Skip to main content
POST
An interstitial is DataDome’s automatic device check (rt: "i", the i.js loader, or a /interstitial/ device URL). Set task to datadome and mode to interstitial. The response payload is already serialized in DataDome’s required form order — submit it unchanged.
Send device_link and html from the current fetch. When the HTML references an external challenge bundle, fetch it through the same target session and send its exact response body as the singular script field. Omit script when the challenge bundle is inline. Evade derives the external script URL from the HTML and does not fetch the page or bundle for you.
The legacy page, document_url, document_navigation_start_ms, and scripts fields are not accepted by this contract.

1. Obtain the device URL

If the blocked response is JSON with a captcha-delivery.com URL, use it unchanged. For an HTML block page, build it from the dd object and the blocked response’s datadome cookie, percent-encoding each query value and preserving any extra values the current loader emits:

2. Fetch the device page and bundle

Fetch the device URL through the same proxy, User-Agent, and cookie jar. Send the final fetched URL as device_link, the exact response body as html, and the session_id. Evade generates navigation timing internally. If the HTML references an external challenge script, fetch that script through the same target session and send only its exact response body as script. Do not send a script URL or an array. If the challenge code is inline, omit script. Reuse the session_id returned by the tags solve so the interstitial uses the same fingerprint and location identity.

3. Submit to DataDome

POST the returned payload to the device URL without its query string (e.g. https://geo.captcha-delivery.com/interstitial/) using Content-Type: application/x-www-form-urlencoded; charset=UTF-8, the returned headers, and the same client. Install the returned cookie into the jar and retry the protected request.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
task
string
required

Solver router discriminator. Must be datadome.

Allowed value: "datadome"
mode
string
required
Allowed value: "tags"
session_id
string
required

Opaque ID returned by an earlier solve. Omit on the first solve.

ddk
string
required

Site key observed in the site's genuine /js/ request.

referer
string<uri>
required
tags_type
enum<string>
required
Available options:
ch,
le
script
string
required

Exact tags.js source the page loaded, fetched through the same connection. Its build defines the beacon's field order and the ddv version, so send the bytes unchanged.

user_agent
string

Exact target User-Agent. Required when session_id is omitted.

accept_language
string

Exact target Accept-Language header. Required when session_id is omitted; navigator.languages is derived server-side.

cid
string

Current datadome cookie value, or an empty string on a fresh visit.

ip
string

Public IP that will submit the beacon. On the first solve, Evade resolves its timezone and country through MaxMind.

hsv
any

Current window._hsv value when the page defines it.

correlation_id
string | null

Page correlation callback result; omit when unpublished.

local_storage_session
boolean
default:false

Response

Requested DataDome material generated.

session_id
string
required

Carry this opaque ID into every later solve for the same target session.

payload
string
required

Complete ordered application/x-www-form-urlencoded request body. Submit it unchanged.

expires_in_seconds
integer

Present when this solve created the session.

client_hints
object

Transport projection present when this solve created the session.

device_memory
integer

Present when this solve created the session.