Was this helpful?
How to bypass Prosopo in the Edge mobile app
Technical engineer
The Edge mobile app uses the Prosopo ProCaptcha protection system to prevent automated logins. The main challenge when working with native mobile apps is the lack of a developer console, unlike in a regular web browser.
For a successful solution, you need to intercept the app's network traffic to extract the dynamic websiteURL and websiteKey parameters, solve the captcha via API v2, and then modify the app's outgoing request by injecting the obtained token.
Task Parameters
The ProsopoTaskProxyless task type is used for solving in the API v2 format.
| Parameter | Type | Required | Description |
|---|---|---|---|
| type | String | Yes | Must be set to ProsopoTaskProxyless |
| websiteURL | String | Yes | Full URL of the endpoint where the captcha is loaded (e.g., https://login.edge.app/captcha/...) |
| websiteKey | String | Yes | Unique identifier of the captcha instance, extracted from the traffic |
How to find parameters in the Edge mobile app
Since this is a mobile app, parameters must be intercepted from network traffic using traffic analysis tools (MITM proxies) such as Charles Proxy, mitmproxy, or HTTP Toolkit.
Instructions:
- Install and configure a proxy tool (e.g., Charles Proxy) on your computer.
- Configure your mobile device to use your computer's IP address and port as an HTTP proxy.
- Install the proxy tool's root certificate on your mobile device to enable HTTPS traffic decryption.
- Open the Edge app and navigate to the login screen to trigger the captcha load.
- In the proxy logs, look for requests to the login.edge.app domain or directly to Prosopo servers.
- Examine the Payload or URL parameters of this request. There you will find the websiteKey and full websiteURL values.
- Copy these values to use in the API request.
Note: If the Edge app uses SSL Pinning protection, you will need to bypass it (e.g., using the Frida framework or by patching the app), otherwise the proxy will not be able to decrypt the traffic and you won't see the parameters.
Code Examples
Python + requests (API v2)
A classic example of sending a task and getting the result via API v2 using JSON.
python
import requests
import time
API_KEY = 'YOUR_API_KEY'
WEBSITE_URL = 'https://login.edge.app/captcha/ITJHWHZGDZ4OGOIZ'
WEBSITE_KEY = '5E1bGh2NgRb8dD4NC5bQKRbgiCz8oBc2EhAuYJzy99q3iJ3s'
# 1. Sending the task
url = 'https://api.2captcha.com/createTask'
headers = {
'Content-Type': 'application/json'
}
payload = {
"clientKey": API_KEY,
"task": {
"type": "ProsopoTaskProxyless",
"websiteKey": WEBSITE_KEY,
"websiteURL": WEBSITE_URL
}
}
response = requests.post(url, headers=headers, json=payload)
result = response.json()
if result.get('errorId') == 0:
task_id = result.get('taskId')
print(f"Task created, ID: {task_id}")
# 2. Waiting for the solution
res_url = 'https://api.2captcha.com/getTaskResult'
while True:
time.sleep(5) # Pause between requests
res_payload = {
"clientKey": API_KEY,
"taskId": task_id
}
res_response = requests.post(res_url, headers=headers, json=res_payload).json()
if res_response.get('errorId') == 0 and res_response.get('status') == 'ready':
print("Captcha solved successfully!")
token = res_response['solution']['token']
print(f"Token: {token}")
break
elif res_response.get('errorId') != 0:
print(f"Error getting result: {res_response.get('errorDescription')}")
break
else:
print(f"Task creation error: {result.get('errorDescription')}")
Python + Playwright (Mobile WebView Emulation)
If the captcha in the Edge app is displayed inside a system WebView, you can use Playwright with mobile device emulation to intercept parameters and inject the token.
