Before you submit — these must be correct
If any of these are wrong, your token may be accepted by our solver but rejected or scored poorly by the target site.
- Send all three values together: token as x-castle-request-token, __cuid as a cookie, and match the returned User-Agent. Sending the token without the cuid cookie triggers InvalidRequestTokenError server-side.
- Tokens expire in 120 seconds and are single-use. Generate a fresh one for each protected request — do not cache or reuse.
Castle Bot Defense Solver, solved in 5.0s.
Generate Castle Bot Defense request tokens automatically. Pass your publishable key and website URL — get back the x-castle-request-token and matching __cuid cookie.
Castle (castle.io) is an account-security and fraud-prevention SDK used by gaming platforms, fintech, and e-commerce sites. It is not a traditional captcha — there is no visible puzzle. Instead, Castle's JavaScript SDK silently collects behavioral fingerprints and device signals, then exposes a createRequestToken() method that produces a short-lived risk-scored token. The token is sent from the client to the site's backend as the HTTP header x-castle-request-token or the hidden form field castle_request_token. The backend validates it against Castle's API, which returns a risk action: allow, challenge, or deny. Castle is commonly used at login, signup, checkout, and password-reset flows on gaming, fintech, and e-commerce sites. Tokens expire after 120 seconds and are single-use. They are bound to the __cuid session cookie — a persistent 16-byte random device identifier Castle stores in the browser. You must send both the token and the __cuid cookie together, or Castle's server-side validation will flag the session as spoofed.
Quick Integration
import requests, time
API = "https://api.capzy.ai"
KEY = "capzy_your_key_here"
# Step 1: Create task
task = requests.post(f"{API}/createTask", json={
"clientKey": KEY,
"task": {
"type": "CastleTaskProxyLess",
"websiteURL": "https://your-target-site.com/signup",
"config_json": "{\"pk\":\"pk_XXXXXXXXXXXXXXXXXXXXXXXXXXXX\",\"wUrl\":\"https://cdn.your-target-site.com/castle/cw.js\",\"swUrl\":\"https://cdn.your-target-site.com/castle/csw.js\",\"avoidCookies\":true}",
"ip": "203.0.113.10"
}
}).json()
task_id = task["taskId"]
print(f"Task created: {task_id}")
# Step 2: Poll for result
while True:
result = requests.post(f"{API}/getTaskResult", json={
"clientKey": KEY,
"taskId": task_id
}).json()
if result["status"] == "ready":
print("Solved!", result["solution"])
break
elif result["status"] == "failed":
print("Failed:", result.get("errorDescription"))
break
time.sleep(1)
Using the result
# Step 3: Use the result — paste the token into the site's captcha form field
token = result["solution"]["token"]
# Browser side: set the textarea value or the hidden input. Then submit.
# Server-to-server: post the token alongside the form fields you normally send.
resp = requests.post("https://target.example.com/submit", data={
"username": "...",
"captcha_response": token, # <-- replace with the field name your site uses
})
print(resp.status_code)1. Send Payload
Dispatch your CastleTaskProxyLess to our processing cluster via the secure API endpoint.
2. Solving Engine
Our solver navigates the real target URL so Castle's SDK initialises in its native context, with the site's own worker scripts, service workers, and behavioral collection active. Modern sites bundle Castle as an ES module (Castle.configure(...).createRequestToken()) so there is no window.Castle global — we handle both integrations: we mint from the page's own SDK when a global is present, otherwise we load the Castle browser SDK ourselves and configure it with your config_json (worker URLs included), and as a final fallback capture the x-castle-request-token the page mints itself. We return the token, the matching __cuid cookie value, and the User-Agent string. You attach the token as x-castle-request-token, set Cookie: __cuid=<cuid>, and match the User-Agent we return. Designed for authorized security testing, QA automation, and bot-detection research.
3. Get Result
Poll getTaskResult for the validated token, then finalize your automated request.
