Supported WAF and Challenge Solutions

Overview

Scrapingbypass API is specifically optimized for bypassing advanced Web Application Firewalls (WAF) and automated browser integrity checks. While we offer industry-leading success rates for specific security suites, our service does not cover every captcha provider.

Supported Protections

The Scrapingbypass API currently supports the automated resolution of the following challenges:

  • Cloudflare
    • JavaScript Challenge: Automatically solves the "5-second shield" (IUAM).
    • Turnstile: Seamlessly handles non-interactive and managed challenges via the [cf_token] injection method.
  • Imperva (Incapsula)
    • Bypasses specialized WAF challenges and integrity checks used by Imperva-protected endpoints.

Unsupported Services

At this time, Scrapingbypass API does not support the following:

  • Google reCAPTCHA: We currently do not provide bypass services for reCAPTCHA v2 (checkbox) or v3 (score-based).
  • Other 3rd-party Captchas: Challenges such as hCaptcha, GeeTest, or AWS WAF Captcha are not currently within our supported scope.

Core Focus

Our engineering team focuses exclusively on Cloudflare and Imperva ecosystems to ensure maximum stability and consistency in TLS/JA3 impersonation and session persistence. If your target site utilizes Google reCAPTCHA, you will need to utilize a dedicated captcha-solving service as Scrapingbypass API will not automatically resolve it.


Recommendation

To verify if a target URL is compatible, perform a test request using the V2 endpoint. If the site triggers a Cloudflare Turnstile or JS Challenge, Scrapingbypass API will handle it automatically. For sites behind Google reCAPTCHA, the request will likely return a 403 or 405 error as it is outside our current technical scope.