Logo of «2Captcha»To home page
Captcha bypass tutorials

Was this helpful?

How to bypass Yidun (NetEase) captcha on Weibo

Gregory Fisher
Gregory Fisher

Technical engineer

The Weibo login page (passport.weibo.com) is protected by Yidun captcha (also known as NetEase Captcha). The main feature of this captcha is that it only appears during login attempts, and its solving parameters (especially the URL) are dynamic and change with every new session.

For a successful solution, it is critically important to extract the actual parameters from the network request at the moment the captcha appears and ensure that the userAgent parameter in the API request exactly matches the userAgent of your browser.

Task Parameters

The YidunTaskProxyless task type is used for solving.

Parameter Type Required Description
type String Yes Must be set to YidunTaskProxyless
websiteURL String Yes Full URL of the page where the captcha is located (decoded value of the referer parameter)
websiteKey String Yes Captcha identifier (value of the id parameter from the request)
userAgent String Yes Browser User-Agent. Must exactly match the one used to load the page

How to find parameters

Since the parameters are dynamic, they must be intercepted in real time.

  1. Open the Weibo login page: https://passport.weibo.com/sso/signin
  2. Press F12 to open Developer Tools (DevTools) and go to the Network tab.
  3. Enable Preserve log.
  4. Enter any test data (login/password) and click the login button to trigger the captcha.
  5. In the Network tab filter, type dun.163.com.
  6. Find the GET request starting with get?referer= or check?referer=. It will look something like this:
    https://c.dun.163.com/api/v3/get?referer=https%3A%2F%2Fpassport.weibo.com%2Fsso%2Fsignin&zoneId=CN31&...&id=7cda0ba2785647ada4d6e946ddb2d465&...
  7. Find the referer parameter in this request. Its value is URL-encoded. Decode it (for example, https%3A%2F%2Fpassport.weibo.com%2Fsso%2Fsignin becomes https://passport.weibo.com/sso/signin). This is your websiteURL.
  8. Find the id parameter in the same request. Its value (e.g., 7cda0ba2785647ada4d6e946ddb2d465) is your websiteKey.

Code Examples

Python + requests

Example of sending a task with pre-known parameters.

python Copy
import requests
import time
import urllib.parse

API_KEY = 'YOUR_API_KEY'
# Decoded URL from the referer parameter
WEBSITE_URL = 'https://passport.weibo.com/sso/signin?entry=miniblog&source=miniblog'
WEBSITE_KEY = '7cda0ba2785647ada4d6e946ddb2d465'
USER_AGENT = 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36'

url = 'https://api.2captcha.com/createTask'
headers = {
    'Content-Type': 'application/json',
    'X-API-Key': API_KEY
}
payload = {
    "clientKey": API_KEY,
    "task": {
        "type": "YidunTaskProxyless",
        "websiteURL": WEBSITE_URL,
        "websiteKey": WEBSITE_KEY,
        "userAgent": USER_AGENT
    }
}

response = requests.post(url, headers=headers, json=payload)
result = response.json()

if result.get('errorId') == 0:
    task_id = result.get('taskId')
    print(f"Task created, ID: {task_id}")
    
    res_url = 'https://api.2captcha.com/getTaskResult'
    while True:
        time.sleep(5)
        
        res_payload = {
            "clientKey": API_KEY,
            "taskId": task_id
        }
        
        res_response = requests.post(res_url, headers=headers, json=res_payload).json()
        
        if res_response.get('errorId') == 0 and res_response.get('status') == 'ready':
            print("Captcha solved successfully!")
            token = res_response['solution']['validate']
            print(f"Token: {token}")
            break
        elif res_response.get('errorId') != 0:
            print(f"Error: {res_response.get('errorDescription')}")
            break
else:
    print(f"Task creation error: {result.get('errorDescription')}")

Python + Playwright

Example of automation that dynamically intercepts the request, extracts parameters, solves the captcha, and injects the token.

python Copy
from playwright.sync_api import sync_playwright
import requests
import time
import urllib.parse

API_KEY = 'YOUR_API_KEY'
TARGET_URL = 'https://passport.weibo.com/sso/signin'

def solve_weibo_yidun():
    with sync_playwright() as p:
        browser = p.chromium.launch(headless=False)
        # Important: set a specific User-Agent to pass it to the API
        user_agent = 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36'
        context = browser.new_context(user_agent=user_agent)
        page = context.new_page()
        
        captured_params = {}

        # Intercept Yidun request to extract parameters
        def handle_request(request):
            if 'c.dun.163.com/api/v3/get' in request.url or 'c.dun.163.com/api/v3/check' in request.url:
                parsed = urllib.parse.urlparse(request.url)
                params = urllib.parse.parse_qs(parsed.query)
                if 'referer' in params:
                    captured_params['websiteURL'] = urllib.parse.unquote(params['referer'][0])
                if 'id' in params:
                    captured_params['websiteKey'] = params['id'][0]

        page.on('request', handle_request)
        
        try:
            page.goto(TARGET_URL)
            
