs, has shipped a single release, in March 2024, and its maintainer says he has lost faith in proof of work.
How a proof-of-work CAPTCHA works, and what it costs
A proof-of-work CAPTCHA asks the visitor's machine for computation instead of asking the visitor a question. The server issues a challenge, the browser tries numbers until one produces a hash that meets the target, and the server checks the answer with a single computation. In ALTCHA, the browser searches in Web Workers for the counter whose derived key starts with the required prefix, using PBKDF2 with SHA-256 by default.
Human visitors pay in seconds. At Cap's default difficulty, the median solve took 578 ms on an 8-core desktop running Chrome, and 1.1 to 5.9 seconds on the phones the project measured. mCaptcha's README promises zero to two seconds depending on the site's load.
Bots pay in hardware. An analysis posted in issue #186 on mCaptcha's repository produced about 250 valid proofs per second on a single Ryzen 9 7950X at the hardest default level, while the server only handled about 650 requests per second carrying invalid proofs: a protection margin under 3x. The maintainer confirmed the findings in June 2026, and wrote that proof of work puts trivial compute demands on LLM crawlers.
GPUs widen the gap on SHA-256. By the measurements of tevador, quoted in Cap's docs, a GPU clears about 150 times as many SHA-256 challenges as a CPU, but only about twice as many with HashWX, which generates a fresh hash function for each challenge and is the default for new keys on Cap's server. ALTCHA offers Argon2id and scrypt for the same reason: memory-hard algorithms, loaded as separate workers. mCaptcha sticks with SHA-256, and its maintainer ruled out defenses against SIMD or ASIC solvers because they would make the web worse for ordinary visitors.
What each tool adds on top of the computation
mCaptcha scales the difficulty with load. Each site key has a visitor counter that rises with every visit and falls after a cooldown, and each visitor threshold carries its own difficulty factor, from 50,000 to 5,000,000 by default in easy mode. The work follows the site's traffic, not how a given visitor behaves.
Cap adds a second challenge, on by default for new keys on its server: a JavaScript program generated for each request, which works on the DOM inside an iframe and whose result the server already knows. An optional setting also blocks automated browsers through seven checks. The docs list what still gets through: undetected-chromedriver and nodriver driving a headed Chrome, and headless Firefox. Against those, only the proof of work is left, and it makes each request cost more without stopping it.
ALTCHA's open-source version gives every visitor the same check. The project's comparison page keeps risk-based challenges, real-time threat intelligence and the dashboard for paying customers. Interaction-signal analysis is a Sentinel feature too, even though the widget collects those signals by default.
What each tool needs to run
Read from the repositories and documentation on 7 October 2026.
| Tool | Licence | What you run | Proof of work | Backend verification | Latest release |
|---|---|---|---|---|---|
| ALTCHA | MIT; Sentinel under a paid licence | a library inside your existing backend; a shared store such as Redis across instances | PBKDF2 and SHA-256, Argon2id or scrypt optional | in your backend, through the library | widget 3.3.0, 5 Oct 2026 |
| Cap | Apache-2.0 | one container on Bun plus Valkey or Redis, about 50 MB idle; or the capjs-core library | HashWX (SHA-256 in capjs-core), plus an instrumentation challenge | the instance's /siteverify, with secret and response as in reCAPTCHA | Standalone 3.1.14, 24 Sep 2026 |
| mCaptcha | AGPL-3.0 or later for the server, MIT or Apache-2.0 for the widget | a Rust binary and PostgreSQL; Redis with a custom module across instances; amd64 images only | SHA-256, difficulty set by traffic | /api/v1/pow/siteverify, in its own format | 0.1.0, 15 Mar 2024 |
ALTCHA has no server of its own. Its MIT libraries come in eleven languages, PHP, Go, Python, Java, Rust and .NET among them: your backend issues an HMAC-signed challenge, then verifies the solution. Replay protection is your backend's job as well. The altcha-lib plugins ship CappedMap, an in-memory store; across several instances, the docs call for a central store with an atomic setIfAbsent, otherwise two simultaneous submissions of the same challenge can both pass. On the JavaScript side, the library needs Node.js 20 or later and doesn't run on Bun or Deno.
Cap Standalone has kept all of its data in Valkey or Redis since v3, and runs on Bun at about 50 MB of memory when idle, per its docs. The instance must be reachable from the internet, behind a reverse proxy: Cap takes the client IP from X-Forwarded-For without checking it, so a container exposed directly lets anyone dodge its default limit of 30 requests per IP every five seconds. The capjs-core library does the same job statelessly with signed JWTs, inside an existing backend or on Cloudflare Workers, but replay protection is then up to you.
mCaptcha relies on PostgreSQL, and the bundled Compose file starts version 18. Without Redis, its visitor counters stay in process memory, which ties you to a single instance; with Redis you need the mcaptcha/cache image, which carries a custom module. No memory or CPU requirements are documented, a question open since August 2025 in issue #189. The credentials given in the README only exist in demo mode, which the Docker configuration turns off along with sign-up.