python
from playwright.sync_api import sync_playwright
import requests
import time
API_KEY = 'YOUR_API_KEY'
TARGET_URL = 'https://login.edge.app/captcha/ITJHWHZGDZ4OGOIZ'
def solve_prosopo_edge_webview():
with sync_playwright() as p:
# Mobile device emulation
iphone = p.devices['iPhone 12']
browser = p.chromium.launch(headless=False)
context = browser.new_context(**iphone)
page = context.new_page()
captured_params = {}
# Intercept requests to find parameters
def handle_request(request):
if 'prosopo' in request.url.lower() or 'captcha' in request.url.lower():
# Logic to extract websiteKey and websiteURL from the request
pass
page.on('request', handle_request)
try:
page.goto(TARGET_URL)
# Actions to trigger the captcha
# page.click('button[type="submit"]')
page.wait_for_timeout(3000)
# Send to API v2 (parameters must be extracted above)
api_url = 'https://api.2captcha.com/createTask'
headers = {'Content-Type': 'application/json'}
payload = {
"clientKey": API_KEY,
"task": {
"type": "ProsopoTaskProxyless",
"websiteKey": "EXTRACTED_KEY",
"websiteURL": page.url
}
}
task_response = requests.post(api_url, headers=headers, json=payload).json()
task_id = task_response.get('taskId')
# Waiting for the solution
res_url = 'https://api.2captcha.com/getTaskResult'
token = None
for _ in range(20):
time.sleep(5)
res = requests.post(res_url, headers=headers, json={"clientKey": API_KEY, "taskId": task_id}).json()
if res.get('status') == 'ready':
token = res['solution']['token']
break
if res.get('errorId') != 0:
print(f"API error: {res.get('errorDescription')}")
break
if token:
print(f"Token received: {token}")
# Injecting the token into the WebView
page.evaluate(f"""
// Example injection, exact selectors depend on the Edge app implementation
const input = document.querySelector('input[name="prosopo_token"]');
if (input) input.value = "{token}";
""")
else:
print("Failed to get token.")
except Exception as e:
print(f"Error: {e}")
finally:
# browser.close()
if __name__ == '__main__':
solve_prosopo_edge_webview()
How to use the received token in the Edge mobile app
Since injecting a token into a native mobile app differs from a web browser, standard DOM manipulation methods will not work directly. There are three main approaches:
- Intercepting and modifying the request (MITM): Using the same proxy (Charles/mitmproxy), set up a rule (Rewrite or Breakpoint) to intercept the outgoing request from the Edge app that sends the captcha response. Replace the empty or generated token field value with the one you received from the API, and forward the request to the server. This is the most reliable method for native apps.
- Dynamic analysis tools (Frida / Xposed): If you are automating the Android version of the Edge app, you can use the Frida framework to hook the native function that processes the captcha response, and forcibly return your solved token to it before it is sent to the server.
- WebView automation via Appium: If the captcha is displayed inside the Edge app's system WebView, use mobile automation tools like Appium to execute JavaScript code to inject the token into the DOM tree of that WebView, similar to how it is done in Playwright.
Common Errors and Solutions
| Error / Problem | Cause | Solution |
|---|---|---|
| Task creation error or ZERO_CAPTCHA | Incorrect or outdated websiteURL and websiteKey. | Ensure you intercepted the freshest parameters immediately before sending the task. They may be tied to a specific app session. |
| App does not send request or gives network error | SSL Pinning protection is enabled in the Edge app. | Use Frida, Objection, or patch the APK/IPA file to disable certificate verification so your proxy can decrypt the traffic. |
| Token is not accepted by the app server | Token injected into the wrong field or request modified incorrectly. | Carefully examine the structure of the app's outgoing request in the proxy. Ensure you are replacing the exact field the server expects, while keeping all other headers and request parameters unchanged. |
| Captcha does not appear | The app does not trigger the load. | Try using incognito mode in the emulator, clear the Edge app cache, or change your IP address to force the verification to appear. |
Useful Links
- API testing sandbox: https://2captcha.com/setting#sandbox
- Prosopo ProCaptcha API documentation: https://2captcha.com/api-docs/prosopo-procaptcha
- Python SDK on GitHub: https://github.com/2captcha/2captcha-python
- Other examples of bypassing captchas on websites: https://2captcha.com/h?category=sites