## TL;DR

Detect CAPTCHAs before you fill the form: fetch the signup page and scan for known challenge markers like reCAPTCHA scripts, Turnstile widgets, or hCaptcha divs. Knowing the challenge type up front lets your flow branch correctly, queue the signup for manual handling, or skip the venue, instead of discovering the CAPTCHA after a failed submit.

```text
detecting signup CAPTCHAs before form submission
```

## Use this when

- Scouting venues for signup automation
- Your signup flow needs to branch on challenge presence
- Building a per-venue capability matrix

## Not for this skill when

- You plan to defeat the CAPTCHA (not covered here)
- The form is behind JavaScript rendering you cannot fetch
- The venue offers an accessible alternative (use that instead)

## Steps

1. Fetch the signup page source. A plain GET usually exposes the markers since challenge scripts load in the HTML. Expected: page source in hand.

2. Scan for the known markers. Each major provider leaves distinctive script URLs, div classes, or site keys in the markup. Expected: you can name the provider or confirm none is present.

```
markers to scan for:
  recaptcha:  google.com/recaptcha, g-recaptcha
  turnstile:  challenges.cloudflare.com, cf-turnstile
  hcaptcha:   js.hcaptcha.com, h-captcha
```

3. Check for invisible or score-based challenges too. Some sites load the script without a visible widget; the script URL in the source is the tell. Expected: no silent challenge slips past.

4. Classify and record per venue: no challenge, visible widget, or invisible script. Expected: your venue matrix has a CAPTCHA column with real data.

5. Branch the flow on the result. No challenge means proceed; a widget means manual queue or skip; log the decision. Expected: no signup attempt ever hits a surprise CAPTCHA.

## Variant phrasings

### how to check if a signup form has a CAPTCHA

Fetch the page and scan for provider script URLs and widget markers before filling anything.

### CAPTCHA detection in signup automation

One page fetch, marker scan, per-venue classification, and flow branching on the result.

### find which CAPTCHA provider a site uses

The script URLs and div classes in the page source name the provider directly.

## Why it happens

Challenge scripts must load before the form can submit, so their markers sit in the page source by design. Sites do not hide which provider they use; the detection is just reading what the page already declares.

## Edge cases / pitfalls

- Challenges can appear only after a failed attempt or on the second signup from an IP; re-scan after failures.
- Some sites A/B test challenge presence; classify per session, not once forever.
- Rendered-JS forms may need a headless fetch to expose markers a plain GET misses.
- Detection is not solving; keep those as separate decisions with separate ethics.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_3xhSeowJFkRUvGDZo8LBzg
