Inspiration
Passwords, OTPs, MFA and CAPTCHAs are already widely used to protect online applications. However, we wanted to explore a different question:
What if security verification could feel more like a game while remaining a serious security layer?
This idea led us to Veyra.
We imagined a system where users create a personalized security pattern using elements such as a preferred color, a preferred visual pattern and a secret word. During verification, Veyra generates a new challenge each time, mixing letters, colors and patterns.
The user knows the rule, but the challenge itself keeps changing.
Our goal was not to replace MFA or existing security systems, but to create an additional layer that makes automated abuse more difficult while keeping verification simple and engaging for legitimate users.
What it does
Veyra is a gamified security API that applications can integrate as an additional verification layer.
A Veyra challenge can combine:
- A user's secret word
- Their selected security color
- Their selected visual pattern
- Randomized letters and distractors
- A time-limited challenge
- Interaction and session signals
For example, if a user's security color is purple and their secret word is TIGER, Veyra can generate a grid containing many letters in different colors.
The user must select the correct letters according to their personalized security rule.
The challenge is regenerated instead of simply replaying the same CAPTCHA.
Veyra can then return a security result to the application:
{
"verified": true,
"risk_level": "low"
}
For suspicious activity, the application can request an additional verification step such as MFA.
The important part is that Veyra is designed as an API first. Developers should be able to integrate the security layer into their own websites or applications through a lightweight widget or SDK.
How we built it
We started with the backend because the API is the core of Veyra.
The system is organized around several components:
Application
│
▼
Veyra API
│
┌───┼───────────────┐
▼ ▼ ▼
Challenge Verification Risk
Engine Engine Engine
│ │ │
└─────────────────┼─────────────┘
▼
Security Result
The Challenge Engine generates randomized security games.
The Verification Engine validates the user's selections and ensures that challenges expire and cannot simply be reused.
The Risk Engine is designed to combine security signals and provide an additional risk assessment.
We also designed a lightweight frontend widget so that the challenge can appear as a small popup instead of requiring developers to build a complete security interface themselves.
Our approach is intentionally API-first: the application being protected remains responsible for its own authentication, while Veyra provides an additional verification layer.
Challenges we ran into
One of our biggest challenges was balancing security and usability.
A challenge that is too simple may be easier to automate. But a challenge that is too complicated can frustrate legitimate users.
We also had to think about unpredictability.
If the challenge always places the same letters in the same positions, an automated system could potentially learn the pattern. This is why Veyra generates different layouts, colors, positions and distractors.
Another challenge was deciding what information should be stored.
Security systems should not unnecessarily store sensitive information. This pushed us to think about how secrets, challenge states and behavioral signals should be handled without exposing the user's actual secret.
Finally, building a security API is different from building a normal application. Every endpoint has to be considered from an attacker's perspective: replay attacks, brute force attempts, automated requests, rate abuse and invalid input all need to be handled.
Accomplishments that we're proud of
We are proud that we moved beyond the idea of simply creating another CAPTCHA.
We created the concept of a personalized, dynamic security game that can function as an API rather than being tied to a single website.
We are particularly proud of:
- Designing a security mechanism that changes from challenge to challenge.
- Combining personalization with randomized challenges.
- Making the architecture API-first.
- Separating challenge generation, verification and risk analysis.
- Designing the system so it can complement existing MFA instead of replacing it.
- Creating a concept that could eventually be integrated into different types of applications.
Most importantly, we turned an initial idea into a concrete security architecture that can be tested and expanded.
What we learned
This project taught us that cybersecurity is not only about making attacks difficult.
It is also about designing systems that remain usable, reliable and predictable for legitimate users while being unpredictable for automated attackers.
We learned about:
- API security
- Challenge generation
- Authentication and MFA
- Rate limiting
- Secure handling of secrets
- Session security
- Randomization
- Risk-based verification
- Human-computer interaction
- Security versus usability trade-offs
We also learned an important lesson: no single security mechanism should be treated as perfect.
A better approach is to combine multiple layers.
Veyra therefore treats its challenge as one additional signal in a larger security system rather than claiming that a game alone can definitively distinguish every human from every bot.
What's next for Veyra
The hackathon version focuses on proving the core concept.
The next versions could expand Veyra into a more complete adaptive security platform.
Possible improvements include:
- WebAuthn and passkey integration
- Adaptive challenge difficulty
- Stronger bot and automation detection
- Device and session risk analysis
- Security event webhooks
- Developer dashboard
- JavaScript and Python SDKs
- More challenge types
- Accessibility-focused challenges
- Privacy-preserving behavioral signals
- Real-time security notifications
We also want to make Veyra easier for developers to integrate, with a simple API such as:
POST /v1/challenges
POST /v1/challenges/{id}/verify
Our long-term vision is simple:
Veyra should become a security layer that developers can add to an application without rebuilding their entire authentication system.
Instead of treating security verification as a repetitive obstacle, Veyra explores a different approach:
Make security dynamic, personalized and harder to automate — without making it harder for legitimate users.
Built With
- language
Log in or sign up for Devpost to join the conversation.