No puzzle. One touch binds the session to a real human. Every action after rides silently on that proof — until something looks wrong, and the secure enclave asks again. A bot can sit in the page all it wants; it dies at the re-prompt.
Runs in your browser. The first tap triggers a real WebAuthn user-verification prompt where supported.
A bot can render the page, click the buttons, even pass a one-time check. What it can't do is survive the moment the session asks the human to prove they're still there.
The session opens with a single secure-enclave verification (Face / fingerprint / PIN). That binds every future receipt to a key only this person, on this device, can release.
Low-risk actions don't re-prompt. They self-sign and chain onto the previous receipt — tamper-evident, zero friction. This is why it's simpler than a captcha: you mostly do nothing.
A new device, a location jump, or a behavioral break forces a fresh enclave verification before the next action signs. A bot has no enclave and no human — the chain stops dead.