No, a CSRF token only introduces information that is not part of the ambient authority of the HTTP client (i.e. an attacker cannot implicitly use it) – it is not uncommon to have deterministic or relatively constant CSRF tokens (e.g. the double-send cookie method). An n-once would fulfil your criteria but is importantly not a valid CSRF token unless it is also correlated or derived from something the attacker can’t know like a session; otherwise the attacker can use their own n-once to submit a victim request.
That and also, most captcha I've used so far require a server-side validation that is not replayable with Curl (as the token has been used during the first submission).
Yes, but captcha is on the form. I'm thinking more about a single-page app that submits form data via an API. That API call can generally be replayed.