Logo of «2Captcha»To home page
Captcha bypass tutorials

Was this helpful?

How to bypass reCAPTCHA v3 Enterprise on Lidl

Gregory Fisher
Gregory Fisher

Technical engineer

The Lidl login page (accounts.lidl.com) is protected by an invisible reCAPTCHA v3 in an Enterprise configuration. The main feature of working with this captcha is that it does not require user interaction, but strictly evaluates the humanity of the actions.

For a successful solution, it is critically important to pass the correct flags isEnterprise and apiDomain, and most importantly, to select the correct minScore parameter. If the website rejects the received token, the first thing to do is to change the minScore value in the API request. It is also important to remember that proxies are not supported for reCAPTCHA v3 tasks in our service; you must exclusively use the RecaptchaV3TaskProxyless task type.

Task Parameters

The RecaptchaV3TaskProxyless task type is used for solving.

Parameter Type Required Description
type String Yes Must be set to RecaptchaV3TaskProxyless
websiteURL String Yes Full URL of the page where the captcha is located (including all query parameters)
websiteKey String Yes Static site key (starts with 6L...)
minScore Float Yes Minimum required score (e.g., 0.3, 0.7, 0.9). If the token is not accepted by the site, change this value.
isEnterprise Boolean Yes Must be set to true for the Enterprise version of reCAPTCHA
apiDomain String Yes API domain. For Lidl, www.recaptcha.net is usually used

How to find parameters

  1. Open the Lidl login page: https://www.lidl.com/ and proceed to the login form.
  2. Press F12 to open Developer Tools (DevTools) and go to the Network tab.
  3. Enable Preserve log.
  4. Enter test data and click the login button to trigger the verification.
  5. In the Network tab filter, type recaptcha or enterprise.
  6. Find the request to Google servers. In the parameters of this request (or in the page source code by searching for data-sitekey), you will find the websiteKey value (e.g., 6LdL-lsaAAAAABo0b2M_cFQbrX0Btbo85uZdRXWS).
  7. Important: Copy the full URL from the browser address bar at the moment the request is sent. It contains important session parameters (e.g., state, transaction_id).
  8. Check the page source code or the request payload to ensure that isEnterprise: true and apiDomain: www.recaptcha.net are used.

Code Examples

Python + requests

Example of sending a task and polling for the result using the requests library.

python Copy
import requests
import time

API_KEY = 'YOUR_API_KEY'
WEBSITE_URL = 'https://accounts.lidl.com/Account/Login?ReturnUrl=%2Fconnect%2Fauthorize%2Fcallback%3Fcountry_code%3DUS%26response_type%3Dcode%26client_id%3DUsaRetailClient%26scope%3Dopenid%2520profile%2520Lidl.Authentication%2520offline_access%26state%3DIFq8BVFUX0qvLy_8qwJRfZx4y8hhyvm0ZdRLIQx1l4g%253D%26redirect_uri%3Dhttps%253A%252F%252Fwww.lidl.com%252Fuser-api%252Fsignin-oidc%26nonce%3DhIXSo9hQoVeh2jESuulV_0vdzkKPa0Tj2bAUW6QSePk%26code_challenge%3DUk_ogCwFo0qP_9b7pppeOnD6wKXCYs3hzXuPPuW-ZKc%26code_challenge_method%3DS256%26step%3Dlogin%26language%3Den-US%26transaction_id%3Dc9f3c914-e3a4-4ee9-916e-bae36d4c6ad8#login'
WEBSITE_KEY = '6LdL-lsaAAAAABo0b2M_cFQbrX0Btbo85uZdRXWS'

# 1. Sending the task
url = 'https://api.2captcha.com/createTask'
headers = {
    'Content-Type': 'application/json'
}
payload = {
    "clientKey": API_KEY,
    "task": {
        "type": "RecaptchaV3TaskProxyless",
        "websiteURL": WEBSITE_URL,
        "websiteKey": WEBSITE_KEY,
        "minScore": 0.3,
        "apiDomain": "www.recaptcha.net",
        "isEnterprise": True
    }
}

response = requests.post(url, headers=headers, json=payload)
result = response.json()

if result.get('errorId') == 0:
    task_id = result.get('taskId')
    print(f"Task created, ID: {task_id}")
    
    # 2. Waiting for the solution
    res_url = 'https://api.2captcha.com/getTaskResult'
    while True:
        time.sleep(5)
        
        res_payload = {
            "clientKey": API_KEY,
            "taskId": task_id
        }
        
        res_response = requests.post(res_url, headers=headers, json=res_payload).json()
        
        if res_response.get('errorId') == 0 and res_response.get('status') == 'ready':
            print("Captcha solved successfully!")
            token = res_response['solution']['gRecaptchaResponse']
            print(f"Token: {token}")
            break
        elif res_response.get('errorId') != 0:
            print(f"Error getting result: {res_response.get('errorDescription')}")
            break
else:
    print(f"Task creation error: {result.get('errorDescription')}")

