hCaptcha Agent Controls

Detect and Manage Agents

Identify agents, understand their behavior, and control what they can do on your site.

Get Started

Agent Visibility

Control How Agents Act

hCaptcha Enterprise identifies agents even when they try to hide from detection. hCaptcha also supports Web Bot Auth cryptographic verification for partner platforms that sign their requests.

Review agent traffic and the actions they take. A known platform can carry both legitimate users and attackers. hCaptcha helps you tell them apart and enforce your policy controls.

How hCaptcha supports Web Bot Auth
Agent analytics with WBA, behavior, and device or network detection signals, plus a table of request outcomes.

Rules and Responses

Set Rules for the Actions That Matter

Let an assistant browse your catalog, require verification before it reserves inventory, and deny requests that violate your policy.

Target the relevant sitekeys and combine agent detections with other risk signals. Start with logging to review matching traffic, then apply the response each flow needs.

Explore the Rules Engine
Agent access policies and a rule editor requiring verification for inventory reservations.

User Journeys

Follow Agent Behavior Across the Session

See what happened before a sensitive action. User Journeys brings session activity together so you can investigate repeated reservations, unusual navigation, or suspicious account behavior.

With User Journeys enabled, captured WebMCP tool calls and cancellations appear by name. Tool arguments and results are not recorded.

See hCaptcha's WebMCP support
A browser agent's session timeline showing catalog searches, an inventory reservation, and hCaptcha verification.

Your Site. Your Policy.

Control Agent Access by Flow

Allow Useful Automation

Permit catalog searches and other low-risk activity from agents that meet your policy.

Verify Protected Actions

Require a valid hCaptcha token before your backend accepts a reservation or another sensitive action.

Deny Abusive Requests

Restrict agents on flows where automation is prohibited, even when the request has a valid signature.

Frequently Asked Questions

Does Web Bot Auth give an agent permission to access my site?

No. WBA authenticates request provenance. A signed request remains subject to hCaptcha's risk assessment and your access policy. You decide which agents can access each flow.

Can hCaptcha detect agents that do not identify themselves?

Yes. hCaptcha evaluates many signals independently of WBA. Detection does not depend on an agent volunteering its identity.

Does WebMCP bypass hCaptcha verification?

No. The optional hcaptcha_verify tool uses your existing challenge settings. If an interactive challenge appears, the agent must pause for the initiating person to complete it. Your backend still validates the token before accepting a protected action.

Can I apply different policies to different actions?

Yes. Apply rules to the relevant sitekeys and combine agent signals with other supported risk conditions. Your application enforces verification and its business checks on each protected endpoint.