Was this helpful?
How to bypass reCAPTCHA v3 Enterprise on Lidl
Technical engineer
The Lidl login page (accounts.lidl.com) is protected by an invisible reCAPTCHA v3 in an Enterprise configuration. The main feature of working with this captcha is that it does not require user interaction, but strictly evaluates the humanity of the actions.
For a successful solution, it is critically important to pass the correct flags isEnterprise and apiDomain, and most importantly, to select the correct minScore parameter. If the website rejects the received token, the first thing to do is to change the minScore value in the API request. It is also important to remember that proxies are not supported for reCAPTCHA v3 tasks in our service; you must exclusively use the RecaptchaV3TaskProxyless task type.
Task Parameters
The RecaptchaV3TaskProxyless task type is used for solving.
| Parameter | Type | Required | Description |
|---|---|---|---|
| type | String | Yes | Must be set to RecaptchaV3TaskProxyless |
| websiteURL | String | Yes | Full URL of the page where the captcha is located (including all query parameters) |
| websiteKey | String | Yes | Static site key (starts with 6L...) |
| minScore | Float | Yes | Minimum required score (e.g., 0.3, 0.7, 0.9). If the token is not accepted by the site, change this value. |
| isEnterprise | Boolean | Yes | Must be set to true for the Enterprise version of reCAPTCHA |
| apiDomain | String | Yes | API domain. For Lidl, www.recaptcha.net is usually used |
How to find parameters
- Open the Lidl login page: https://www.lidl.com/ and proceed to the login form.
- Press F12 to open Developer Tools (DevTools) and go to the Network tab.
- Enable Preserve log.
- Enter test data and click the login button to trigger the verification.
- In the Network tab filter, type recaptcha or enterprise.
- Find the request to Google servers. In the parameters of this request (or in the page source code by searching for data-sitekey), you will find the websiteKey value (e.g., 6LdL-lsaAAAAABo0b2M_cFQbrX0Btbo85uZdRXWS).
- Important: Copy the full URL from the browser address bar at the moment the request is sent. It contains important session parameters (e.g., state, transaction_id).
- Check the page source code or the request payload to ensure that isEnterprise: true and apiDomain: www.recaptcha.net are used.
Code Examples
Python + requests
Example of sending a task and polling for the result using the requests library.
python
import requests
import time
API_KEY = 'YOUR_API_KEY'
WEBSITE_URL = 'https://accounts.lidl.com/Account/Login?ReturnUrl=%2Fconnect%2Fauthorize%2Fcallback%3Fcountry_code%3DUS%26response_type%3Dcode%26client_id%3DUsaRetailClient%26scope%3Dopenid%2520profile%2520Lidl.Authentication%2520offline_access%26state%3DIFq8BVFUX0qvLy_8qwJRfZx4y8hhyvm0ZdRLIQx1l4g%253D%26redirect_uri%3Dhttps%253A%252F%252Fwww.lidl.com%252Fuser-api%252Fsignin-oidc%26nonce%3DhIXSo9hQoVeh2jESuulV_0vdzkKPa0Tj2bAUW6QSePk%26code_challenge%3DUk_ogCwFo0qP_9b7pppeOnD6wKXCYs3hzXuPPuW-ZKc%26code_challenge_method%3DS256%26step%3Dlogin%26language%3Den-US%26transaction_id%3Dc9f3c914-e3a4-4ee9-916e-bae36d4c6ad8#login'
WEBSITE_KEY = '6LdL-lsaAAAAABo0b2M_cFQbrX0Btbo85uZdRXWS'
# 1. Sending the task
url = 'https://api.2captcha.com/createTask'
headers = {
'Content-Type': 'application/json'
}
payload = {
"clientKey": API_KEY,
"task": {
"type": "RecaptchaV3TaskProxyless",
"websiteURL": WEBSITE_URL,
"websiteKey": WEBSITE_KEY,
"minScore": 0.3,
"apiDomain": "www.recaptcha.net",
"isEnterprise": True
}
}
response = requests.post(url, headers=headers, json=payload)
result = response.json()
if result.get('errorId') == 0:
task_id = result.get('taskId')
print(f"Task created, ID: {task_id}")
# 2. Waiting for the solution
res_url = 'https://api.2captcha.com/getTaskResult'
while True:
time.sleep(5)
res_payload = {
"clientKey": API_KEY,
"taskId": task_id
}
res_response = requests.post(res_url, headers=headers, json=res_payload).json()
if res_response.get('errorId') == 0 and res_response.get('status') == 'ready':
print("Captcha solved successfully!")
token = res_response['solution']['gRecaptchaResponse']
print(f"Token: {token}")
break
elif res_response.get('errorId') != 0:
print(f"Error getting result: {res_response.get('errorDescription')}")
break
else:
print(f"Task creation error: {result.get('errorDescription')}")
Python + Playwright
Example of automation that dynamically extracts the current URL and key, sends the task, and receives the token.
