Skip to main content
POST
Create a new solve with the complete page and regional context, or provide an active session_id for a follow-up request. Fresh solves are sessionless by default. Set retain_session: true on the initial request when another protected request may follow. The final application request is always submitted by your backend, not by Evade. Set task to shape on every request.
Replay all returned headers and the returned user_agent unchanged through the same proxy. Generate a new header set whenever the destination URL, method, or application context changes.
shape_js_url is optional only when Evade can discover the loader or an embedded interstitial from target_url. Evade never submits the request to the destination application.

Supply the loader JavaScript

On a fresh solve, you can set loader_source to the exact JavaScript returned by shape_js_url. This avoids downloading the loader again. Keep shape_js_url in the request: it identifies the loader and is fetched automatically if the supplied source cannot be parsed as a valid loader. Pass the JavaScript as a normal JSON string, not as base64. loader_source is optional, cannot be used on a session continuation, and is limited to 4 MiB.
For large loaders, compress the entire JSON request body with gzip or zstd and set Content-Encoding: gzip or Content-Encoding: zstd. The decoded request body is limited to 12 MiB.

Authorizations

Authorization
string
header
required

Evade API key with the solve scope.

Headers

Content-Encoding
enum<string>
default:identity

Optional compression for the entire JSON request body. Use gzip or zstd when including a large loader_source. The decoded request body is limited to 12 MiB.

Available options:
identity,
gzip,
zstd

Body

application/json
task
string
required

Solver router discriminator. Must be shape.

Allowed value: "shape"
proxy
string<uri>
required

Absolute http, https, socks4, or socks5 proxy URL.

Example:

"http://username:password@proxy.example:8080"

target_url
string<uri>
required

Absolute URL of the protected page.

target_api
string<uri>
required

Exact destination URL of the application request.

target_api_method
enum<string>
required

Required HTTP method of the protected application request.

Available options:
GET,
POST
referer
string<uri>
required

Absolute page referrer.

time_zone
string
required

IANA timezone matching the proxy exit region.

Example:

"America/Los_Angeles"

shape_js_url
string<uri>

Shape loader URL. Optional when Evade can discover the loader or an embedded interstitial from target_url.

loader_source
string

Optional exact JavaScript source returned by shape_js_url for a fresh solve. Pass plain JavaScript as a JSON string, not base64. Evade uses shape_js_url as a network fallback when the supplied source cannot be parsed as a valid loader. Cannot be supplied on a session continuation.

Maximum string length: 4194304
title
string

Optional page title; extracted from the fetched page when available.

ua
string

Optional browser user agent. When omitted, Evade selects a browser identity and returns it as user_agent.

cookies
object

Current application cookies to install in the solve session.

request_transport
enum<string>
default:xhr

Browser API modeled during generation. direct requires a GET navigation whose target_api exactly matches target_url.

Available options:
xhr,
fetch,
direct
retain_session
boolean
default:false

Keep the solve state for follow-up protected requests and return a session_id. Set this on the initial request when a continuation may be selected from the application response. Omit it for one request.

debug
boolean
default:false

Include diagnostic response fields. Requires the debug scope.

Response

Headers generated successfully.

success
boolean
required
headers
object
required

Solver-owned browser and Shape headers for the protected request.

user_agent
string
required

Exact user agent to use for replay.

timings
object
required
session_id
string

Short-lived continuation ID. Returned only when the initial request set retain_session to true; omitted for sessionless solves and one-time interstitials.

Pattern: ^[A-Za-z0-9_-]{32}$
one_time
boolean

True when the result can be replayed only once and cannot be resumed.

session_reused
boolean

Debug-only continuation indicator.