A checkbox in front of your forms.
Nothing in front of your customers.
Put an "I'm not a robot" checkbox on your own forms and pages, and an origin-side check in front of anything you host with Xuda. It only escalates to an image challenge, and then to an AI check, when the visitor's signals look automated.
Escalation levels · most visitors never leave the first
Captcha vendors in the path · built in-house
Tier covering your own forms and Xuda-hosted targets
Leading zero bits of proof of work, by default
Bots should work harder. Customers should not.
Most checks treat every visitor the same: squint at a picture, prove yourself, try again. Xuda Bot Protection starts with a checkbox and a set of signals the visitor's browser gives away for free. If those look human, that is the end of it. Only when they look automated does anyone see an image challenge, and only after that does an AI get involved.
It is built in-house. There is no captcha vendor behind it, no account to open somewhere else, and nothing about your visitors is handed to a third-party service to score.
Four moves from nothing to protected.
Bot Protection sits in the MODULES group of your account menu. Nothing is switched on until you choose a tier, and Free is a real one.
- 01
Choose a tier
Open Bot Protection and pick from the four-card ladder. Free is an activation, not an assumption: press Activate and you owe nothing. Paid tiers state the money in plain words before you confirm, and add one line to the invoice you already get.
- 02
Flip the widget on and save
On the Setup tab, turn Bot protection on and press Save changes. That first save mints your public site key and your private secret key. Set Aggressiveness to Low, Medium or High while you are there.
- 03
Paste the snippet, verify on your server
Copy the script tag, or the inline mount div if you want to place the checkbox yourself. Then post the secret and the response token from the form to the verification endpoint and read success, score and level_reached back.
- 04
Arm anything you host with Xuda
On the Protection tab, press Add protection, pick a VPS, deployment, datacenter or load balancer, and flip Armed. The origin starts enforcing within one 30 second refresh, and disarming is the same switch.
One check, two places to put it.
A widget for the forms and pages you host yourself, and an origin-side gate for anything running on Xuda. Same ladder, same keys, same dashboard.
A checkbox, not an obstacle course
Level 0 is a click plus a set of signals the browser gives away anyway. Clear it and there is no puzzle, no grid of buses, no second attempt. That is the whole experience for most people.
Signals scored before anything is shown
Pointer, key and scroll counts, touch, WebGL and canvas presence, hardware concurrency, languages, timezone, automation flags and dwell time become a single human likelihood, with named reasons like no_interaction, webdriver, headless and instant_click.
The browser pays before it is believed
Every visitor solves a SHA-256 proof-of-work puzzle, 16 leading zero bits by default, one bit harder on Medium aggressiveness and two on High. Cheap once, expensive at bot volume.
Image challenges with no photo library
Level 1 is a 9-tile grid drawn in process as SVG: five shapes, eight colors, at least two correct tiles, prompted as "Select every image that shows a ...". Nothing is fetched from a third party and nothing is scraped from your users.
AI as the last word, not the first
Level 2 asks for a risk verdict of human, bot or borderline. A borderline visitor gets one generated common-sense question with a hashed expected answer. If the scorer is unreachable the visitor is treated as borderline rather than failed.
Single-use, short-lived pass tokens
A pass is a signed token that lives two minutes and is burned the first time your server verifies it. Replay the same token and the answer is timeout-or-duplicate. There are no server-side sessions to sync.
Drop-in for code you already wrote
The verification call takes a secret and a response and answers with success, score, level_reached, hostname, challenge_ts and error-codes. Existing backend code usually only needs its URL changed.
Origin-side enforcement, no extra edge
Armed targets are enforced by the Xuda router itself. A cleared visitor carries an httpOnly, secure, SameSite=Lax cookie for the clearance window, so the interstitial is a one-time event, not a toll booth.
Flood control and a silent honeypot
60 verification attempts a minute per visitor IP and site key, 600 a minute per site key. A decoy field that gets filled fails the visitor with a deliberately uninformative reason, so the bot learns nothing from the rejection.
Flip it on. Copy two lines. Done.
Turning the widget on for the first time mints your site key and your secret key. The site key is public and goes in the snippet. The secret key stays on your server and is what verifies a pass. Both live in one card on the Setup tab, with copy buttons and a Rotate secret button next to them.
- Paste the script once on any page and the checkbox mounts itself, or drop the inline mount div exactly where you want it.
