ADAPTIVE HUMAN VERIFICATION

Human by design.Automation denied.

NexaCAPTCHA keeps verification clear for legitimate users while increasing the time, computation, and uncertainty required for automated solving.

  • Designed for human readability
  • 17.6% model success in our Gravity test
  • Two attempts before expiry

CAPTCHA MODULES

Available verifications.

LIVE DEMO

Try NexaCAPTCHA Gravity

Ready

Gravity presents four distorted characters in a static image. Read all four, or use the Audio button to hear them.

Open the full Gravity demo
Your result will appear here.
Use the hosted service Add NexaCAPTCHA with the official browser loader. Self-host NexaCAPTCHA Run the compatible service on your own infrastructure.

VERIFICATION TEST

Verification performance, measured.

All agents started without prior context and developed their approach during the test.

Tested build
Verification system Human GPT 5.6 Sol - Medium
NexaCAPTCHA Gravity 3.8 seconds average 17.6% success rate · 31.6 seconds average
Google reCAPTCHA 1.9 seconds average 99% success rate · 7.6 seconds average
hCaptcha 11.8 seconds average 85.7% success rate · 49.6 seconds average

This is a recorded test, not a promise that every model or every run will behave the same way.

INTEGRATION

Connect NexaCAPTCHA.

Add Gravity to your page, then pass the completed result to your backend.

01

Frontend setup

Load Gravity below. The callback name and submission logic are yours to change.

Frontend loader
Gravity loader https://nexacaptcha.nxlabtw.com/captcha/gravity.js
HTML · page markup
<script
  src="https://nexacaptcha.nxlabtw.com/captcha/gravity.js"
  defer
></script>

<div
  class="nexa-captcha"
  data-callback="onCaptchaComplete"
></div>

Choose your own callback name if you prefer. Use exactly the same name in the HTML and JavaScript.

JavaScript · frontend
function onCaptchaComplete(result) {
  if (!result.success) return;

  yourSubmitFunction({
    verificationId: result.verificationId,
    responseToken: result.responseToken
  });
}

The callback is a frontend handoff, not final proof. Accept the form only after /api/siteverify returns success: true.

02

Callback parameters

The callback receives one result object with these fields.

result
The object passed into your callback function.
result.success
A boolean. It is true when the verification has been completed.
result.verificationId
The 16-character verification ID. Send it to your backend.
result.responseToken
The 64-character one-time token. Send it to your backend without changing it.

BACKEND VERIFICATION

Validate every response server-side.

Before accepting a form submission, registration, or login, send both values to NexaCAPTCHA.

POST/api/siteverify

Request

{
  "verificationId": "<verificationId>",
  "responseToken": "<responseToken>"
}

Response · success

{
  "success": true,
  "verifiedAt": "2026-08-07T12:30:00.000Z"
}

Response · failure

{
  "success": false,
  "errorCode": "invalid-or-expired-verification"
}
Node.js · backend
const response = await fetch(
  "https://nexacaptcha.nxlabtw.com/api/siteverify",
  {
    method: "POST",
    headers: { "Content-Type": "application/json" },
    body: JSON.stringify({
      verificationId,
      responseToken
    })
  }
);

const result = await response.json();
if (!result.success) {
  return res.status(403).send("Verification failed");
}