Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

When a CAPTCHA blocks an automated browser flow, treat it as a blocked state—not as a page-load error to ignore or a challenge every API can solve. Detect the interruption, record enough context to diagnose it, and continue only through a human step or test path the site owner has approved. Playwright provides page, locator, and network controls; Browserless and 2Captcha separately describe managed-browser services with CAPTCHA-related handling. None of those facts guarantees that a particular challenge can be completed or that automated solving is authorized.

What a CAPTCHA means for an automation workflow

A CAPTCHA is an intervention in the flow, not an ordinary success page. A script that keeps waiting for a login button, retries the same request indefinitely, or reports success without checking the destination can turn a visible block into a silent failure. Instead, represent the challenge as its own outcome, distinct from success, timeout, and application error.

There is no single dependable selector or page shape for all CAPTCHAs. A challenge may be embedded in a frame, rendered dynamically, or presented through a vendor-specific flow. Detection therefore needs to be tailored to the site you are authorized to automate; do not assume that searching for one universal word or element will identify every challenge.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Observe: check whether the expected action or page transition happened, and whether a known challenge indicator is present.
  • Decide: stop normal automation and mark the run blocked or awaiting intervention.
  • Resume only through an approved route: use a human step or a test configuration provided by the site owner. For third-party sites, establish permission and follow the site’s rules.

What browser automation APIs do—and do not—provide

Playwright: page and network controls

Playwright’s Page API documentation describes general browser-page interaction and locator handlers for unexpected overlays that block test actions. Those handlers can help a test respond to ordinary overlays; they are not evidence that Playwright includes a CAPTCHA solver.

#1 Best Overall
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Playwright’s network documentation covers monitoring and modifying HTTP and HTTPS traffic, including XHR and fetch requests, as well as request mocking. That is useful in a controlled test environment—for example, when the site owner supplies a supported test route—but intercepting or mocking traffic does not resolve an external site’s live challenge by itself.

Managed-browser and CAPTCHA-related services

Browserless documentation describes managed-browser routes and CAPTCHA-related handling. 2Captcha’s Browser API documentation describes a cloud browser controlled through CDP, with clients such as Playwright and Puppeteer, and lists CAPTCHA handling as a use case. These are vendors’ descriptions of their own services, not independent performance evaluations or guarantees of success. Coverage, compatibility, and availability may change; consult each vendor’s current documentation.

A service offering does not establish that automated solving is permitted for a particular target. Authorization, site terms, the data exposed to a service, and what happens when a challenge changes remain decisions for the operator and site owner.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build a visible, fail-safe CAPTCHA state in Playwright

The following Node.js example uses a site-specific selector supplied in CAPTCHA_SELECTOR. It performs a normal navigation, checks the configured indicator, saves a diagnostic screenshot if the indicator appears, then pauses for an authorized person in a visible browser. It proceeds only if the expected post-login selector becomes visible. The selector is not universal: obtain it from the site owner or verify it against the authorized application and its current interface.

Rank #2
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Install Playwright with npm install playwright. Set LOGIN_URL, CAPTCHA_SELECTOR, and SUCCESS_SELECTOR to values appropriate to your authorized test. This example deliberately does not attempt to solve, click through, or bypass a challenge.

const { chromium } = require('playwright');

async function main() {
  const loginUrl = process.env.LOGIN_URL;
  const captchaSelector = process.env.CAPTCHA_SELECTOR;
  const successSelector = process.env.SUCCESS_SELECTOR;

  if (!loginUrl || !captchaSelector || !successSelector) {
    throw new Error('Set LOGIN_URL, CAPTCHA_SELECTOR, and SUCCESS_SELECTOR');
  }

  const browser = await chromium.launch({ headless: false });
  const page = await browser.newPage();

  try {
    await page.goto(loginUrl, { waitUntil: 'domcontentloaded', timeout: 30000 });
    await page.screenshot({ path: 'before-check.png', fullPage: true });

    const challenge = page.locator(captchaSelector).first();
    const challengeVisible = await challenge.isVisible().catch(() => false);

    if (challengeVisible) {
      console.log('Blocked: challenge detected. Complete it only if authorized.');
      await page.screenshot({ path: 'challenge.png', fullPage: true });

      // Human intervention is bounded; a timeout exits as a blocked run.
      try {
        await page.locator(successSelector).waitFor({
          state: 'visible',
          timeout: 120000
        });
      } catch {
        throw new Error('Blocked: approved human step did not reach expected state');
      }
    } else {
      // Do not declare success just because no configured challenge matched.
      await page.locator(successSelector).waitFor({
        state: 'visible',
        timeout: 15000
      });
    }

    console.log('Expected application state reached.');
    await page.screenshot({ path: 'after-check.png', fullPage: true });
  } finally {
    await browser.close();
  }
}

main().catch((error) => {
  console.error(error.message);
  process.exitCode = 1;
});

The example detects only the selector you configure. If that selector is absent, the expected success-state check still prevents the script from claiming success merely because no challenge was found. In production, report the final outcome to the job runner as a distinct status such as blocked, retain the error and timestamps, and apply your own data-retention rules to screenshots and browser state.

