Abstract
A feedback form meant for connection, quickly overrun by bots. Messages no longer authentic, buried in floods of fake submissions. Each day heavier, inbox unusable, trust eroded. The tools available asked too much—servers to manage, privacy surrendered, design locked away. Then came discovery of Cap, a proof-of-work CAPTCHA light and direct. No tracking, no infrastructure, only computation as barrier. That concept sparked Capybara, adapted for Cloudflare Workers, reshaped to match the constraints of cost, privacy, and simplicity. From a small necessity, a new approach emerged.
| CAPTCHA | Open | Free | Fast solve | Easy use | Customizable | Integrating |
|---|---|---|---|---|---|---|
| Capybara | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Cloudflare Turnstile | ✗ | ✓ | Medium | ✓ | ✗ | ✓ |
| reCAPTCHA | ✗ | Limited | ✓ | ✗ | ✗ | ✓ |
| hCAPTCHA | ✗ | Limited | ✗ | ✗ | ✗ | ✓ |
| Altcha | ✓ | ✓ | ✓ | ✓ | ✓ | Medium |
| FriendlyCaptcha | ✗ | ✗ | Medium | ✓ | ✓ | Medium |
| MTCaptcha | ✗ | Limited | ✗ | ✗ | ✗ | Medium |
| GeeTest | ✗ | ✗ | Medium | Medium | ✗ | Medium |
| Arkose Labs | ✗ | ✗ | ✗ | ✗ | Medium | Difficult |
Tip (Project beginning)
Timeline: A personal struggle turned open-source tool
Trigger: Spam overwhelming a simple form
Constraint: Zero budget, no servers
Solution: Serverless Proof of Work
Inspiration: capjs.js.org refined through Cloudflare Workers
The Problem
The attack on the form exposed truth about CAPTCHA choices. Expensive systems demanding servers. Privacy breached through surveillance. Free tiers stripped of flexibility. For one developer, no path forward. Limited resources, firm values, but need for control. A solution absent, yet essential.
Server budget available
Privacy commitment required
Customization options in free tiers
Important (Critical realization)
A path needed: respect privacy, demand no servers, adapt to unique design, remain free.
Discovery Proof of Work
Research brought me to proof-of-work approaches, simple yet sharp. Instead of tracking behaviors or building profiles, it leaned on puzzles. Tasks trivial for humans yet costly for bots. Computation became shield, not surveillance. Load adjustable, fairness preserved, privacy untouched.
Challenge–response: provider sets puzzle, client answers, difficulty tuned in real time.
Solution–verification: puzzle chosen by client, provider checks, no fixed link required. Methods iterative, probabilistic, echoing Hashcash.
Solution
Capybara built on this logic. Proof of Work merged with Cloudflare Workers, serverless at the edge. Design priorities fixed: no servers, no surveillance, full control, smooth integration. Each constraint shaped the architecture. Workers as gatekeepers. KV storage for state. Edge delivery for speed. Free plan covering scale. Reliability without cost, flexibility without compromise.
- 404 on /api/*: path misconfigured
- Redirect incorrect?: set
REDIRECT_URL - Rate limit failing?: confirm KV set, adjust limits
Integration & KV Flow
Challenge Lifecycle
KV Structure
Implementation
Three endpoints at core. Challenge generation, retrieval, verification. Minimal, efficient, transparent.
POST /api/challenge → ( id, nonce, difficulty, duration )GET /api/challenge/:id → ( nonce, difficulty, duration )POST /api/verify → ( id, solution ) → ( success: boolean )Privacy anchored each choice. No cookies, no tracking, only ephemeral storage. IP-based limits, data discarded. Sessions absent, freedom intact.
Performance tuned. Edge latency minimized. Storage tiny. Throughput massive, free tier sufficient.
Average response time
Storage per challenge
Daily requests (free tier)
Results
Spam gone. Messages genuine. Privacy preserved. Cost zero. Uptime continuous through Cloudflare’s edge. What started as a shield for one developer became usable by many. Open-sourced, improved, adopted. Feedback confirmed trust: privacy valued, simplicity embraced.
Remark (Community feedback)
“Finally, a CAPTCHA that respects users. Simple, effective, private.” – Open Source User
Learning Journey
Pain points personal, but universal. Privacy not an afterthought, but feature. Serverless unlocked possibility, letting small projects rival giants. Open source established credibility, trust built on transparency.
FAQ
- Dependent on upstream? No, independent with KV storage.
- Multiple deployments? Yes, set unique
INSTANCE_ID. - Original code needed? No, Worker self-contained.
Conclusion
Capybara demonstrated that limits could drive creation. Budget absent, privacy absolute, customization required. The result surpassed what established services offered. Security without surveillance, architecture without servers, integration without friction. Proof that constraints sharpen solutions, guiding toward tools both effective and humane.
Related Posts
Developing Capybara
Technical depth: architecture, API, deployment strategies.
JWT Payload Implementation
Exploring the token system behind secure verification.
References
- Wikipedia contributors. Proof of work. Wikipedia. Retrieved August 30, 2025, from https://en.wikipedia.org/wiki/Proof_of_work
- Tiago. Quickstart | Cap. Cap.js. Retrieved August 30, 2025, from https://capjs.js.org/guide
Got something in mind?
✳︎ ask me anything ✳︎