Python + Playwright

Example of automation that dynamically extracts the current URL and key, sends the task, and receives the token.

python Copy
from playwright.sync_api import sync_playwright
import requests
import time

API_KEY = 'YOUR_API_KEY'
TARGET_URL = 'https://www.lidl.com/'

def solve_lidl_recaptcha_v3():
    with sync_playwright() as p:
        browser = p.chromium.launch(headless=False)
        page = browser.new_page()
        
        try:
            page.goto(TARGET_URL)
            page.wait_for_url('**/accounts.lidl.com/**', timeout=15000)
            
            current_url = page.url
            website_key = page.evaluate("document.querySelector('[data-sitekey]')?.getAttribute('data-sitekey')")
            
            if not website_key:
                website_key = page.evaluate("""
                    () => {
                        const scripts = document.querySelectorAll('script');
                        for (const script of scripts) {
                            const match = script.textContent.match(/sitekey['":\s]+['"]?(6L[a-zA-Z0-9_-]{39})['"]?/);
                            if (match) return match[1];
                        }
                        return null;
                    }
                """)

            print(f"URL: {current_url}")
            print(f"Key: {website_key}")
            
            api_url = 'https://api.2captcha.com/createTask'
            headers = {'Content-Type': 'application/json'}
            payload = {
                "clientKey": API_KEY,
                "task": {
                    "type": "RecaptchaV3TaskProxyless",
                    "websiteURL": current_url,
                    "websiteKey": website_key,
                    "minScore": 0.3,
                    "apiDomain": "www.recaptcha.net",
                    "isEnterprise": True
                }
            }
            
            task_response = requests.post(api_url, headers=headers, json=payload).json()
            task_id = task_response.get('taskId')
            
            res_url = 'https://api.2captcha.com/getTaskResult'
            token = None
            for _ in range(20):
                time.sleep(5)
                res = requests.post(res_url, headers=headers, json={"clientKey": API_KEY, "taskId": task_id}).json()
                if res.get('status') == 'ready':
                    token = res['solution']['gRecaptchaResponse']
                    break
                if res.get('errorId') != 0:
                    print(f"API error: {res.get('errorDescription')}")
                    break
                    
            if token:
                print(f"Token received: {token[:30]}...")
            else:
                print("Failed to get token.")
                
        except Exception as e:
            print(f"Error: {e}")

if __name__ == '__main__':
    solve_lidl_recaptcha_v3()

How to use the received token (Injection without callback)

Unlike reCAPTCHA v2, version v3 does not use callback functions to pass the result. The token must be passed to the server explicitly. On the Lidl website, this is usually implemented in the following way:

Hidden form field: The site automatically reads the value from a hidden input named g-recaptcha-response when the form is submitted.

python Copy
page.evaluate(f"""
    let input = document.querySelector('input[name="g-recaptcha-response"]');
    if (!input) {{
        input = document.createElement('input');
        input.type = 'hidden';
        input.name = 'g-recaptcha-response';
        const form = document.querySelector('form') || document.body;
        form.appendChild(input);
    }}
    input.value = "{token}";
""")

If the form is submitted via JavaScript (Fetch/XHR), the token may not be read from the DOM, but formed in the data object. In this case, you need to intercept the form submission request and add the gRecaptchaResponse field to the request body before sending it to the server.

Testing in Sandbox Mode

Before running automation, verify the correctness of the extracted parameters in the 2captcha Sandbox.

  1. Send a task via the API using your websiteURL, websiteKey, minScore, apiDomain, and isEnterprise.
  2. Go to the Sandbox https://2captcha.com/setting#sandbox and switch to Worker mode.
  3. If you receive this task and see a correctly loading reCAPTCHA v3 Enterprise widget, the parameters are collected correctly. If the widget shows an error, check the exact match of websiteURL and apiDomain.

Common Errors and Solutions

Error / Problem Cause Solution
Site rejects the token The minScore value does not match the site requirements. Change the minScore parameter in the API request. Try values 0.1, 0.3, 0.5, 0.7, or 0.9.
Proxy-related error Using proxies for reCAPTCHA v3. Proxies are not supported for reCAPTCHA v3. Always use the RecaptchaV3TaskProxyless task type.
ERROR_INVALID_SITE_KEY Invalid websiteKey or domain mismatch in websiteURL. Make sure the key starts with 6L and websiteURL exactly matches the address in the browser, including all parameters.
Token not accepted by the form Incorrect token injection method. Make sure you are not trying to use a callback. Inject the token into the hidden g-recaptcha-response field or add it to the request payload.