$npx skillfedfor your agent

altcha

A library for creating and verifying challenges for ALTCHA.

Worth itPyPI CryptographyReleased Jul 2026296.5K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — altcha-2.1.0-py3-none-any.whl
v2.1.0 · released 2026-07-27 · Python >=3.9

Yes. The library is actively maintained, has zero runtime dependencies, installs easily, carries no known vulnerabilities, and solves a real problem (bot protection via proof-of-work). It is permissively licensed and supports current Python versions. Install it if you need ALTCHA challenge generation and verification; the API is straightforward and the documentation includes working examples.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later.
  • Argon2id support requires optional argon2-cffi dependency.
  • Installs with no runtime dependencies and is actively maintained; last release was 18 days ago with a recent commit on 2026-07-27.

License · maintenance · safety

permissive license (permissive) — Licensed under MIT (permissive), so you can use, modify, and distribute it freely in commercial and open-source projects.

last release 2026-07-27 (18 days) · last repo commit 2026-07-27 · 31 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 296,462 downloads/mo, #7,897 on PyPI

Verify before relying

pip install altcha

from altcha import create_challenge, solve_challenge, verify_solution, Payload

challenge = create_challenge(algorithm="PBKDF2/SHA-256", cost=5_000, hmac_secret="secret")
solution = solve_challenge(challenge)
payload_b64 = Payload(challenge, solution).to_base64()
result = verify_solution(payload_b64, "secret")
print(result.verified)
  • Whether the library is suitable for production web applications at scale beyond the stated monthly download volume.
  • Performance characteristics and typical solve times for different algorithm/cost combinations in real deployments.
Same gist for agents: .md · .json

What it is and what it does

ALTCHA is a zero-dependency Python library for creating and verifying proof-of-work challenges designed to protect against automated attacks. It implements PoW v2, which uses key derivation functions (KDFs) instead of simple hash matching—clients must find a counter value whose derived key starts with a required prefix. The library supports multiple algorithms: fast iterated SHA variants for testing, PBKDF2 for general use, and memory-hard algorithms like scrypt and Argon2id that resist GPU/ASIC attacks.

The typical workflow is server-side: create a challenge with a chosen algorithm and cost, send it to the client, which solves it by brute-forcing counter values, then transmit the solution back to the server for verification. The library handles challenge expiry, optional HMAC signing for tamper detection, and a fast verification path when you pre-solve challenges server-side. It also supports custom KDF functions and server signature verification via the ALTCHA Sentinel API.

Use it for

  • Protect web forms and APIs from bot submissions by requiring clients to solve a proof-of-work challenge before accepting requests.
  • Implement rate limiting or anti-spam mechanisms that are resistant to GPU-accelerated attacks using memory-hard algorithms.
  • Verify that a client performed computational work before granting access to expensive resources or rate-limited endpoints.
  • Embed tamper-proof challenges in web applications by signing them with HMAC and verifying the signature server-side.
  • Test proof-of-work implementations quickly using fast SHA-based algorithms without deploying memory-hard variants.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

The library is actively maintained, has zero runtime dependencies, installs easily, carries no known vulnerabilities, and solves a real problem (bot protection via proof-of-work). It is permissively licensed and supports current Python versions. Install it if you need ALTCHA challenge generation and verification; the API is straightforward and the documentation includes working examples.

Install

altcha on PyPI

Before you install

Installs with no runtime dependencies and is actively maintained; last release was 18 days ago with a recent commit on 2026-07-27.

Requires Python 3.9 or later. Argon2id support requires optional argon2-cffi dependency.

License in practice

Licensed under MIT (permissive), so you can use, modify, and distribute it freely in commercial and open-source projects.

Quickstart

pip install altcha

from altcha import create_challenge, solve_challenge, verify_solution, Payload

challenge = create_challenge(algorithm="PBKDF2/SHA-256", cost=5_000, hmac_secret="secret")
solution = solve_challenge(challenge)
payload_b64 = Payload(challenge, solution).to_base64()
result = verify_solution(payload_b64, "secret")
print(result.verified)

Verify before relying

  • Whether the library is suitable for production web applications at scale beyond the stated monthly download volume.
  • Performance characteristics and typical solve times for different algorithm/cost combinations in real deployments.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 18 days since the last release
Last repo commit
First released
Downloads296,462 / month, #7,897 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3

Evidence: altcha-2.1.0-py3-none-any.whl

Tags

Capabilities
proof of work challenge verificationALTCHA challenge librarybot protection proof of workkey derivation function proof of workPBKDF2 Argon2id challenge solveranti-bot challenge systemmemory-hard proof of work
Topics
proof-of-workbot-protectioncryptography

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “proof of work challenge verification”

  • altchaCreates and verifies ALTCHA proof-of-work challenges using key…
  • chiaposPython bindings for Chia's proof-of-space implementation, providing…
  • pkceGenerates PKCE (Proof Key for Code Exchange) code verifiers and…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also argon2-cffi · pkce · eth-keyfile · bcrypt · hkdf · scrypt · pyscrypt · standardwebhooks · eth-keys