I have a need at #dayjob to add some kind of bot-signup prevention on a public-facing web app, i.e., a #CAPTCHA. I'm strongly opposed to using #reCAPTCHA, and I'm not crazy about the CAPTCHA user experience in general.
Things I'm currently considering are the Honeypot Technique, email verification, timestamps, and OAuth. What's the best practice in 2019?