Safer MFA

End SMS Tolling Attacks Forever

Get Started

Stop tolling attacks and stay ahead of persistent threats

hCaptcha MFA is more secure than traditional SMS OTP. Pull-based SMS prevents tolling attacks, and Account Defense detects ATOs and SIM swaps.
Get Started

How it Works

Streamlined User Experience

No more copy & paste: codes are pre-filled in the native SMS app.

Stronger Verification

Authentication at the carrier and device level level blocks tolling and SIM swaps.

Faster, More Intelligent MFA

Complete MFA in seconds, powered by real-time risk signals.

Multi-Layer Account Defense

Traditional SMS OTP is convenient, but risky. It's vulnerable to SIM swaps, number hijacking, and toll fraud that drive up costs and put users at risk.

hCaptcha MFA flips the OTP model with a pull-based approach. Users send a pre-filled SMS to us: no outbound messages, no tolling risk.

The result? Higher completion rates, fewer errors, and stronger protection, especially when paired with Account Defense.

Prevent Social Engineering

With Pull-based MFA, fraudsters can no longer call users to impersonate your service and have them read back a code they sent to the user.

The user must initiate MFA actions on their device, making common social engineering attacks harder.

Seamless MFA
Where it Matters Most

hCaptcha MFA works alongside your existing defenses, adding a layer of protection without increasing complexity.

Set up SMS-based authentication in minutes, backed by privacy-first security.



With the Rules Engine, you control when MFA is triggered: apply it across all traffic, or only under specific conditions.

Prefer your own UI?
Use our Backend API

Our MFA solution is flexible; use our full-featured UI via SDKs, or use your own UX  and call our backend APIs instead.

Get all the benefits of hCaptcha MFA, including SMS-based OTP and privacy-first security, without changing your frontend.

With our Rules Engine, you're in full control: trigger MFA for all users or only when risk signals are detected. Fast, secure, and completely under your control.