[ how_it_works ]
Six signals. One deterministic verdict.
HumanProof reads the shape of interaction and the integrity of the client — passively, without content — and combines the evidence into a reason-coded, confidence-qualified proof.
[ the_signals ]
Pointer rhythm
The cadence and timing of movement — never the coordinates. Human pointers hesitate, curve and drift at tempos scripts struggle to fake.
Typing cadence
Inter-key rhythm and natural hesitation — the tempo of a human hand, never the keys pressed.
Scroll rhythm
The cadence and presence of scrolling — the timing, not pixel deltas or reading position.
Browser integrity
Does the client behave like the browser it claims to be — real event loops, real rendering, no headless tells.
Request coherence
Declared-vs-actual checks: browser declarations against the request headers the browser itself emits.
Network evidence
Origin, transport and timing consistency across the session — evidence, never identity.
[ standing ]
Prove once.
It holds.
The verdict isn’t a gate you pass once — it’s a standing that persists across the session and decays honestly when the evidence goes quiet. Your backend reads it any time, right before the action that costs you money.
[ deterministic ]
Deterministic, not a guess.
No LLM, no black box. The same evidence always produces the same verdict, with reason codes you can read, log and audit. When we say coherence_mismatch, you can see exactly why.
[ the_honest_ceiling ]
Likely — never guaranteed.
A fully coherent cold bot can still pass. The proof is confidence-qualified because that’s the truth of the problem — and pretending otherwise is how the CAPTCHA industry got here. We say so plainly, on every surface.
Counts, never contents.
No prompts, no keystrokes, no coordinates, no page data. We measure behavior — then drop the raw. Read the boundary →