> For the complete documentation index, see [llms.txt](https://docs.apexsolutions.lol/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.apexsolutions.lol/api-reference/aws-waf.md).

# AWS WAF

Solve the AWS WAF browser Challenge or CAPTCHA and get the token as a cookie.

Solves the AWS WAF bot-control mechanisms for a page and returns the token to replay as a cookie on your requests to the protected site.

* **`POST /payload`** — the silent JS **Challenge** (HashcashScrypt, SHA256 or NetworkBandwidth) -> `aws-waf-token`.
* **`POST /captcha`** — the interactive **CAPTCHA** (image-recognition puzzle) -> `aws-waf-captcha-token`.

### Params-driven

The client extracts the AWS WAF artifacts from its **own traffic** (the 405/202 interstitial HTML) and sends them as params — the solver never re-discovers the target. See the guide pages for how to extract each value.

### What you get back

Both endpoints carry the `token` under `result`. Unlike a backend validation token, it is a cookie you attach to the requests you send to the protected page, so the site stops serving the challenge or captcha.

## Solve the AWS WAF Challenge

> Completes the AWS WAF Challenge proof-of-work (scrypt / sha256 /\
> bandwidth) against the \`challenge\_url\` you extracted from your traffic,\
> builds the browser fingerprint, and returns an \`aws-waf-token\`.<br>

```json
{"openapi":"3.0.3","info":{"title":"AWS WAF","version":"1.1.0"},"tags":[{"name":"AWS WAF","description":"Solves the AWS WAF bot-control mechanisms for a page and returns the token\nto replay as a cookie on your requests to the protected site.\n\n- **`POST /payload`** — the silent JS **Challenge** (HashcashScrypt, SHA256\n  or NetworkBandwidth) -> `aws-waf-token`.\n- **`POST /captcha`** — the interactive **CAPTCHA** (image-recognition\n  puzzle) -> `aws-waf-captcha-token`.\n\n## Params-driven\n\nThe client extracts the AWS WAF artifacts from its **own traffic** (the\n405/202 interstitial HTML) and sends them as params — the solver never\nre-discovers the target. See the guide pages for how to extract each value.\n\n## What you get back\n\nBoth endpoints carry the `token` under `result`. Unlike a backend\nvalidation token, it is a cookie you attach to the requests you send to\nthe protected page, so the site stops serving the challenge or captcha.\n"}],"servers":[{"url":"https://waf.apexsolutions.lol"}],"paths":{"/payload":{"post":{"tags":["AWS WAF"],"summary":"Solve the AWS WAF Challenge","description":"Completes the AWS WAF Challenge proof-of-work (scrypt / sha256 /\nbandwidth) against the `challenge_url` you extracted from your traffic,\nbuilds the browser fingerprint, and returns an `aws-waf-token`.\n","parameters":[{"name":"Content-Type","in":"header","required":true,"description":"The Content-Type of the request body.","schema":{"type":"string","enum":["application/json"]}},{"name":"Authorization","in":"header","required":true,"description":"Your API key for authentication.","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AwsWafSolveRequest"}}}},"responses":{"200":{"description":"Challenge solved. The `aws-waf-token` is under `result`.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/AwsWafSolveResponse"}}}},"400":{"description":"Missing or invalid request. See the error envelope for the reason.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Proxy connection failed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}}}}}},"components":{"schemas":{"AwsWafSolveRequest":{"type":"object","required":["params","proxy"],"properties":{"params":{"type":"object","required":["challenge_url","page_url","user_agent"],"properties":{"challenge_url":{"type":"string","description":"The base of the `challenge.js` script URL from your traffic (host + 3-segment path, WITHOUT `/challenge.js`), e.g. `https://{id}.{region}.token.awswaf.com/{id}/{hashA}/{hashB}`. NOT a fixed value per site: the region and path hashes rotate, so always parse it from a fresh 405/202 response.\n"},"page_url":{"type":"string","description":"The EXACT URL of the page where the SDK runs. It lands in the encrypted fingerprint (`fp.location`); a wrong URL raises the proof-of-work difficulty (e.g. `/` vs `/sign_in`: diff=1 -> diff=4).\n"},"user_agent":{"type":"string","description":"Your Google Chrome on Windows user agent. The fingerprint is built from it, so it must match the browser your client uses.\n"}}},"proxy":{"type":"string","description":"Required proxy (sticky session recommended)."}}},"AwsWafSolveResponse":{"type":"object","properties":{"solve_id":{"type":"string","description":"Identifier of the solve."},"status":{"type":"string","description":"Always `succeeded` on a 200."},"provider":{"type":"string","description":"Always `aws_waf`."},"result":{"type":"object","properties":{"token":{"type":"string","description":"The `aws-waf-token`. Replay it as the `aws-waf-token` cookie on your requests to the protected site.\n"}}}}},"Error":{"type":"object","properties":{"error":{"type":"object","properties":{"code":{"type":"string","description":"Machine-readable error code."},"message":{"type":"string","description":"Human-readable error message."}}}}}}}}
```

