Was this helpful?
How to bypass captcha in UIPath
Tech builder focused on infrastructure, automation, backend systems, and scalable SaaS development
UIPath is a powerful RPA platform for automating workflows in enterprise and desktop environments. But when your automation hits a captcha, your bot is stuck.
This article shows how to use captcha solver API to automatically solve captchas in UIPath.
Standard UiPath activities like Click or Type Into hit a brick wall when facing modern uipath captcha challenges. While the UiPath Marketplace is full of "Captcha Solver" packages, experienced developers know the reality: most are abandonware, have unresolved dependency conflicts, or simply fail against modern challenges like Cloudflare Turnstile.
For enterprise-grade captcha automation in UiPath, the only reliable architectural pattern is handling the solving logic via direct HTTP requests to an external API. This guide covers how to implement a robust Ui captcha solver without relying on flaky browser extensions or third-party libraries.
Phase 0: Prevention (Best Practices)
Before engineering a bypass, verify if the challenge can be avoided entirely. In the UiPath community, two strategies often eliminate the need for a solver:
- Whitelisting: If the target application is internal or belongs to a partner, request that InfoSec whitelists your bot's IP address.
- Session Persistence: Anti-bot systems (like Cloudflare or Akamai) often flag "clean" sessions. Configure your robot to use a browser profile with persistent cookies. If the bot appears as a returning user, the CAPTCHA often won't trigger at all.
If these methods fail (e.g., during public web scraping), proceed to the API implementation.
Phase 1: The API Architecture
To implement captcha automation using uipath, we will use the UiPath.WebAPI.Activities package. The logic follows a strict three-step asynchronous pattern:
- POST the site parameters to the solver service.
- Poll the service until the solution is ready.
- Inject the resulting token into the DOM using JavaScript.
You will need an API key from a provider that supports standard protocols. Reliable options include:
Step 1: Create the Task
Your robot must first scrape the data-sitekey (from the HTML) and the current Page URL. Use the HTTP Request activity:
- Endpoint:
https://api.2captcha.com/createTask(or your provider's equivalent) - Method:
POST - Payload (JSON):
json
{ "clientKey": "YOUR_API_KEY", "task": { "type": "recaptcha2", "websiteKey": "6Lc_aXkUAAAAA...", "websiteURL": "https://example.com" } }
Critical Note on Task Types (type):
- reCAPTCHA v2:
recaptcha2 - Cloudflare Turnstile:
turnstile - GeeTest v4:
geetest_v4
Parse the response using Deserialize JSON and extract the taskId.
Step 2: The Polling Loop
Services take 10–30 seconds to solve a puzzle. If you request the result immediately, the API will return a "Processing" status. You must implement a Do While loop in UiPath:
- Delay: Wait 5–7 seconds (essential to avoid rate-limiting).
- HTTP Request: POST to
getTaskResult.json{ "clientKey": "YOUR_API_KEY", "taskId": "TASK_ID_FROM_STEP_1" } - Exit Condition: Loop while
jsonResponse("status").ToStringequals"processing".
Once the status switches to "ready", extract the token from solution.gRecaptchaResponse (or token for Turnstile).
Step 3: JS Injection
This is the failure point for most uipath captcha automation attempts. UiPath cannot "type" into a hidden field (type="hidden"). You must use the Inject JS Script activity targeting the browser scope.
The Script:
javascript
function(element, token) {
// 1. Locate the hidden response field
// For Google: 'g-recaptcha-response'
// For Cloudflare: 'cf-turnstile-response'
var el = document.getElementById('g-recaptcha-response');
if (el) {
el.value = token;
// Debugging: make it visible if needed
// el.style.display = 'block';
}
// 2. CRITICAL: Trigger the Callback
// Modern apps (React/Angular) won't detect the value change.
// Check the page source for 'data-callback' and trigger it manually:
// window.onSuccessCallback(token);
}
Input Parameter: Pass your token variable here.
After injection, perform a standard Click on the Login/Submit button.
Troubleshooting Common Failures
If your captcha uipath workflow breaks, check these three common culprits:
| Symptom | Probable Cause | Fix |
|---|---|---|
| Status: Failed (Immediate) | Mismatched Parameters | The websiteKey and websiteURL must match the target site byte-for-byte. Do not use a generic URL. |
| Infinite "Processing" | Wrong Task Type | You are sending recaptcha2 but the site uses Enterprise v3. Inspect the network traffic in Chrome DevTools to confirm the vendor. |
| Token Injected, Login Fails | Missing Event Trigger | The site doesn't know the field changed. Update your JS script to dispatch an input event: el.dispatchEvent(new Event('input')). |
Summary
Relying on "No-Code" marketplace activities for uipath captcha handling is a technical debt risk. By implementing the HTTP request pattern directly, you ensure your unattended robots remain resilient to platform updates and can handle any captcha type—from reCAPTCHA to Turnstile—without manual intervention.