retain_session: true on the
initial request when another protected request may follow. A successful
retained solve returns a session_id; reusing it preserves the prepared proxy,
page, browser identity, page profile, and challenge state. Embedded
interstitials return one_time: true and cannot be resumed.
Start a session
A new session requires:taskproxytarget_urltarget_apitarget_api_methodreferertime_zoneretain_session: true
shape_js_url is required only when the loader cannot be discovered from the
page. ua is optional; when omitted, Evade selects the browser identity.
Omit retain_session for a single protected request. If the first application
response determines whether another protected request is needed, set
retain_session: true before the first solve. A sessionless result cannot be
converted into a retained session afterward.
Continue a session
target_api and target_api_method remain required because each generated set
is bound to that request. You may also pass current cookies from the previous
application response so the solver session observes updated application state.
Omit time_zone on continuation requests; it can only be set when the session
starts. Other original context fields can be omitted. If provided, they must
exactly match the cached session.
Do not send retain_session on a continuation request. The active
session_id already identifies the retained session.
Expiration
Sessions are short-lived—10 minutes after their last use by default. An unavailable ID returns400 invalid_request. Create a new session with the
complete initial request instead of retrying the ID.