            # Perform action triggering captcha (e.g., entering data and clicking)
            # page.fill('input[name="username"]', 'testuser')
            # page.fill('input[name="password"]', 'testpass')
            # page.click('a[node-type="submitBtn"]')
            
            # Wait for the Yidun request to appear
            page.wait_for_timeout(5000) 
            
            if 'websiteURL' not in captured_params or 'websiteKey' not in captured_params:
                raise Exception("Failed to intercept Yidun parameters. Check page actions.")
            
            print(f"URL: {captured_params['websiteURL']}")
            print(f"Key: {captured_params['websiteKey']}")
            
            # Send to API
            api_url = 'https://api.2captcha.com/createTask'
            headers = {'Content-Type': 'application/json', 'X-API-Key': API_KEY}
            payload = {
                "clientKey": API_KEY,
                "task": {
                    "type": "YidunTaskProxyless",
                    "websiteURL": captured_params['websiteURL'],
                    "websiteKey": captured_params['websiteKey'],
                    "userAgent": user_agent
                }
            }
            
            task_response = requests.post(api_url, headers=headers, json=payload).json()
            task_id = task_response.get('taskId')
            
            # Wait for solution
            res_url = 'https://api.2captcha.com/getTaskResult'
            token = None
            for _ in range(20):
                time.sleep(5)
                res = requests.post(res_url, headers=headers, json={"clientKey": API_KEY, "taskId": task_id}).json()
                if res.get('status') == 'ready':
                    token = res['solution']['validate']
                    break
                if res.get('errorId') != 0:
                    print(f"API error: {res.get('errorDescription')}")
                    break
                    
            if token:
                print(f"Token received: {token}")
                
                # Token injection
                page.evaluate(f"""
                    // Attempt to find hidden field
                    let input = document.querySelector('input[name="captchaValidate"], input[name="NECaptchaValidate"], input[name="token"]');
                    if (!input) {{
                        input = document.createElement('input');
                        input.type = 'hidden';
                        input.name = 'captchaValidate';
                        document.querySelector('form')?.appendChild(input);
                    }}
                    input.value = "{token}";
                """)
                print("Token injected into DOM.")
            else:
                print("Failed to get token.")
                
        except Exception as e:
            print(f"Error: {e}")
        finally:
            # browser.close()

if __name__ == '__main__':
    solve_weibo_yidun()

How to use the received token

The exact mechanism of Yidun token injection on Weibo may be updated, but there are two main proven methods:

  1. Injection into a hidden form field: As shown in the example above, the site often expects the token in a hidden input with names like captchaValidate, NECaptchaValidate, or token.
  2. Intercepting and modifying the XHR request (Most reliable method): If the form is submitted via JavaScript, the token might not be read from the DOM. In this case, it is best to intercept the authorization request using page.route in Playwright and add the token to the request payload before sending it to the server.

Reporting correct/incorrect solutions

If the website rejected the received token, be sure to report it via the reportIncorrect method. This helps the service improve its recognition algorithms and refunds your funds for the unsolved task. If the solution successfully passed verification, send a reportCorrect.

python Copy
import requests

API_KEY = "YOUR_API_KEY"
TASK_ID = "123456789" # Task ID received upon creation

# Report incorrect solution
requests.post(
    "https://api.2captcha.com/reportIncorrect",
    json={"clientKey": API_KEY, "taskId": TASK_ID}
)

# Report correct solution
requests.post(
    "https://api.2captcha.com/reportCorrect",
    json={"clientKey": API_KEY, "taskId": TASK_ID}
)

Common Errors and Solutions

Error / Problem Cause Solution
Validation error or infinite loading Mismatch between userAgent in the API request and the browser. Ensure the userAgent string in the API task matches byte-for-byte with what your browser sends.
ERROR_INVALID_CAPTCHA_ID Invalid websiteKey. Make sure you are copying the value of the id parameter, not another parameter from the request.
Token not accepted by the site Incorrect injection method or outdated websiteURL. Use XHR request interception (page.route) to add the token to the payload, as this is the most reliable method for modern login forms.
Captcha does not appear The site does not trigger the check. Try using incognito mode, clearing cookies, or changing your IP address to force the captcha to appear.