- Rotate the secret whenever you like. The dialog warns you that the old one stops working everywhere it is used.
- Aggressiveness is one select: Low escalates rarely, High escalates readily. Medium is the default.
7hQ2pXv0nMbK4sRj9TfLdA•••••••••••••••••••••• 4c9E Reveal Rotate secretBalanced. Most visitors clear the checkbox without ever seeing a challenge.
<script src="https://xuda.io/dist/runtime/js/captcha-loader.js"
data-sitekey="7hQ2pXv0nMbK4sRj9TfLdA"></script><div class="xuda-captcha" data-sitekey="7hQ2pXv0nMbK4sRj9TfLdA"></div>Nobody sees a puzzle until they have earned one.
Level 0 is the checkbox, the passive signals and a proof-of-work puzzle the browser has to solve. Level 1 is a 9-tile image challenge. Level 2 is an AI risk verdict and, if that verdict is borderline, one generated question. Each level only exists because the one before it failed.
Checkbox, signals and proof of work
where almost everyone stopsThe visitor clicks once. Server side, the passive signals become a score and the browser has to have solved the proof-of-work puzzle. A pass that arrives faster than the minimum age is not accepted.
- Pass threshold moves with aggressiveness: 0.6 on Low, 0.7 on Medium, 0.8 on High.
- Proof of work is clamped to 8..24 leading zero bits when you set it by hand.
- The session token behind the widget lives 15 minutes.
A 9-tile image challenge
only after level 0 failsOne target shape, nine tiles, at least two of them correct. The grid is generated on the spot from five shapes and eight colors, and it is graded against a hash of the correct tiles rather than a stored answer.
- Refresh gives a new grid; Verify submits the selection.
- Each issued challenge is good for two minutes.
- No photographs, no street signs, no vendor library.
An AI risk check, then one question
the last step before a blockThe collected evidence goes to a structured risk verdict: a score, a verdict of human, bot or borderline, and a reason. A clear human passes, a clear bot is blocked, and a borderline visitor gets exactly one generated question to answer.
- The verdict has to score at least 0.7 to pass at this level.
- The generated question is good for three minutes and is asked once.
- If the scorer cannot be reached the visitor is treated as borderline, not failed.
Your backend already knows how to talk to this.
The verification endpoint takes a secret and a response token and answers in the same shape reCAPTCHA and Turnstile answer in. If you have written that code once, you have written it for this. Usually only the URL changes.
- Same request shape as the siteverify calls you have already written: a secret, a response token, an optional visitor IP.
- A pass returns the score and the level the visitor reached, so you can log how hard the check had to work.
- Failures come back as readable codes: missing-input, invalid-input-secret, invalid-input-response, timeout-or-duplicate.
- Call it from your server only. The secret key is the credential, so it never belongs in page markup.
$ curl -X POST https://xuda.io/cpi/captcha_siteverify \
-H 'content-type: application/json' \
-d '{"secret":"YOUR_SECRET_KEY","response":"<token from the form>"}'
{
"success": true,
"score": 0.86,
"level_reached": 0,
"hostname": "studio.co",
"challenge_ts": "2026-08-11T09:14:02Z",
"error-codes": []
}Put the check in front of the whole site.
Pick a VPS, a deployment, a datacenter or a load balancer you host with Xuda, then flip Armed. Every uncleared visitor gets a full-page "Checking your browser" screen before the site loads. Flip it off and they stop. Only Xuda-hosted targets can be protected today.
| Target | Traffic | Armed |
|---|---|---|
shop.mysite.com Deployment · eu1 | 18,402 served 1,196 challenged, 284 blocked | |
api-prod-01 VPS · us1 | 6,051 served 410 challenged, 97 blocked | |
edge-balancer Load balancer · eu1 | 2,338 served 84 challenged, 12 blocked |
Enforced at your origin
The Xuda router keeps the armed list in memory and refreshes it every 30 seconds, so arming and disarming take effect within one refresh and there is no extra hop on the hot path.
One pass, then silence
A visitor who clears the check gets an httpOnly, secure, SameSite=Lax clearance cookie and browses normally for the rest of the window, 30 minutes by default.
Or one toggle on the app
A deployment's Quick Actions card carries "Bot Protection (Under Attack)". Flip it there and the same check goes up, with a challenges-served line underneath.
Rules in countries, paths and hours.
