Skip to main content
POST
A slider challenge is identified by rt: "c", the c.js loader, or a /captcha/ device URL; it can also follow an interstitial whose view is captcha. Set task to datadome and mode to captcha. Fetch the captcha page through the same proxy, User-Agent, and cookie jar, then submit its exact HTML as page with document_url and parent_url. If the page references its Browserify bundle through one external script instead of embedding it, fetch that script through the same target session and submit its exact source as the optional script field. Evade performs no target fetches. It generates the full slider interaction and its timeline server-side, so no interaction or timing input is required. Reuse the session_id returned by the tags solve so the slider uses the same fingerprint and location identity.
Add "script": "...exact fetched Browserify source..." only when the captcha page references an external bundle.

Submit the check

The response payload is the complete DataDome request URL. GET it unchanged through the same client with the returned headers, using the captcha page as the referrer and preserving the cookie jar. When DataDome returns a cookie value, replace the existing datadome cookie and retry the protected request.
Only the simple-slider configuration is supported. A puzzle-image challenge that needs an unresolved image displacement fails closed with captcha_failed instead of returning a guess.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
task
string
required

Solver router discriminator. Must be datadome.

Allowed value: "datadome"
mode
string
required
Allowed value: "tags"
session_id
string
required

Opaque ID returned by an earlier solve. Omit on the first solve.

ddk
string
required

Site key observed in the site's genuine /js/ request.

referer
string<uri>
required
tags_type
enum<string>
required
Available options:
ch,
le
script
string
required

Exact tags.js source the page loaded, fetched through the same connection. Its build defines the beacon's field order and the ddv version, so send the bytes unchanged.

user_agent
string

Exact target User-Agent. Required when session_id is omitted.

accept_language
string

Exact target Accept-Language header. Required when session_id is omitted; navigator.languages is derived server-side.

cid
string

Current datadome cookie value, or an empty string on a fresh visit.

ip
string

Public IP that will submit the beacon. On the first solve, Evade resolves its timezone and country through MaxMind.

hsv
any

Current window._hsv value when the page defines it.

correlation_id
string | null

Page correlation callback result; omit when unpublished.

local_storage_session
boolean
default:false

Response

Requested DataDome material generated.

session_id
string
required

Carry this opaque ID into every later solve for the same target session.

payload
string
required

Complete ordered application/x-www-form-urlencoded request body. Submit it unchanged.

expires_in_seconds
integer

Present when this solve created the session.

client_hints
object

Transport projection present when this solve created the session.

device_memory
integer

Present when this solve created the session.