FunCaptcha

Solves Arkose Labs FunCaptcha, including rotate, match and pick-the-image puzzles. Costs $1.00 per 1,000 tokens.

Task object

Send this as task in createTask.

FunCaptchaTask fields
FieldTypeDescription
type RequiredstringAlways FunCaptchaTask.
websiteURL RequiredstringThe full URL of the page where the captcha appears.
websitePublicKey RequiredstringThe Arkose public key for the site. See below for how to find it.
funcaptchaApiJSSubdomain OptionalstringThe host the site loads Arkose from, if it is not client-api.arkoselabs.com.
data OptionalstringExtra data the site passes to Arkose, as a JSON string. Usually a blob value.
proxy RecommendedstringThe proxy your session uses, so the token is issued for the same IP.
userAgent OptionalstringThe user agent your session uses. Send it when you send a proxy.
JSON
{
  "clientKey": "YOUR_API_KEY",
  "task": {
    "type": "FunCaptchaTask",
    "websiteURL": "https://example.com/signup",
    "websitePublicKey": "476068BF-9607-4799-B53D-966BE98E2B81",
    "funcaptchaApiJSSubdomain": "client-api.arkoselabs.com",
    "data": "{\"blob\":\"HERE_IS_THE_BLOB\"}",
    "proxy": "http://user:[email protected]:8080",
    "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ..."
  }
}

Finding the public key

Open the page with your browser's developer tools and look for one of these:

  • A data-pkey attribute on the element that holds the captcha.
  • A network request to /fc/gt2/public_key/<KEY> or /v2/<KEY>/api.js. The key is the part in angle brackets.
  • A pk= parameter in the captcha iframe's URL.

If those requests go to a host other than client-api.arkoselabs.com, send that host as funcaptchaApiJSSubdomain.

Blob data

Some sites pass a one-time blob to Arkose. It appears in the same network requests, often as data[blob]. Fetch a fresh blob for every task and send it as {"blob":"..."} in data. A reused blob produces a token the site will reject.

Solution

FunCaptcha solution fields
FieldTypeDescription
token RequiredstringThe Arkose session token. Submit it where the site expects fc-token or verification-token.
JSON
{
  "errorId": 0,
  "status": "ready",
  "solution": {
    "token": "3017b7b5a0c23c1f2.1234567805|r=us-east-1|meta=3|..."
  }
}

Tokens are tied to the IP and user agent they were solved with. Send the same proxy and user agent you'll submit the token from.