We're building Humanmark, a human verification service that uses the secure hardware in smartphones instead of puzzles or behavioral tracking.
Existing verification methods have failed:
CAPTCHAs are now solved more accurately by AI than humans
Behavioral analysis creates false positives that block legitimate users
SMS verification is expensive and inherently sensitive
These tools no longer verify humanity, they just measure automation quality.
We use the secure hardware already present in smartphones to create cryptographic proof of human presence. When users verify with their fingerprint, face, or passcode, the hardware generates an unforgeable signature that we validate.
For developers, it's a simple SDK integration. For users, it's a 2-second tap instead of solving puzzles.
Backend API: Complete and stable
iOS and Android apps: Live in app stores
JavaScript SDK: Published on NPM
Documentation: Available at humanmark.dev
We're in beta and looking for businesses with real automation problems to work with.
Free: Up to 2,000 verifications/month
Paid: Starting at $49/month for higher volumes
Target market: E-commerce, ticketing, content; any online property dealing with automation
Stateless design - no user tracking
Hardware attestation that can't be virtualized
Binary output: human or not human
Framework-agnostic SDK
For those who've built developer tools: what channels worked best for reaching technical decision makers?
How do you price infrastructure that prevents losses rather than driving revenue?
What's your experience with bottom-up (developer-led) vs top-down (business-led) adoption?
Demo: humanmark.dev/demo
Documentation: humanmark.dev
GitHub: github.com/humanmark
If you're dealing with automation problems, we're offering free integration support during beta to learn from real-world use cases.
How are you currently handling bot prevention? Is it working?
This is a really cool approach, love that you’re leveraging hardware instead of throwing yet another CAPTCHA puzzle at users.
In our analytics tool (Betterlytics), we currently handle bot prevention in a simpler way, mainly filtering requests by known bot user agents or invalid user agents. It’s straightforward and works well for most use cases, but it doesn’t catch the more advanced automation.
Excited to see how Humanmark evolves and impacts the bot prevention space!