// vendor intelligence
what hcaptcha detects
hcaptcha is a captcha vendor. it declares native challenge (3/3), strong behavioral (2/3), partial js fingerprint (1/3) capability. below: the layers it enforces and the cookie, endpoint, and header tells it leaves.
catalog data undated confirmed
enforced detection layers
| detection layer | capability | what it covers |
|---|---|---|
| tls / network fingerprint | unaddressed | the ja3/ja4 clienthello and http/2 settings signature the edge reads before any javascript runs. |
| ip reputation | unaddressed | asn, proxy-class, and abuse-history scoring of the connecting address. |
| js fingerprint | 1/3 partial | canvas, webgl, navigator, font, and audio signals collected in-page. |
| behavioral | 2/3 strong | mouse, keyboard, and timing biometrics read from interaction cadence. |
| challenge | 3/3 native | interactive or invisible captcha and proof-of-work gates. |
| attestation | unaddressed | hardware or os-backed integrity checks (webauthn, play integrity, device attestation). |
| server coherence | unaddressed | cross-checking headers, tls, ip, and js for internal consistency. |
unaddressed means this tool type does not operate at that layer, so it is not a failing score. a red 0/3 is a real, declared score of zero. both are declared capability, not live pass-rates.
tells
- cookies
- hmt_id
- endpoints
- hcaptcha.com/getcaptcha, hcaptcha.com/checkcaptcha
- header tells
- hmt_id, h-captcha-response
- gate token
- h-captcha-response
image-grid by default; enterprise adds a passive risk score. inverted polarity: 1.0=high threat (bad), 0.0=human (good).
questions
- what does hcaptcha detect?
- it declares native challenge (3/3), strong behavioral (2/3), partial js fingerprint (1/3) capability. layers not listed are not enforced by hcaptcha.
- what are hcaptcha's tells?
- header/script tells: hmt_id, h-captcha-response. cookies: hmt_id. endpoints: hcaptcha.com/getcaptcha, hcaptcha.com/checkcaptcha.
sites defended by this vendor
other vendors
where to go from here
layer intensities are catalog-declared (0..3), confirmed, and the catalog carries no capture date for this record. layer definitions in the glossary.