altcha-django
Django integration for ALTCHA — built around Widget v3, Proof-of-Work v2, and ALTCHA Sentinel.
- A real Django form field (
Form,ModelForm, formsets,Widget.Media, translated errors). - Pluggable verification backend: local proof-of-work or Sentinel (local server-signature verification or the remote API).
- Atomic replay protection via Django's cache framework.
- Signals for every verification outcome; optional built-in stats.
- Test mode and
django checksystem checks. - Optional Django REST Framework field.
Requires Python 3.10+ and Django 4.2+.
Install
pip install altcha-django
# extras: [sentinel] (httpx), [argon2] (argon2-cffi), [drf] (djangorestframework)
Quick start — local verification
# settings.py
INSTALLED_APPS = [..., "altcha_django"]
ALTCHA_HMAC_SECRET = "a-long-random-string" # keep secret
# urls.py
urlpatterns = [..., path("altcha/", include("altcha_django.urls"))]
# forms.py
from django import forms
from altcha_django import AltchaField, AltchaMixin
class ContactForm(AltchaMixin, forms.Form):
email = forms.EmailField()
captcha = AltchaField()
# views.py
form = ContactForm(request.POST or None, request=request)
{{ form.media }}
<form method="post">{% csrf_token %}{{ form.as_p }}<button>Send</button></form>
Quick start — Sentinel
ALTCHA_VERIFIER = "sentinel"
# Full challenge URL of your self-hosted Sentinel, API key in the query string:
ALTCHA_SENTINEL_CHALLENGE_URL = "https://sentinel.example.com/v1/challenge?apiKey=key_..."
ALTCHA_SENTINEL_API_SECRET = "sec_..." # private — never leaves the server
Nothing else changes: the widget fetches its challenge from your Sentinel and the
field verifies the signed result locally. Read score / classification with
AltchaField(return_result=True).
See docs/ for the full settings reference, signals, system checks,
Sentinel guide, testing notes, and migration from django-altcha.
License
MIT
Metadata
Release files for altcha-django 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| altcha_django-1.0.0.tar.gz | 123.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| altcha_django-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 224.5 kB
Release files / altcha_django-1.0.0.tar.gz
| Download URL | altcha_django-1.0.0.tar.gz |
|---|---|
| Size | 123.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
593391a8ea149efd16b1a2b81549031f5f0d81b008fd70d8d502734a722f6303
|
|
BLAKE2b-256 checksum How to use checksums |
c57365e0d5f6fd7c601fcce550b97c25f43e857b3106060c26472bd0ad2f3cb7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 29, 2026.
Transparency logRelease files / altcha_django-1.0.0-py3-none-any.whl
| Download URL | altcha_django-1.0.0-py3-none-any.whl |
|---|---|
| Size | 100.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
39a92d53c5856bcd77c8bd994c437c0563b35fefc21aed7cde0560b258c04e29
|
|
BLAKE2b-256 checksum How to use checksums |
80a918a657e9ba0efc47e2f7f774d1bc9848f2fdb55228693b27f4c0ef693844
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 29, 2026.
Transparency log