Captchas
Captchas are an optional anti-abuse step in ioki Platform. They are used to protect workflows that can be targeted by automated or repeated requests.
If a captcha is present, the user must solve it before the protected workflow can continue.
When captchas can appear
Captchas can appear in flows that create or continue a verification process. Today, this mainly affects Passenger API verification-related workflows, Platform API verification-related workflows, some administrator verification workflows, and web-based user deletion requests.
In verified high-level terms, ioki Platform can introduce a captcha when it detects elevated abuse risk, when SMS quota pressure is a concern, or when additional protection is required for the deletion flow.
How captchas affect a workflow
The exact client implementation can differ, but the high-level flow is the same:
- A user starts a workflow such as phone verification or account deletion.
- ioki Platform determines whether a captcha is needed.
- If a captcha is required, the user must solve it before continuing.
- After a successful solve, the original workflow can continue.
The captcha is a separate challenge step. It does not replace the underlying verification or deletion flow.
Captcha outcomes
- If the captcha is solved successfully, the protected workflow continues.
- If the captcha is solved incorrectly, the workflow does not continue until the captcha is solved correctly.
- If the captcha is no longer valid, the user must start again with a new captcha step.