## Solve the AWS WAF CAPTCHA

> Solves the AWS WAF CAPTCHA (the interactive image-recognition puzzle)\
> using the interstitial params you extracted from the 405 response\
> (\`token\_host\`, \`captcha\_host\`, \`goku\_props\`) and returns an\
> \`aws-waf-captcha-token\`. If \`existing\_token\` is omitted, the solver\
> mints the \`aws-waf-token\` (Challenge) internally first and then solves\
> the CAPTCHA.<br>

```json
{"openapi":"3.0.3","info":{"title":"AWS WAF","version":"1.1.0"},"tags":[{"name":"AWS WAF","description":"Solves the AWS WAF bot-control mechanisms for a page and returns the token\nto replay as a cookie on your requests to the protected site.\n\n- **`POST /payload`** — the silent JS **Challenge** (HashcashScrypt, SHA256\n  or NetworkBandwidth) -> `aws-waf-token`.\n- **`POST /captcha`** — the interactive **CAPTCHA** (image-recognition\n  puzzle) -> `aws-waf-captcha-token`.\n\n## Params-driven\n\nThe client extracts the AWS WAF artifacts from its **own traffic** (the\n405/202 interstitial HTML) and sends them as params — the solver never\nre-discovers the target. See the guide pages for how to extract each value.\n\n## What you get back\n\nBoth endpoints carry the `token` under `result`. Unlike a backend\nvalidation token, it is a cookie you attach to the requests you send to\nthe protected page, so the site stops serving the challenge or captcha.\n"}],"servers":[{"url":"https://waf.apexsolutions.lol"}],"paths":{"/captcha":{"post":{"tags":["AWS WAF"],"summary":"Solve the AWS WAF CAPTCHA","description":"Solves the AWS WAF CAPTCHA (the interactive image-recognition puzzle)\nusing the interstitial params you extracted from the 405 response\n(`token_host`, `captcha_host`, `goku_props`) and returns an\n`aws-waf-captcha-token`. If `existing_token` is omitted, the solver\nmints the `aws-waf-token` (Challenge) internally first and then solves\nthe CAPTCHA.\n","parameters":[{"name":"Content-Type","in":"header","required":true,"description":"The Content-Type of the request body.","schema":{"type":"string","enum":["application/json"]}},{"name":"Authorization","in":"header","required":true,"description":"Your API key for authentication.","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AwsWafCaptchaRequest"}}}},"responses":{"200":{"description":"CAPTCHA solved. The `aws-waf-captcha-token` is under `result`.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/AwsWafCaptchaResponse"}}}},"400":{"description":"Missing or invalid request. See the error envelope for the reason.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Proxy connection failed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}}}}}},"components":{"schemas":{"AwsWafCaptchaRequest":{"type":"object","required":["params","proxy"],"properties":{"params":{"type":"object","required":["token_host","captcha_host","goku_props","page_url","user_agent"],"properties":{"token_host":{"type":"string","description":"The base of the `challenge.js` script URL from the 405 interstitial (host + 3-segment path, WITHOUT `/challenge.js`).\n"},"captcha_host":{"type":"string","description":"The base of the `captcha.js` script URL from the 405 interstitial (host + 3-segment path, WITHOUT `/captcha.js`). Same `{id}.{region}` prefix as `token_host`, `.captcha.awswaf.com`.\n"},"goku_props":{"type":"object","required":["key","iv","context"],"description":"The `window.gokuProps` object from the 405 interstitial HTML. Sent in the verify step; without it the server rejects the solve.\n","properties":{"key":{"type":"string"},"iv":{"type":"string"},"context":{"type":"string"}}},"page_url":{"type":"string","description":"The EXACT URL of the page/endpoint that returned the 405. Sent as the `domain` of the captcha `/problem`.\n"},"user_agent":{"type":"string","description":"Your Google Chrome on Windows user agent. Must match the browser your client uses for the session.\n"},"existing_token":{"type":"string","description":"Optional. An existing `aws-waf-token` for the same domain. When omitted, the solver mints one internally (Challenge) first.\n"}}},"proxy":{"type":"string","description":"Required proxy (sticky session recommended)."}}},"AwsWafCaptchaResponse":{"type":"object","properties":{"solve_id":{"type":"string","description":"Identifier of the solve."},"status":{"type":"string","description":"Always `succeeded` on a 200."},"provider":{"type":"string","description":"Always `aws_waf_captcha`."},"result":{"type":"object","properties":{"token":{"type":"string","description":"The `aws-waf-captcha-token`. Replay it as the `aws-waf-captcha-token` cookie on your requests to the protected site.\n"}}}}},"Error":{"type":"object","properties":{"error":{"type":"object","properties":{"code":{"type":"string","description":"Machine-readable error code."},"message":{"type":"string","description":"Human-readable error message."}}}}}}}}
```
