Режим контроля
BOT_DETECTION_MODE live
Description Checks enforced — denials short-circuit the request.
Активная защита от злоупотреблений — капча, ловушка, ограничения запросов, бюджет ИИ.
Proof-of-work captcha (ALTCHA) on auth flows. Single-use payload via Upstash replay store.
Hidden field "bookmark" + 2000ms minimum fill time. Currently on the feedback form.
Per-IP and per-email Upstash limiters across auth, feedback, AI, and the captcha endpoint. Per-email: 5/1 h.
Daily token cap of 100,000 per user. Caps cost-amplification abuse.