FCaptcha v1.34: Seven Releases About Not Blocking Humans
Most of FCaptcha v1.28–v1.34 protects the visitor who did nothing wrong: expired tabs, sparse mouse traces, invisible mode. Plus one breaking change.
bot-detectionTurn bot detections into an investigation: see likely targets, repeat visits, and crawl breadth, with the requests behind every observed pattern.
A bot alert gets your attention. Understanding what that traffic is doing tells you where to look next.
Is it returning to the same article? Working through dozens of different pages? Requesting numbered resources in sequence? A detection count can’t answer those questions on its own, and reading individual requests takes work.
AI Journey Insights turns an actor’s observed requests into a short, inspectable explanation. Open a journey in WebDecoy to see likely collection targets, supported access patterns, and the requests behind the observed behavior.
You get a starting point for the investigation, with the evidence already connected.
Two samples from traffic to webdecoy.com show why this matters.
In one journey, 38 of 48 sampled requests returned to the same article. Forty of the requests used article or documentation routes. The useful takeaway was the concentration on a particular piece of content, with repeated requests at different times.
Another journey reached 45 distinct targets across 48 sampled requests. Most targets were requested once. The busiest target was /robots.txt, with four requests. Thirty-six requests used article or documentation routes.
Both samples included substantial interest in content. Their request patterns were very different:
| Observed sample | What stands out | Where to start investigating |
|---|---|---|
| 38 of 48 requests to one article | Repeated attention to a specific target | Inspect the repeat requests and their timing |
| 45 distinct targets in 48 requests | Broad coverage with little repetition | Review the path distribution and pages reached |
These are two observed samples, not a benchmark for all bot traffic. But they illustrate the question customers need answered: what is distinctive about this actor’s activity?
Journey Insights brings that distinction to the top of the page. For the second sample, the headline reads:
This sample reaches 45 distinct targets, mostly requesting each once.
That is a more useful place to begin than a long list of URLs.
The AI classifies two aspects of an eligible journey: the information the traffic appears to seek and the access strategy supported by its request sequence.
Likely targets can include articles and documentation, prices, inventory, reviews, or contact information. Access patterns can include repeated checks, pagination, numbered resources, or archive dates. When the evidence is unclear, the result can remain undetermined.
Alongside those classifications, WebDecoy computes observations from the saved sample. A finding can show how many requests used article routes, which requests returned to a target, or which ordered paths support a sequence.
Expand Inspect matching requests to see that evidence. Select a request to open its detection details. You can follow the explanation all the way back to the event you are investigating.
Those observations help you assess the AI’s interpretation. They are measured facts from the sample, rather than a generated explanation presented as proof.
Sometimes the paths suggest interest in your content without establishing how the actor navigated it. Journey Insights still gives you three ways to understand the activity.
Breadth shows how much ground it covered. See the number of distinct original targets and expand the path distribution to find the routes represented in the sample.
Concentration shows where its attention went. See the busiest target’s share and inspect its matching requests. A sample spread across many targets warrants a different investigation from one dominated by a single article or endpoint.
Timing shows how the observed requests arrived. Inspect the busiest 60-second window and the longest gap between sampled requests. Expand the timing details to review activity groups and their individual detections.
These measurements remain available when the AI does not identify a clear access strategy. You can still work from concrete evidence.
The feature lives where you already investigate an actor:
The observed journey remains below the insights panel, giving you the broader investigation view alongside the explanation.
Analysis runs when you open an eligible journey. Saved results are reused, and expanding evidence does not request another AI analysis. When newer evidence is available, you can explicitly update the analysis.
Scope is part of the result. A panel that says 48 of 686 requests analyzed describes those 48 requests, with their observation dates visible. It does not claim to explain every request in the actor’s history.
The analysis uses up to the latest 48 stored requests. Earlier activity and traffic that was not recorded may differ. Activity groups are separated by gaps in the sample; they are not verified sessions or proof that nothing happened between observations.
Redaction also matters. Different original URLs can look identical after sensitive values are removed. WebDecoy checks whether the saved data supports exact target grouping before assigning repeat evidence or a target’s share of requests.
And a likely collection target is an inference. It does not establish successful collection, malicious intent, or who operates the traffic. Journey Insights leaves threat scores and enforcement decisions unchanged, giving you evidence to review before you decide what to do.
For a content team, the next question may be which articles attract repeated attention. For an engineer, it may be whether requests are spread across routes or concentrated on one endpoint. For an analyst, it may be which detections deserve a closer look.
AI Journey Insights gives each of them a clearer starting point: a takeaway, observed behavior, and direct access to the supporting requests.
Open WebDecoy and investigate an actor’s journey.
New to WebDecoy? Explore AI Journey Insights and the detection platform, or see how WebDecoy measures AI crawler activity and referrals.
Open Actors in WebDecoy, select an actor, and open its Journey tab for the property you want to investigate. Eligible journeys are analyzed on demand. The panel shows a takeaway, AI classifications, observed sample behavior, and links to the underlying detections.
It uses a bounded sample of up to the latest 48 stored requests for the selected actor and property. The panel shows the sample count, full stored count, and observation dates. Earlier or unrecorded traffic may behave differently.
No. Journey Insights helps you investigate likely collection targets and access patterns. It does not change threat scores or enforcement decisions. Review the supporting detections before deciding how to respond.
Most of FCaptcha v1.28–v1.34 protects the visitor who did nothing wrong: expired tabs, sparse mouse traces, invisible mode. Plus one breaking change.
bot-detectionBenchmark bot detection in shadow mode, measure precision and recall, protect shared-IP users, and roll out enforcement without losing customers.
bot-detectionAI Traffic is live in WebDecoy. See crawls and observed AI referrals for your property, then freeze the figures into a shareable report.
bot-detectionLike this post? Share it with your friends!
Get a personalized demo from our team.