OSS Tanbou

self-host a privacy-focused CAPTCHA alternative built around proof-of-work and instrumentation challenges

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
7,924
Primary language
JavaScript
License
Apache-2.0
Repository last updated
Oct 3, 2026
On this page

Overview

Cap replaces image-selection CAPTCHA flows with proof-of-work and browser instrumentation challenges. Its recommended Cap Standalone deployment runs in Docker and provides a web dashboard, multiple site keys, and a reCAPTCHA-compatible siteverify API that can stay on infrastructure you control.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Run challenges without visual image puzzles

Cap combines proof-of-work with instrumentation challenges instead of requiring visitors to select images. The widget can point directly at your own Cap instance.

Sources: [1][2]

Verify tokens through a reCAPTCHA-compatible API

Standalone exposes a siteverify endpoint so application backends can validate widget tokens using a flow that is familiar to teams migrating from reCAPTCHA.

Sources: [2]

Operate a dashboard-backed Docker and Valkey deployment

The documented setup combines the Cap container with Valkey and manages site keys through the dashboard. Standalone 3.1.13 also added health endpoints and graceful shutdown behavior.

Sources: [2][3]

Best fit

Fits web services that want anti-bot checks on controlled infrastructure

It is relevant for signup, login, and form protection when teams want to reduce third-party CAPTCHA data flows and keep the verification service under their own operations.

Sources: [1]

Before adoption

Replace the example administrator key before exposure

The documented Compose file contains an example ADMIN_KEY. The guide recommends a value of at least 32 characters, so production deployments should replace it before the service is reachable.

Sources: [2]

Review real-client-IP forwarding and rate limiting behind a proxy

The instance must be reachable by the widget. Reverse-proxy deployments should follow the documented options so rate limiting sees the correct client IP.

Sources: [2]

Retain Apache-2.0 notices when redistributing

The repository root is Apache-2.0 licensed. Modified or redistributed copies must preserve the license and applicable copyright or NOTICE information.

Sources: [4]

Official sources

  1. [1]tiagozip/cap README(2026-10-03)
  2. [2]Cap Standalone guide(2026-10-03)
  3. [3]Cap Standalone 3.1.13 release(2026-10-03)
  4. [4]Cap Apache-2.0 license(2026-10-03)
Supplemental curator note

Cap is useful when anti-bot checks should stay on infrastructure you control instead of sending visitors through a third-party CAPTCHA service. Before public deployment, validate the admin key, HTTPS, real-client-IP forwarding, and rate limiting.

Try it in 3 steps

  1. 1

    Fetch the stable Standalone setup

    Fetch the official Compose setup for Cap Standalone 3.1.13.

    git clone --branch 'standalone@3.1.13' --depth 1 https://github.com/tiagozip/cap.git && cd cap/standalone
  2. 2

    Replace the example administrator key

    Use a strong ADMIN_KEY of at least 32 characters before exposing the service.

    Edit docker-compose.yml and replace ADMIN_KEY: your_secret_password
  3. 3

    Start the containers and open the dashboard

    Open http://localhost:3000, sign in with the admin key, and create a site key.

    docker compose up -d
Check the official README

Growth

Growth trends · Last 30 days

7,924 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
18
Open PRs
2

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • captcha
  • javascript
  • proof-of-work
  • antispam
  • anti-abuse
  • anti-bot
  • defense
  • anti-scraper
Stars
7,924
Forks
601
Watchers
25
Open issues
6
Contributors
30
Owner type
User
Primary language
JavaScript
License
Apache-2.0
Repository last updated
Oct 3, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?