Swapping out reCAPTCHA's verification call
A backend protected by reCAPTCHA posts secret and response to Google and reads a success field back, as reCAPTCHA's verification docs describe. Cap Standalone's /siteverify takes the same parameters, as JSON and at your instance's URL, and the form sends a cap-token field instead of g-recaptcha-response. mCaptcha's website advertises APIs compatible with reCAPTCHA and hCaptcha, yet its documented endpoint expects token, key and secret and answers with valid, so the backend check has to be rewritten. ALTCHA has no remote call to swap: the library verifies the solution inside your backend.
Cap and mCaptcha also appear among the bot challenges of BunkerWeb, a web application firewall that sits in front of your apps as a reverse proxy and applies them per service.
What each tool keeps about visitors
ALTCHA, Cap and mCaptcha set no cookie by default. ALTCHA's widget submits its proof in a hidden form field, but the server can force a cookie through the X-Altcha-Config header. mCaptcha's CAPTCHA routes set none according to its README, and its website says it doesn't rate-limit by IP address, which spares visitors behind a NAT.
Cap Standalone's code keeps counters per site key: passed, failed and rate-limited challenges and latency, bucketed by hour, plus platform and OS parsed from the User-Agent. The IP address serves as the rate-limit key and expires a few seconds later. Country and ASN are recorded only if you configure them, through a proxy header or an IP database: DB-IP Lite or MaxMind GeoLite2 downloaded to the server, or the IPInfo API, which then receives every address.
In the browser, ALTCHA's open-source version talks to no third party. Cap's docs promise verification without third-party calls, yet its install tag loads the widget from cdn.jsdelivr.net, which also serves its two WASM files at solve time. mCaptcha's HTML snippet loads its integration script from unpkg.com. Keeping every request on your own domain means installing those packages from npm and serving them yourself, or, with Cap, turning on Standalone's asset server, which is off by default.
Accessibility and fallback challenges
ALTCHA and Cap both claim WCAG 2.2 AA conformance without citing an external audit. ALTCHA's compliance page leaves final responsibility with whoever integrates the widget. Cap's adds the European EN 301 549 standard and US Section 508, with a note that it describes how Cap is designed to support them and isn't legal advice. ALTCHA documents keyboard navigation, screen-reader labels and more than 50 languages. Its fallback challenge, a code read from an image or an audio clip, needs Sentinel or a server implementation of your own.
Solve time matters for access too: 1.1 to 5.9 seconds on phones at Cap's default difficulty, and HashWX needs WebAssembly, so for clients without it the key has to fall back to SHA-256. mCaptcha's README says nothing about accessibility, but the project documents a way through without JavaScript: a command-line tool computes the proof from the page URL, and the visitor pastes the resulting code into the form.
Licences and paid plans
ALTCHA's widget and its eleven server libraries are under MIT. Sentinel isn't: only its deployment scripts and Helm charts are on GitHub, it runs as a 30-day trial without a key, and production use needs a licence, from €99 a month for three instances and ten accounts, or €799 for Enterprise. ALTCHA's EU-hosted cloud starts at €47 a month for 1,000 requests a day and three sites; beyond that, requests get an HTTP 429 error and go unverified. The free WordPress plugin covers login, registration and comments, and protecting Contact Form 7 or WooCommerce takes the €18.90-a-month plan.
Cap is under Apache-2.0 across the whole repository, with no paid tier and no managed hosting; its docs send anyone unwilling to host anything to Turnstile or FriendlyCaptcha. mCaptcha's server is under AGPL-3.0 or later, so anyone running a modified version as a network service has to publish its source. Its widget is under MIT or Apache-2.0, your pick. The project sells nothing, and its README warns that the demo instances' database is "frequently wiped".
Where the projects stand
ALTCHA rewrote its widget and its proof-of-work protocol in v3.0.0 on 7 April 2026, then shipped 16 more releases up to v3.3.0 on 5 October. That release closes a verifySolution bypass in altcha/lib: without a key signature, any counter passed with no work done. The same day, altcha-lib 2.6.0 fixed a bypass in deterministic mode and two replay-protection flaws in its plugins, and the Go library had retracted v2.0.0 through v2.3.0 on 3 October. Updating the widget alone isn't enough; the server library has to follow.
Cap's repository dates from January 2025. Standalone has shipped 25 releases since January 2026, including v3 and its Valkey storage in April, and one developer wrote 668 of the 709 commits. The README names bunny.net and AdGuard among its production users.
mCaptcha's only release is v0.1.0, from 15 March 2024. The last commit landed on 7 October 2025, one developer wrote 761 of the 879 commits, and the README still reads "active development". In issue #186 the maintainer says he is "disillusioned with PoW"; his plan is to update dependencies, ship a release, then look for another approach, with Privacy Pass mentioned.
