Skip to main content
This article will introduce a method for integrating the hCaptcha protocol recognition API, which allows users to bypass the identification and clicking of hCaptcha verification images, and instead achieve automatic decoding in the background by simply submitting the Website Key.

Application Process

To use the hCaptcha protocol recognition API, first go to the Ace Data Cloud Console to obtain your API Token for future use. If you are not logged in or registered, you will be automatically redirected to the login page inviting you to register and log in, after which you will be automatically returned to the current page. One API Token can call all services on the platform, without the need to apply separately for each service. The first application will grant a free quota for a trial experience; when the quota is insufficient, you can recharge the general balance in the console.
📘 Complete Documentation: hCaptcha Protocol Recognition API →

Basic Usage

First, understand the basic usage method, which is to input the URL of the website that needs to process the hCaptcha verification code to obtain the processed result. You first need to simply pass a website_url field. Our example website is: https://accounts.hcaptcha.com/demo, and we need to obtain the website_key from the website_url page. First, open this webpage, press F12 to enter the console, and then perform a global search for hcaptcha-demo on the Element page. We can obtain the following result:

The string corresponding to data-sitekey is the value of the website_key. Below are the specific parameter results:

Here we can see that we have set the Request Headers, including:
  • accept: the format of the response result you want to receive, filled in as application/json, which means JSON format.
  • authorization: the key for calling the API, which can be directly selected after application.
Additionally, the Request Body is set, including:
  • website_url: the URL of the website that needs to process the verification code.
  • website_key: the website key identifier in hCaptcha.
After selection, you can find that the corresponding code is also generated on the right side, as shown in the figure:

Click the “Try” button to conduct a test, as shown in the above figure, where we obtained the following result:
We can see that we have obtained the verification result for processing the hCaptcha verification code, which we can use for POST or simulate submission to the target website, for one-time use, valid for 120 seconds, and it is recommended to use it within 60 seconds. Next, a CURL version will be provided to submit the processed token to the target website to pass the Recaptcha2 verification. First, we need to understand how the website sends the POST request so that we can pass the generated token into it. We need to open the F12 console and manually go through the verification. Finally, we can see that the website has sent a POST request. We only need to check the construction of this POST request. The specific process is as follows:
  • First, manually go through the verification, as shown in the figure below:

  • Then click submit and watch the changes in the console’s network, as shown in the figure below:

  • Analyze the construction of this submitted POST request, and finally right-click on the request to copy the CURL code, as shown in the figure below:

From the above analysis, we can see that the URL of this POST request is: https://accounts.hcaptcha.com/demo. We only need to submit the parameters g-recaptcha-response, h-captcha-response, and email, and then we just need to pass the processed token into the data below. The corresponding CURL code for calling the token verification is as follows:
The corresponding Python code for calling the token verification is as follows:
Then we observe that the console has changed to the following result:

Finally, we have passed the hCaptcha verification. Additionally, if you want to generate the corresponding integration code, you can directly copy it, for example, the CURL code is as follows:
The Python integration code is as follows:

Asynchronous Mode (async)

By default, the API is synchronous and blocking: a request will wait until the token processing is complete before returning. If you are doing multi-solver rotation and want to “immediately get the task_id after submitting the task, schedule other solvers, and come back later to get the result,” you can pass async: true in the request body. After passing async: true, the interface will immediately return a task_id without blocking:
Then use the task_id to poll POST /captcha/tasks (recommended every 3-5 seconds) to get the result:
During processing, it will return status: processing:
When processing is complete, it will return status: ready and the token:
Billing Explanation: In asynchronous mode, creating tasks and polling “processing” do not incur charges; only when successfully obtaining the token is there a charge once (consistent with the price of synchronous mode). Therefore, canceling unfinished tasks during rotation will not incur costs. /captcha/tasks is applicable to all verification code interfaces (token and recognition series, such as hcaptcha, recaptcha2, recaptcha3, recognition/*, etc.), and the same task_id can be used for polling.

Error Handling

When calling the API, if an error occurs, the API will return the corresponding error code and message. For example:
  • 400 token_mismatched: Bad request, possibly due to missing or invalid parameters.
  • 400 api_not_implemented: Bad request, possibly due to missing or invalid parameters.
  • 401 invalid_token: Unauthorized, invalid or missing authorization token.
  • 429 too_many_requests: Too many requests, you have exceeded the rate limit.
  • 500 api_error: Internal server error, something went wrong on the server.

Error Response Example

Conclusion

Through this document, you have learned how to use the hCaptcha protocol recognition API to allow users to bypass recognizing and clicking on hCaptcha verification code images, achieving automatic decoding in the background by simply submitting the Website Key. We hope this document can help you better integrate and use this API. If you have any questions, please feel free to contact our technical support team.