Choose an approved way to continue

For a site you own or test

Ask the site owner to provide a supported test configuration or a human-intervention route for the environment. Keep the test outcome meaningful: a mocked or specially configured flow tests the conditions it was designed to test, not necessarily the live CAPTCHA experience. Document which route ran so downstream systems do not mistake a test exception for a production verification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a third-party site

Confirm that your automation and any managed service are allowed by the site’s rules and by your authorization. If no approved route exists, stop the job and surface the block for review rather than silently retrying or treating a vendor integration as permission.

Rank #3
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

When evaluating a managed service

Assess the service against your own requirements: whether the site owner authorizes it, how session and page data are handled, what integration and maintenance it adds, and whether an unavailable or changed challenge fails visibly. The cited vendor pages describe their offerings; they do not provide a like-for-like independent comparison of effectiveness, cost, latency, or supported challenge coverage.

Diagnostics, reliability, and cost controls

Capture enough context to distinguish a challenge from a broken application without collecting more sensitive data than the workflow needs. A useful record can include the run identifier, URL or route where permitted, timestamp, expected state, observed state, and the error or timeout. A screenshot may help an operator understand the block, but it can also contain personal or account data; apply the same access and retention controls as for other test artifacts.

  • Bound waits: use explicit timeouts for navigation, challenge intervention, and success-state checks so one blocked run cannot wait forever.
  • Limit retries: retry only failures that are known to be transient and safe to retry. Repeating a challenge flow does not make it authorized or guarantee progress.
  • Keep outcomes separate: distinguish challenge/intervention required from selector mismatch, navigation timeout, and application failure in logs and job status.
  • Review changes: revalidate site-specific selectors when the application changes. A missing challenge selector is not proof that no challenge occurred.
  • Control artifacts: store screenshots, cookies, and browser traces only as long as needed and only where authorized.

There is no source-supported universal rate, latency, success percentage, or cost for completing CAPTCHA challenges with these approaches. Estimate operational cost from your own authorized workflow and vendor terms, including human review and maintenance when the page or challenge changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common blocked-flow failures

The script times out waiting for the expected page

Check whether the site presented an unrecognized challenge, an ordinary overlay, a slow application response, or an incorrect success selector. Save the page state allowed by your data policy and classify the outcome as blocked or failed rather than extending the timeout without diagnosis.

Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

The challenge is visible but the configured selector is not found

The selector is site-specific and may be inside a frame or may have changed. Verify the authorized page structure and update the test configuration; do not infer that a generic Playwright locator handler will solve the challenge.

A network mock does not remove the live challenge

Playwright network interception and request mocking are controls for traffic in a workflow, particularly useful in controlled testing. They do not constitute a solver for an external live challenge. Ask the site owner for an approved test path instead.

A managed service cannot complete the flow

Check the provider’s current documentation for the route and integration you are using, then verify authorization and compatibility with the target. The provider’s description is not an assurance for every challenge. Fail visibly and provide a human or owner-approved next step when the route is unavailable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The job reports success after a challenge appears

Require a concrete application postcondition—such as a known authenticated-page element—instead of using absence of an error as success. Keep the blocked path and the successful path separate in job results.

Or skip the browser setup

If the task is to capture a page rather than complete its CAPTCHA, ScreenshotNeo offers a screenshot API and MCP server. A screenshot API does not solve a CAPTCHA or authorize access; if the target presents a challenge, treat that as a blocked capture. For pages you are allowed to capture, one GET request can return an image or PDF. See the ScreenshotNeo API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before capture; those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and the response identifies the page verdict and billing status in headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for AI agents. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots. Every feature is on every plan.

Sign up free for 1,000 screenshots a month with no card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Does a Playwright locator handler handle an embedded CAPTCHA frame?

Not necessarily. Locator handlers address configured page overlays; an embedded challenge may require a site-specific, owner-approved intervention path.

Can an MCP client use ScreenshotNeo to complete a CAPTCHA?

No. Its MCP tools are for screenshot, page-info, and PDF capture, not CAPTCHA completion.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.