Using your own proxy
Use CastleTask instead of CastleTaskProxyLess to route the solve through your own proxy — useful when the target site checks that the solving IP matches the submitting IP.
import requests, time
API = "https://api.capzy.ai"
KEY = "capzy_your_key_here"
# Step 1: Create task
task = requests.post(f"{API}/createTask", json={
"clientKey": KEY,
"task": {
"type": "CastleTask",
"websiteURL": "https://your-target-site.com/signup",
"config_json": "{\"pk\":\"pk_XXXXXXXXXXXXXXXXXXXXXXXXXXXX\",\"wUrl\":\"https://cdn.your-target-site.com/castle/cw.js\",\"swUrl\":\"https://cdn.your-target-site.com/castle/csw.js\",\"avoidCookies\":true}",
"proxyType": "http",
"proxyAddress": "123.45.67.89",
"proxyPort": "8080",
"proxyLogin": "user",
"proxyPassword": "pass"
}
}).json()
task_id = task["taskId"]
print(f"Task created: {task_id}")
# Step 2: Poll for result
while True:
result = requests.post(f"{API}/getTaskResult", json={
"clientKey": KEY,
"taskId": task_id
}).json()
if result["status"] == "ready":
print("Solved!", result["solution"])
break
elif result["status"] == "failed":
print("Failed:", result.get("errorDescription"))
break
time.sleep(1)
Additional proxy parameters
proxyTypetypestringreqrequiredProxy protocol: http, https, socks4, or socks5proxyAddresstypestringreqrequiredProxy IP address or hostnameproxyPorttypenumberreqrequiredProxy port numberproxyLogintypestringreqoptionalProxy username (if auth required)proxyPasswordtypestringreqoptionalProxy password (if auth required)userAgenttypestringreqoptionalUser-Agent string to use. Must match the UA you use when submitting the tokenTask Parameters
API SpectypetypestringreqrequiredCastleTaskProxyLess or CastleTaskwebsiteURLtypestringreqrequiredThe exact page URL where Castle is active (e.g. the login or signup page). Castle's SDK must load on this page.config_jsontypeobjectreqrequiredThe Castle.configure() object for this site. The pk field (publishable key, starts with pk_) is required. Other site-specific fields such as wUrl, swUrl, and avoidCookies are passed through as-is.config_json.sdkUrltypestringreqoptionalOptional. Direct URL to the Castle browser SDK to inject on sites that bundle Castle as a module (no window.Castle global). Tried before our built-in candidates. Only needed if a bundled site's token minting fails; most sites work without it.backendtypestringreqoptionalOptional. Leave unset for the default fast engine (~1s). Pass "browser" to force a full real-browser solve instead — slower, only needed in rare cases where the fast path can't mint a token.iptypestringreqoptionalRecommended. The IP address you will submit the token from. Castle scores the token's timezone against the geo of the request IP — we look up the timezone for your IP and mint the token to match, so no proxy is needed. Pass this for the fastest, most reliable solve. If you send a proxy instead, we use the proxy's exit geo automatically.Response Shape
tokentypestringThe Castle request token. Set this as the x-castle-request-token header (or castle_request_token form field) on your follow-up request. 120-second TTL, single-use.cuidtypestringValue of the __cuid cookie bound to the token. You must send Cookie: __cuid=<cuid> on the same request as the token, or Castle will flag it as spoofed. Empty when the site uses avoidCookies: true.userAgenttypestringThe User-Agent of the browser that generated the token. Set this on your follow-up request to keep the fingerprint coherent.Example response
{
"errorId": 0,
"status": "ready",
"solution": {
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJjdWlkIjoiYWJjMTIzZGVmNDU2Nzg5MCIsImlhdCI6MTcyMDAwMDAwMCwiZXhwIjoxNzIwMDAwMTIwfQ.SigPlaceholder",
"cuid": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4",
"userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
}
}Error response
{
"errorId": 1,
"errorCode": "ERROR_CAPTCHA_UNSOLVABLE",
"errorDescription": "Solver gave up."
}Features
Pricing & Stats
Start solving castle bot defense.
$0.10 in free credits — no card. ~250 free solves to test before you spend.