> For the complete documentation index, see [llms.txt](https://docs.apexsolutions.lol/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.apexsolutions.lol/captchafox/getting-started.md).

# Getting Started

How CaptchaFox works, how to tell a site uses it, and what the solve returns.

If you already know how CaptchaFox works, skip to the **API reference**. This page explains what it is, how to tell a site uses it, and how the whole flow fits together — you do not need to reverse-engineer anything.

## Understanding CaptchaFox

CaptchaFox is a challenge service that protects signups and sensitive actions. It serves a widget on the page that, when a visit looks suspicious, issues a **slide challenge**: you drag a puzzle piece across a track to align it with a gap in the background image. A proof-of-work is also required to slow down automation.

When the challenge passes, CaptchaFox issues a **response token**. That token is not a cookie you replay — you send it to the site's backend, and the backend validates it with CaptchaFox (siteverify) before allowing the action.

## Identifying CaptchaFox

Before solving, confirm the site actually uses CaptchaFox:

1. **The site key.** CaptchaFox widgets embed a public key starting with `sk_` (for example `sk_1a2b...`). It is what the solve API needs.
2. **The widget.** The page loads a CaptchaFox script and renders a `captchafox-frame` or a challenge button.
3. **The API host.** Challenge traffic goes to `*.captchafox.com` (for example `mam-api.captchafox.com` or `api.captchafox.com`).

You only need the **site key** and the **page URL** to solve.

## How a session is built

There is no long-lived session. Apex fetches the challenge configuration, replays a real-Chrome attestation (`cs`), solves the proof-of-work, detects the slider gap in the background image, and submits the answer. When CaptchaFox accepts it, the response contains a **token**. You submit that token to the site's backend for validation.

## Solution Flow

1. **Identify the site key** (`sk_...`) and the protected page URL.
2. **Solve through Apex.** Send the page URL, the site key, and your sticky proxy. Apex returns the `token`. See the API reference for the exact request.
3. **Validate the token on the backend.** Your client sends the `token` to the site's own API, which verifies it with CaptchaFox (siteverify). The token is single-use and short-lived.

## Important Notes

{% hint style="info" %}
**The token is for the site's backend, not your requests.** It is not a cookie or header — submit it to the site's API that protects the action, and let the site verify it. A **sticky proxy is required** on every solve, like all Apex providers — the solve always runs through your proxy.
{% endhint %}
