Captchas

Captchas are an optional anti-abuse step in ioki Platform. They are used to protect workflows that can be targeted by automated or repeated requests.

If a captcha is present, the user must solve it before the protected workflow can continue.

When captchas can appear

Captchas can appear in flows that create or continue a verification process. Today, this mainly affects Passenger API verification-related workflows, Platform API verification-related workflows, some administrator verification workflows, and web-based user deletion requests.

In verified high-level terms, ioki Platform can introduce a captcha when it detects elevated abuse risk, when SMS quota pressure is a concern, or when additional protection is required for the deletion flow.

How captchas affect a workflow

The exact client implementation can differ, but the high-level flow is the same:

  1. A user starts a workflow such as phone verification or account deletion.
  2. ioki Platform determines whether a captcha is needed.
  3. If a captcha is required, the user must solve it before continuing.
  4. After a successful solve, the original workflow can continue.

The captcha is a separate challenge step. It does not replace the underlying verification or deletion flow.

Captcha outcomes

  • If the captcha is solved successfully, the protected workflow continues.
  • If the captcha is solved incorrectly, the workflow does not continue until the captcha is solved correctly.
  • If the captcha is no longer valid, the user must start again with a new captcha step.