Skip to content

5.9.0 ​

API ​

API v5.9.0 — Proof of work & captcha challenge.

  • Added endpoint GET /pow: a proof of work replacing the captcha — the server issues a salt and a difficulty, the client looks for a nonce whose sha256 fingerprint starts with that many zeros, then posts it back for verification. At the default difficulty of 4, solving takes under a second in a browser and stays imperceptible to a person, but becomes ruinous for a bot repeating it thousands of times. It is the only anti-bot protection a vision model cannot shortcut, and the documentation now recommends preferring it over the visual captcha.
  • GET /captcha gains a challenge mode: the image comes with a signed token in the X-Captcha-Token header, and the answer is no longer delivered in clear. It exists only inside the token's signature — impossible to extract, even by intercepting the response. A POST /captcha carrying token and answer then returns { "valid": true }.
  • The rendering of that challenge mode is hardened against automated reading: glyphs overlap so they cannot be segmented, ride a sine baseline, mix font families, and are crossed by strokes drawn in the text's own colors, which no filter can remove. The default mode does not change by a single pixel.
  • Captcha and proof-of-work tokens are single-use and expire after 5 minutes: a replayed token answers used, an expired one expired, a forged one or one from another instance wrong.
  • The CHALLENGE_SECRET variable signs those tokens. Until it is set, each process invents its own key: tokens stop being valid after a restart and are rejected by neighbouring instances — to be defined for any deployment running more than one process.
  • The X-Captcha-Text and X-Captcha-Token headers are now exposed to browser JavaScript; until now they stayed invisible from a web page, for lack of a CORS declaration.
  • Logs now distinguish severity levels: a server error is recorded as error, a client refusal as warn, and the rest as info.

Documentation ​

  • Added the documentation pages for Pow, covering the challenge and a browser solving example, and Pow verification for checking a solved challenge.
  • Rewrote Captcha for the two modes, with a callout recommending Pow for anti-bot protection, and added Captcha verification for the POST route.
  • Both endpoints now expose one page per HTTP method, grouped in the sidebar like Chat and Tic-Tac-Toe.
  • Corrected stale values on the Captcha page inherited from v4: the width default is 60 × the text length rather than 300, height is 120 rather than 150, noise is a level (low, medium, high) rather than a number of lines, and the Noise must be one of… error starts with a capital letter.
  • Added the endpoint to the sidebar, the Playground registry and the homepage feature cards.