Generate headers
Generate request headers for one protected API call.
session_id for a follow-up request. Fresh solves are sessionless by
default. Set retain_session: true on the initial request when another
protected request may follow. The final application request is always
submitted by your backend, not by Evade.
Set task to shape on every request.
shape_js_url is optional only when Evade can discover the loader or an
embedded interstitial from target_url. Evade never submits the request to
the destination application.Supply the loader JavaScript
On a fresh solve, you can setloader_source to the exact JavaScript returned
by shape_js_url. This avoids downloading the loader again. Keep
shape_js_url in the request: it identifies the loader and is fetched
automatically if the supplied source cannot be parsed as a valid loader.
Pass the JavaScript as a normal JSON string, not as base64. loader_source is
optional, cannot be used on a session continuation, and is limited to 4 MiB.
Content-Encoding: gzip or Content-Encoding: zstd. The decoded request
body is limited to 12 MiB.Authorizations
Evade API key with the solve scope.
Headers
Optional compression for the entire JSON request body. Use gzip or zstd when including a large loader_source. The decoded request body is limited to 12 MiB.
identity, gzip, zstd Body
- Fresh solve request
- Session continuation request
Solver router discriminator. Must be shape.
"shape"Absolute http, https, socks4, or socks5 proxy URL.
"http://username:password@proxy.example:8080"
Absolute URL of the protected page.
Exact destination URL of the application request.
Required HTTP method of the protected application request.
GET, POST Absolute page referrer.
IANA timezone matching the proxy exit region.
"America/Los_Angeles"
Shape loader URL. Optional when Evade can discover the loader or an embedded interstitial from target_url.
Optional exact JavaScript source returned by shape_js_url for a fresh solve. Pass plain JavaScript as a JSON string, not base64. Evade uses shape_js_url as a network fallback when the supplied source cannot be parsed as a valid loader. Cannot be supplied on a session continuation.
4194304Optional page title; extracted from the fetched page when available.
Optional browser user agent. When omitted, Evade selects a browser
identity and returns it as user_agent.
Current application cookies to install in the solve session.
Browser API modeled during generation. direct requires a GET navigation
whose target_api exactly matches target_url.
xhr, fetch, direct Keep the solve state for follow-up protected requests and return a session_id. Set this on the initial request when a continuation may be selected from the application response. Omit it for one request.
Include diagnostic response fields. Requires the debug scope.
Response
Headers generated successfully.
Solver-owned browser and Shape headers for the protected request.
Exact user agent to use for replay.
Short-lived continuation ID. Returned only when the initial request set retain_session to true; omitted for sessionless solves and one-time interstitials.
^[A-Za-z0-9_-]{32}$True when the result can be replayed only once and cannot be resumed.
Debug-only continuation indicator.