The privacy-first, self-hosted CAPTCHA for the modern web. http://capjs.js.org/
  • JavaScript 88.8%
  • CSS 8.9%
  • Rust 1.5%
  • HTML 0.8%
Find a file
2026-10-09 17:19:07 +01:00
.github feat(widget@0.1.58): solve hashwx challenges 2026-09-23 17:52:15 +01:00
assets update animated captcha svg 2026-03-30 18:40:02 +01:00
core fix(core): load hashwx wasm as a precompiled module on workers 2026-10-09 17:19:07 +01:00
demo fix(demo): bundle widget translations 2026-09-23 17:52:15 +01:00
docs fix(core): load hashwx wasm as a precompiled module on workers 2026-10-09 17:19:07 +01:00
standalone fix(standalone): set oci image source label on docker image 2026-10-04 17:26:39 +01:00
wasm feat(wasm@0.0.8): ship hashwx.wasm 2026-09-23 17:52:15 +01:00
widget feat(widget@0.1.58): solve hashwx challenges 2026-09-23 17:52:15 +01:00
.gitattributes chore: add theme css to gitattributes 2026-02-28 22:19:35 +00:00
.gitignore chore: ignore bench 2026-09-23 17:52:15 +01:00
biome.json feat(core@0.1.0): introduce capjs-core stateless server library 2026-05-10 16:30:41 +01:00
CNAME add cname file for github pages 2025-04-10 17:40:16 +01:00
CONTRIBUTING.md feat: small website and readme copy changes :3 2026-10-03 11:43:37 +01:00
LICENSE another license fix. 2025-09-26 15:56:36 +01:00
README.md feat: small website and readme copy changes :3 2026-10-03 11:43:37 +01:00
SECURITY.MD feat: small website and readme copy changes :3 2026-10-03 11:43:37 +01:00


cap logo

a privacy-first and self-hosted CAPTCHA.
read the docs or try the demo


cap widget

what's cap?

cap is a self-hosted and privacy-first captcha alternative that doesn't force your users to click on traffic lights. there are no puzzles, no tracking, and no third parties watching your visitors.

instead, the user's browser quietly solves a few small challenges in the background, such as gpu-resistant proof-of-work and instrumentation, which can also be configured to stop autonomous AI agents from using up your resources.

it has no dependencies by default, is 200x smaller than hCaptcha, and you can run it with docker, on workers or on railway. it's already used in production by large companies like bunny.net and adguard.

license

cap is licensed under apache 2.0.


OpenSSF Best Practices jsdelivr