Sometimes the answer is not harder for everyone, it is harder for one country, one path or one window of the day. Custom rules run at the edge in a fixed order, so you always know which rule won. They come with the Custom Rules plan.
- Allow, challenge or block by country, chosen from the full ISO 3166-1 alpha-2 list.
- Per-path rules such as /login or /checkout, each set to challenge, block or allow.
- Hour-of-day and day-of-week windows, for the times you know traffic should be quiet.
- Always allow and always block lists that take IP addresses, CIDR ranges or country codes.
- A referer requirement, plus a clearance window you can set anywhere from one minute to 24 hours.
Four tiers, and one line on the invoice.
The plan sits on the account, not on each protected thing, so nothing here is charged per protected target. Free is an activation rather than a trial, and moving between paid tiers reprices a single line instead of stacking a second charge.
Free
Start hereThe checkbox on your own forms, and the full-page check on anything you host with Xuda.
- The "I'm not a robot" checkbox on any page you host yourself, as a script tag or an inline mount div.
- The full-page check in front of a Xuda VPS, deployment, datacenter or load balancer.
- Server-side verification through the siteverify endpoint, with no API key involved.
- Aggressiveness, proof-of-work difficulty and the 30 minute clearance window are all yours to set.
- Targets you host elsewhere
- Programmatic API access
- Custom rules
- Charged per protected target
- Never
External
The entitlement to protect a target you host somewhere other than Xuda.
- The external-target capability on the account, enforced in code and ready for the day the attach path opens.
- Targets you host elsewhere
- Entitled, not attachable yet
- Programmatic API access
- Custom rules
- Charged per protected target
- Never
API
Meant for driving the check from your own code. The programmatic surface is not open yet.
- The API capability on the account. Verifying a pass from your own backend does not wait for it: the siteverify endpoint is public and sits on Free.
- Targets you host elsewhere
- Entitled, not attachable yet
- Programmatic API access
- Not open yet
- Custom rules
- Charged per protected target
- Never
Custom Rules
Most completeFor when a blanket is too blunt and you want the check aimed at one country, one path or one window.
- Allow, challenge or block by country, from the full ISO 3166-1 alpha-2 list.
- Per-path rules such as /login or /checkout, each set to challenge, block or allow.
- Hour-of-day and day-of-week windows, plus a referer requirement.
- Always allow and always block lists taking IP addresses, CIDR ranges or country codes.
- Per-target aggressiveness, evaluated at the edge in a fixed order so you know which rule won.
- Path rules
- 100 max
- Entries per allow or block list
- 200 max
- Clearance window
- 1 min to 24 hours
- Charged per protected target
- Never
Said plainly: bot protection is live and verified on dev and has not been published to the production regions yet. The External tier is billable but there is no way to attach a target outside Xuda today. The API tier's methods are not open to API keys, so the only key-free surface right now is the server-side verification endpoint, and that is already on Free. On Custom Rules, the country, path, hour, day, referer and allow and block list rules are enforced at the edge; the rate, fingerprint and bad-ASN controls are saved but not yet acted on.
No vendor to sign up with. No visitors to hand over.
The realistic choices are a hosted captcha widget from a third party, a network-level block in front of your site, or a honeypot field you wrote yourself. Here is what each one actually gives you.
Xuda Bot Protection You | A third-party captcha widget | A network-level block | Your own honeypot field | |
|---|---|---|---|---|
| Checkbox you can paste on your own forms | ||||
| Full-page check in front of a whole hosted site | ||||
| Escalates only when the signals look automated | Varies | |||
| Proof of work before the browser is believed | 16 bits by default | Varies | ||
| Image challenge generated in process, no photo set | Varies | |||
| AI risk verdict as the final step | Varies | |||
| Visitor signals scored by a third party | Varies | Varies | ||
| Server-side verify in the siteverify shape | ||||
| Single-use pass token, replay rejected | 2 minutes | Varies | ||
| Per-visitor and per-site rate limiting included | Varies | |||
| Country, path, hour and day rules | Custom Rules plan | Varies | ||
| Charged per protected target | Varies | Varies |
The things worth asking first.
Stop the bots. Leave everyone else alone.
Turn on the checkbox for your own forms and pages, or arm the full-page check in front of anything you host with Xuda. Free tier, no card, no per-target fee, and no captcha vendor in the middle.