AWS WAF challenge.js and jsapi.js fields: a preflight reference
A field reference for documented AWS WAF challenge.js and jsapi.js inputs, proxyless task creation, response checks, and safer release preflight.

AWS WAF challenge.js and jsapi.js fields are optional inputs for the documented AntiAwsWafTaskProxyLess request, but they are not interchangeable. A reliable preflight starts by identifying what the protected page actually exposes, retaining the values only for the request that needs them, and sending a minimal documented task to CapBypass.
This reference covers authorized server-side integrations using the proxyless AWS WAF web task. It focuses on request construction before createTask, not on replaying an AWS WAF integration tutorial. The current CapBypass documentation lists AntiAwsWafTaskProxyLess as the built-in-proxy web challenge task and documents the fields below.
Choose the task before collecting fields
Use AntiAwsWafTaskProxyLess when the web challenge should use CapBypass proxy infrastructure. Do not add a proxy field for this task. The companion AntiAwsWafTask is the own-proxy variant and requires a caller-supplied proxy. Treat those as separate routing choices rather than fallback values for the same payload.
The mobile task is also separate. The documentation describes AntiAwsWafMobileTask as a mobile app token flow with no URL, parameters, or proxy. It does not share the web task field set in this reference.
For a proxyless web task, websiteURL is required. It must be the protected page URL observed by the authorized application. Keep the URL specific to the page whose challenge values were collected. A different path or a stale page capture can make the optional values unsuitable for the request.
Field reference
| Field | Required | Use it when | Preflight check |
|---|---|---|---|
websiteURL |
Yes | Every proxyless AWS WAF web task | Confirm it is the protected page URL. |
awsChallengeJS |
No | The page exposes a challenge.js script URL |
Preserve the script URL exactly as observed. |
awsApiJs |
No | The page exposes a jsapi.js script URL for a CAPTCHA flow |
Preserve the script URL exactly as observed. |
awsKey |
No | The CAPTCHA page provides a key value | Pair it with values collected from the same page state. |
awsIv |
No | The CAPTCHA page provides an iv value | Do not substitute a value from another request. |
awsContext |
No | The CAPTCHA page provides a context value | Keep it aligned with the page state that produced it. |
awsProblemUrl |
No | The integration has a documented problem endpoint URL | Use the observed endpoint URL, not a guessed path. |
awsApiKey |
No | The page provides an api_key value |
Send only the value collected by the authorized flow. |
awsExistingToken |
No | Refreshing a previously issued aws-waf-token |
Use it only for the documented refresh case. |
Optional does not mean synthetic. Omit a field that the authorized page did not provide. Do not manufacture awsChallengeJS, awsApiJs, awsKey, awsIv, or awsContext to make a payload look complete.
Build the smallest documented request
The API endpoint is POST https://api.capbypass.pro/createTask. The following request uses only the required proxyless task fields. Replace YOUR_API_KEY with your CapBypass client key and replace the example URL with a page you are authorized to automate.
curl -X POST https://api.capbypass.pro/createTask \
-H 'Content-Type: application/json' \
-d '{
"clientKey": "YOUR_API_KEY",
"task": {
"type": "AntiAwsWafTaskProxyLess",
"websiteURL": "https://example.com/protected"
}
}'When the protected page exposes a relevant script URL, add the matching documented field without changing the task type. For example, add "awsChallengeJS": "https://example.com/challenge.js" only after the authorized page has supplied that URL. For a CAPTCHA flow that supplies jsapi.js, use awsApiJs instead. A payload can contain the optional values that the page actually provides, but the field names should remain exactly as documented.
A successful create response has errorId set to 0 and returns a taskId. Store that task ID with the request evidence needed for your own audit trail. Poll the documented POST https://api.capbypass.pro/getTaskResult endpoint with the same client key and task ID. Bound polling in your application and handle a nonzero error response as a signal to inspect the captured input rather than repeatedly resubmitting an unchanged payload.
Validate challenge.js versus jsapi.js
The names identify different documented inputs. Use awsChallengeJS for the challenge.js script URL. Use awsApiJs for the jsapi.js script URL in a CAPTCHA flow. Neither field replaces websiteURL, and neither proves that the other values are available.
Before creating a task, record four pieces of evidence: the protected page URL, the collection time, the applicable script URL, and any optional key, iv, or context values obtained from the same authorized page state. This makes it possible to distinguish a missing field from a mismatched capture when investigating a failed task.
Avoid combining values from different page visits. A key, iv, or context value may belong to the page state that generated it. A minimal request is easier to review, and adding every optional field by default makes it harder to identify the source of a mismatch.
Response and release checks
Use the create response as the first validation point. Confirm that errorId is 0 and retain the returned taskId. At the result endpoint, validate the response before consuming any returned value in the authorized application. Keep task creation, result polling, and downstream use as separate steps so an API error cannot be mistaken for a usable result.
A practical release checklist is:
- Confirm the task type is exactly
AntiAwsWafTaskProxyLess. - Confirm
websiteURLis the protected page URL from the authorized flow. - Include only optional values observed for that same page state.
- Do not send
proxy; this is the documented built-in-proxy task. - Check
errorIdand retaintaskIdbefore polling. - Bound polling and log the field names used, not secret values.
For the complete current schema and task lifecycle, use the AWS WAF documentation and the CapBypass API reference.
Bonus: +5% credits on every top-up
New to CapBypass? Apply code
WELCOME_2026at checkout for an extra 5% in credits on every top-up, with no minimum and no expiry. Redeem it on the top-up page.
Keep the preflight narrow
The most useful AWS WAF field check is not a larger JSON body. It is a narrow mapping from the protected page to the documented parameter: challenge.js to awsChallengeJS, jsapi.js to awsApiJs, and page-provided values to their matching optional fields. With that mapping recorded, a proxyless request stays reviewable and can be corrected without changing undocumented parameters.
Ready to start solving CAPTCHAs?
Get started with CapBypass in minutes. No credit card required.


