Overview
dePuzzled solves captchas in a real browser and returns the token. It speaks the CapSolver protocol, so an existing integration only needs its base URL changed.
Initial setup
On first start there is no account, and every page redirects to /setup. Creating the account is the only way in — there is no registration endpoint and no password reset. The database is created and migrated automatically on boot.
Authentication
Send the API key in the request body as clientKey, matching CapSolver's wire format. Keys are stored as hashes; the plaintext is shown once at creation.
POST /createTask
Content-Type: application/json
{
"clientKey": "dp_live_…",
"task": { … }
}Creating a key
Open APIs and choose Create API key. A key can be limited by rate and by source address, and can be rotated or revoked at any time.
Captcha types
The task type decides which solver runs. ProxyLess variants use the configured proxy pool.
| Task type | Returns | Typical time |
|---|---|---|
| AntiTurnstileTaskProxyLess | token | 3–12 s |
| ReCaptchaV2TaskProxyLess | gRecaptchaResponse | 4–15 s |
| ReCaptchaV3TaskProxyLess | gRecaptchaResponse | 3–10 s |
| HCaptchaTaskProxyLess | token | 5–20 s |
| AntiCloudflareTask | cf_clearance cookie | 8–25 s |
Errors
| Status | Description |
|---|---|
| 401 | Missing or invalid API key |
| 403 | Key revoked, or the source address is not allowed |
| 429 | Rate limit exceeded for this key |
| 400 | Malformed request or unsupported task type |
| 503 | The solver is temporarily unavailable |
Limits
Concurrency, timeouts, and retention are set in Settings and apply immediately — no restart. A task lives for 5 minutes or 120 polls, whichever comes first.
Security
Keep keys on your server, never in client-side code. Requests to private and loopback addresses are refused by default. Revoke unused keys from the API detail page.