Not reCAPTCHA, please. It’s horrendous in any environment that blocks any real amount of tracking. Rate limiting would solve the bot issue without inconveniencing regular users.
As someone with lots of anti-anti-botting knowledge - both are ineffective. Even if it's a "global rate limit" I'll find out the value (never ran into someone randomizing it) and jump on the web request faster than anyone else RIGHT as it comes up. With CAPTCHAs I'll bypass with a solving service and/or computer vision if it's easy, or even just get past the noCAPTCHA solutions with primed browser instances from cred…
What would solve it? Or rather, what is the best defensive measure these days?