> For the complete documentation index, see [llms.txt](https://docs.apexsolutions.lol/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.apexsolutions.lol/friendlycaptcha/getting-started.md).

# Getting Started

How FriendlyCaptcha works, how to tell a site uses it, and what the solve returns.

If you already know how FriendlyCaptcha works, skip to the **API reference**. This page explains what it is, how to tell a site uses it, and how the whole flow fits together - you do not need to reverse-engineer anything.

## Understanding FriendlyCaptcha

FriendlyCaptcha v2 is a proof-of-work challenge service that protects signups, logins, and sensitive actions. The widget runs a **BLAKE3 proof-of-work** in the browser and collects **behavioral signals** (device fingerprint, movement, timing). When the proof is accepted, FriendlyCaptcha issues a **frc\_token**.

That token is not a cookie you replay - you send it to the site's backend, and the backend validates it with FriendlyCaptcha's **siteverify** API before allowing the action.

## Identifying FriendlyCaptcha

Before solving, confirm the site actually uses FriendlyCaptcha:

1. **The site key.** FriendlyCaptcha widgets embed a public key starting with `FCMU` (for example `FCMU08117KKFLBRL`). It is what the solve API needs.
2. **The widget.** The page renders a "I am human" button inside a `frc-captcha` container.
3. **The API host.** Challenge traffic goes to `global.frcapi.com` (agent and widget iframes under `/api/v2/captcha`).

You only need the **site key** to solve.

## How a session is built

There is no long-lived session. Apex fetches the solve context, activates a session, obtains a quote (the proof-of-work difficulty), solves the BLAKE3 proof-of-work, and redeems it with the behavioral signals. When FriendlyCaptcha accepts it, the response contains a **frc\_token**. You submit that token to the site's backend for validation.

## Solution Flow

1. **Identify the site key** (`FCMU...`) from the protected page.
2. **Solve through Apex.** Send the site key and your proxy (required). Apex returns the `token`. See the API reference for the exact request.
3. **Validate the token on the backend.** Your client sends the `token` to the site's own API, which verifies it with FriendlyCaptcha (siteverify). The token is single-use and short-lived.

## Important Notes

{% hint style="info" %}
**The token is for the site's backend, not your requests.** It is not a cookie or header - submit it to the site's API that protects the action, and let the site verify it. A **proxy is required** - the solver always runs through yours, never from Apex's servers.
{% endhint %}