python
from playwright.sync_api import sync_playwright
import requests
import time
API_KEY = 'YOUR_API_KEY'
TARGET_URL = 'https://www.lidl.com/'
def solve_lidl_recaptcha_v3():
with sync_playwright() as p:
browser = p.chromium.launch(headless=False)
page = browser.new_page()
try:
page.goto(TARGET_URL)
page.wait_for_url('**/accounts.lidl.com/**', timeout=15000)
current_url = page.url
website_key = page.evaluate("document.querySelector('[data-sitekey]')?.getAttribute('data-sitekey')")
if not website_key:
website_key = page.evaluate("""
() => {
const scripts = document.querySelectorAll('script');
for (const script of scripts) {
const match = script.textContent.match(/sitekey['":\s]+['"]?(6L[a-zA-Z0-9_-]{39})['"]?/);
if (match) return match[1];
}
return null;
}
""")
print(f"URL: {current_url}")
print(f"Key: {website_key}")
api_url = 'https://api.2captcha.com/createTask'
headers = {'Content-Type': 'application/json'}
payload = {
"clientKey": API_KEY,
"task": {
"type": "RecaptchaV3TaskProxyless",
"websiteURL": current_url,
"websiteKey": website_key,
"minScore": 0.3,
"apiDomain": "www.recaptcha.net",
"isEnterprise": True
}
}
task_response = requests.post(api_url, headers=headers, json=payload).json()
task_id = task_response.get('taskId')
res_url = 'https://api.2captcha.com/getTaskResult'
token = None
for _ in range(20):
time.sleep(5)
res = requests.post(res_url, headers=headers, json={"clientKey": API_KEY, "taskId": task_id}).json()
if res.get('status') == 'ready':
token = res['solution']['gRecaptchaResponse']
break
if res.get('errorId') != 0:
print(f"API error: {res.get('errorDescription')}")
break
if token:
print(f"Token received: {token[:30]}...")
else:
print("Failed to get token.")
except Exception as e:
print(f"Error: {e}")
if __name__ == '__main__':
solve_lidl_recaptcha_v3()
How to use the received token (Injection without callback)
Unlike reCAPTCHA v2, version v3 does not use callback functions to pass the result. The token must be passed to the server explicitly. On the Lidl website, this is usually implemented in the following way:
Hidden form field: The site automatically reads the value from a hidden input named g-recaptcha-response when the form is submitted.
python
page.evaluate(f"""
let input = document.querySelector('input[name="g-recaptcha-response"]');
if (!input) {{
input = document.createElement('input');
input.type = 'hidden';
input.name = 'g-recaptcha-response';
const form = document.querySelector('form') || document.body;
form.appendChild(input);
}}
input.value = "{token}";
""")
If the form is submitted via JavaScript (Fetch/XHR), the token may not be read from the DOM, but formed in the data object. In this case, you need to intercept the form submission request and add the gRecaptchaResponse field to the request body before sending it to the server.
Testing in Sandbox Mode
Before running automation, verify the correctness of the extracted parameters in the 2captcha Sandbox.
- Send a task via the API using your websiteURL, websiteKey, minScore, apiDomain, and isEnterprise.
- Go to the Sandbox https://2captcha.com/setting#sandbox and switch to Worker mode.
- If you receive this task and see a correctly loading reCAPTCHA v3 Enterprise widget, the parameters are collected correctly. If the widget shows an error, check the exact match of websiteURL and apiDomain.
Common Errors and Solutions
| Error / Problem | Cause | Solution |
|---|---|---|
| Site rejects the token | The minScore value does not match the site requirements. | Change the minScore parameter in the API request. Try values 0.1, 0.3, 0.5, 0.7, or 0.9. |
| Proxy-related error | Using proxies for reCAPTCHA v3. | Proxies are not supported for reCAPTCHA v3. Always use the RecaptchaV3TaskProxyless task type. |
| ERROR_INVALID_SITE_KEY | Invalid websiteKey or domain mismatch in websiteURL. | Make sure the key starts with 6L and websiteURL exactly matches the address in the browser, including all parameters. |
| Token not accepted by the form | Incorrect token injection method. | Make sure you are not trying to use a callback. Inject the token into the hidden g-recaptcha-response field or add it to the request payload. |
Useful Links
- API testing sandbox: https://2captcha.com/setting#sandbox
- reCAPTCHA v3 API documentation: https://2captcha.com/api-docs/recaptcha-v3
- Python SDK on GitHub: https://github.com/2captcha/2captcha-python
- Other examples of bypassing captchas on websites: https://2captcha.com/h?category=sites