> For the complete documentation index, see [llms.txt](https://docs.apexsolutions.lol/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.apexsolutions.lol/altcha/workflow.md).

# Integration Workflow

The end-to-end Altcha integration: get the challenge, solve, and submit the payload.

The step-by-step implementation of the Altcha flow. Each step describes what to do and why, with the actual requests against Apex. The full request and response reference lives in the **API reference**.

## Step 1: Get the challenge

The ALTCHA widget fetches a challenge from its `challengeurl`, or the site embeds it inline. Two common shapes:

**v1 (flat):**

```json
{
  "algorithm": "SHA-256",
  "challenge": "2dc7a99e00a4417a8f69a670df710dc6fbf1ae202d9ffcd9de6e50d2e79e2460",
  "salt": "BBuC8FJsQS4h",
  "signature": "f3d95b9393d3fcf9ea023b731718d24649c0a96ec2139f3d9cc27d5381e65b6f"
}
```

**v2 (parameters):**

```json
{
  "parameters": {
    "algorithm": "PBKDF2/SHA-256",
    "cost": 100,
    "keyLength": 32,
    "keyPrefix": "00",
    "nonce": "405d18fdb58f829a12a83d65c2e1c390",
    "salt": "1b7f6a1c3d2e4f5a6b7c8d9e0f1a2b3c"
  },
  "signature": "9a4b..."
}
```

On WordPress sites the challenge usually comes from an `admin-ajax.php` action, e.g. `POST https://{site}/wp-admin/admin-ajax.php` with `action=tt_get_altcha_challenge`.

## Step 2: Build the solve

Call Apex with the challenge inline, or with the challenge URL and action:

{% tabs %}
{% tab title="Go" %}

```go
package main

import (
	"bytes"
	"encoding/json"
	"net/http"
)

func main() {
	body, _ := json.Marshal(map[string]any{
		"params": map[string]any{
			"challenge": map[string]any{
				"algorithm": "SHA-256",
				"challenge": "2dc7a99e00a4417a8f69a670df710dc6fbf1ae202d9ffcd9de6e50d2e79e2460",
				"salt":      "BBuC8FJsQS4h",
			},
		},
		"proxy": "http://user:pass@host:port",
	})

	req, _ := http.NewRequest("POST", "https://altcha.apexsolutions.lol/payload", bytes.NewReader(body))
	req.Header.Set("Authorization", "Bearer your-api-key")
	req.Header.Set("Content-Type", "application/json")

	resp, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer resp.Body.Close()
}
```

{% endtab %}

{% tab title="Python" %}

```python
import requests

challenge = {
    "algorithm": "SHA-256",
    "challenge": "2dc7a99e00a4417a8f69a670df710dc6fbf1ae202d9ffcd9de6e50d2e79e2460",
    "salt": "BBuC8FJsQS4h",
}

resp = requests.post(
    "https://altcha.apexsolutions.lol/payload",
    headers={"Authorization": "Bearer your-api-key"},
    json={"params": {"challenge": challenge}, "proxy": "http://user:pass@host:port"},
)

print(resp.status_code, resp.json())
```

{% endtab %}

{% tab title="JS/TS" %}

```jsts
const resp = await fetch("https://altcha.apexsolutions.lol/payload", {
  method: "POST",
  headers: {
    "Authorization": "Bearer your-api-key",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    params: {
      challenge_url: "https://{site}/wp-admin/admin-ajax.php",
      action: "tt_get_altcha_challenge",
    },
    proxy: "http://user:pass@host:port",
  }),
});

const data = await resp.json();
console.log(data);
```

{% endtab %}
{% endtabs %}

The response gives you the `altcha` payload under `result`.

## Step 3: Submit the payload

Put the `altcha` value into the form's hidden field and submit normally - the site's backend verifies it server-side:

```python
import requests

form = {"domain": "example.com", "altcha": payload}
resp = requests.post("https://{target}/form", data=form)
print(resp.status_code, resp.text)
```

## Important Notes

{% hint style="info" %}
**The payload is single-use and short-lived.** If a solve is rejected, the challenge likely expired - fetch a fresh challenge and solve again. For **v2 challenges**, the API reference documents the same endpoint; the proof-of-work uses key derivation (PBKDF2/SCRYPT/ARGON2ID). The **Code Captcha** escalation (`codeChallenge` in the challenge) is not yet solved.
{% endhint %}
