osec Captcha cover: reCAPTCHA's free tier is now 10,000 a month

What changed

• reCAPTCHA free tier: 10,000 assessments a month.
• Past 10,000: a flat $8 up to 100,000, then $1 per 1,000 (Enterprise tier).
• No billing account? You stay on the Essentials tier and get emails as you approach the limit.
• 10,000 is small: a busy contact form, a signup page and a login page can pass it in a week of bot traffic.

Your options

• Pay Google: fine for big sites, a new bill for small ones.
• Cloudflare Turnstile: free and good; needs a Cloudflare account, works on any site.
• hCaptcha: free tier of 100,000 a month, with image puzzles.
• osec Captcha: invisible proof-of-work, no puzzles, no tracking cookies, 500 checks a day free on every account, credits when you grow.

How osec Captcha works

1. The widget asks osec.one for a signed puzzle.
2. The visitor's browser solves it in the background (about a quarter second on a phone).
3. A check mark appears. The answer goes into your form as osec-captcha-response.
4. Your server sends it to /captcha/siteverify with your secret.
5. You get {"success": true} or an error code, the same shape as reCAPTCHA.

A contact form with the osec Captcha widget showing You're verified
The real widget on a demo contact form: no puzzle, just a check mark.

Why bots hate it

• Every attempt costs CPU. One form post is cheap; 100,000 are not.
• Difficulty rises per IP: an address that asks for many puzzles gets harder ones, up to 20x.
• One use only: each solution works once and expires in 10 minutes.
• Locked to your key and hostnames: a solution for one site is useless on another.

Swap it in

1. Sign in at osec.one → Console → Site keys → New key. List your hostnames.
2. Copy the secret. It's shown once.
3. In your form: <div class="osec-captcha" data-sitekey="osk_…"></div>
4. Load https://osec.one/assets/osec-captcha/osec-captcha.js.
5. On your server: POST secret + response to https://api.osec.one/tools/captcha/siteverify.
6. Accept the form only when success is true.

osec.one console, Site keys page with the Captcha snippets for HTML, curl, Node.js and PHP
Console → Site keys → Snippets: copy-paste code with your sitekey filled in.

Good to know

• Free: 500 metered requests a day per account (one siteverify = one request).
• More: $10 buys 20 credits, each adds 500 a day for 30 days. Emails at 80% and 100%.
• Over quota: siteverify answers quota-exceeded; you choose to block or let the form through.
• Accessible: nothing to see, drag or click for people using screen readers.
• Honest limit: proof-of-work raises the cost of abuse; it doesn't stop a determined attacker with real browsers. Pair it with rate limits.

Invisible, private captcha with reCAPTCHA-style siteverify. 500 checks a day free.

Try osec Captcha

Sources

• Google Cloud, reCAPTCHA billing information: https://docs.cloud.google.com/recaptcha/docs/billing-information
• reCAPTCHA pricing in 2026 (phpcaptcha.org): https://www.phpcaptcha.org/recaptcha-pricing
• Cloudflare Turnstile plans: https://developers.cloudflare.com/turnstile/plans/
• hCaptcha review and pricing (phpcaptcha.org): https://phpcaptcha.org/hcaptcha-review/