Capybara: PoW based & Serverless CAPTCHA
Overview
zamkara.uk
Client Logo

Capybara: PoW based & Serverless CAPTCHA

September 29, 2025
3 min read (13 min read total)
2 subposts
Share this article
index

Abstract

A feedback form meant for connection, quickly overrun by bots. Messages no longer authentic, buried in floods of fake submissions. Each day heavier, inbox unusable, trust eroded. The tools available asked too much—servers to manage, privacy surrendered, design locked away. Then came discovery of Cap, a proof-of-work CAPTCHA light and direct. No tracking, no infrastructure, only computation as barrier. That concept sparked Capybara, adapted for Cloudflare Workers, reshaped to match the constraints of cost, privacy, and simplicity. From a small necessity, a new approach emerged.

Capybara CAPTCHA Demonstration
CAPTCHAOpenFreeFast solveEasy useCustomizableIntegrating
Capybara✓✓✓✓✓✓
Cloudflare Turnstile✗✓Medium✓✗✓
reCAPTCHA✗Limited✓✗✗✓
hCAPTCHA✗Limited✗✗✗✓
Altcha✓✓✓✓✓Medium
FriendlyCaptcha✗✗Medium✓✓Medium
MTCaptcha✗Limited✗✗✗Medium
GeeTest✗✗MediumMedium✗Medium
Arkose Labs✗✗✗✗MediumDifficult
Tip (Project beginning)

Timeline: A personal struggle turned open-source tool
Trigger: Spam overwhelming a simple form
Constraint: Zero budget, no servers
Solution: Serverless Proof of Work
Inspiration: capjs.js.org refined through Cloudflare Workers


The Problem

The attack on the form exposed truth about CAPTCHA choices. Expensive systems demanding servers. Privacy breached through surveillance. Free tiers stripped of flexibility. For one developer, no path forward. Limited resources, firm values, but need for control. A solution absent, yet essential.

$0

Server budget available

100%

Privacy commitment required

Limited

Customization options in free tiers

Important (Critical realization)

A path needed: respect privacy, demand no servers, adapt to unique design, remain free.


Discovery Proof of Work

Research brought me to proof-of-work approaches, simple yet sharp. Instead of tracking behaviors or building profiles, it leaned on puzzles. Tasks trivial for humans yet costly for bots. Computation became shield, not surveillance. Load adjustable, fairness preserved, privacy untouched.

Challenge–response Source Wikipedia

Challenge–response: provider sets puzzle, client answers, difficulty tuned in real time.
Solution–verification: puzzle chosen by client, provider checks, no fixed link required. Methods iterative, probabilistic, echoing Hashcash.

souce:Solution–verification Source Wikipedia

Solution

Capybara built on this logic. Proof of Work merged with Cloudflare Workers, serverless at the edge. Design priorities fixed: no servers, no surveillance, full control, smooth integration. Each constraint shaped the architecture. Workers as gatekeepers. KV storage for state. Edge delivery for speed. Free plan covering scale. Reliability without cost, flexibility without compromise.

  • 404 on /api/*: path misconfigured
  • Redirect incorrect?: set REDIRECT_URL
  • Rate limit failing?: confirm KV set, adjust limits

Integration & KV Flow

Integration & KV Flow

Challenge Lifecycle

Challenge

Verification

KV Structure

KV Structure


Implementation

Three endpoints at core. Challenge generation, retrieval, verification. Minimal, efficient, transparent.

POST /api/challenge → ( id, nonce, difficulty, duration )
GET /api/challenge/:id → ( nonce, difficulty, duration )
POST /api/verify → ( id, solution ) → ( success: boolean )

Privacy anchored each choice. No cookies, no tracking, only ephemeral storage. IP-based limits, data discarded. Sessions absent, freedom intact.

Performance tuned. Edge latency minimized. Storage tiny. Throughput massive, free tier sufficient.

~50ms

Average response time

5KB

Storage per challenge

100K

Daily requests (free tier)


Results

Spam gone. Messages genuine. Privacy preserved. Cost zero. Uptime continuous through Cloudflare’s edge. What started as a shield for one developer became usable by many. Open-sourced, improved, adopted. Feedback confirmed trust: privacy valued, simplicity embraced.

Remark (Community feedback)

“Finally, a CAPTCHA that respects users. Simple, effective, private.” – Open Source User


Learning Journey

Pain points personal, but universal. Privacy not an afterthought, but feature. Serverless unlocked possibility, letting small projects rival giants. Open source established credibility, trust built on transparency.


FAQ

  • Dependent on upstream? No, independent with KV storage.
  • Multiple deployments? Yes, set unique INSTANCE_ID.
  • Original code needed? No, Worker self-contained.

Conclusion

Capybara demonstrated that limits could drive creation. Budget absent, privacy absolute, customization required. The result surpassed what established services offered. Security without surveillance, architecture without servers, integration without friction. Proof that constraints sharpen solutions, guiding toward tools both effective and humane.

Related Posts


References

  1. Wikipedia contributors. Proof of work. Wikipedia. Retrieved August 30, 2025, from https://en.wikipedia.org/wiki/Proof_of_work
  2. Tiago. Quickstart | Cap. Cap.js. Retrieved August 30, 2025, from https://capjs.js.org/guide

Got something in mind?

✳︎ ask me anything ✳︎

Yo, you open for freelance right now?