# How to Bypass Amazon CAPTCHA in 2026: Main Approaches > Source: https://scrape.do/blog/bypass-amazon-captcha/ Published: 2026-10-05 · Updated: 2026-10-05 · Authors: Antonello Zanini · Categories: Anti Bot Amazon's CAPTCHA system has changed significantly in 2026. Instead of the traditional text-based challenge, you may now get a simple "Continue shopping" button. This new human-verification system can complicate Amazon scraping and browser automation. Below, you will learn how the new human-verification mechanism works and explore three practical approaches to Amazon CAPTCHA bypass: automated click logic, browser automation with rotating proxies, and an all-in-one Amazon scraper API. ## An Introduction to the Amazon CAPTCHA Before diving into Amazon CAPTCHA bypass, you need to understand what this challenge is and how it has evolved. ### What is the Amazon CAPTCHA? Amazon CAPTCHA is an automated security test that Amazon uses to distinguish human users from automated bots. Its goal is to prevent unauthorized scraping, spam orders, and excessive traffic from overwhelming Amazon's servers. ### Old Amazon CAPTCHA vs New Amazon "Continue shopping" Challenge Before 2026, Amazon used to show text-based CAPTCHAs when it detected suspicious traffic: ![The old Amazon CAPTCHA](/uploads/blog/bypass-amazon-captcha-old-text-captcha.webp) This does not represent a particularly strong challenge for modern automated systems. [OCR models](https://www.sciencedirect.com/science/article/pii/S2666720725000189), vision-language models, and other machine-learning systems can often extract and interpret the text from these types of images relatively easily. ![Note how Gemini can easily detect the right characters from the CAPTCHA challenge](/uploads/blog/bypass-amazon-captcha-gemini-solves-text-captcha.webp) However, as with many modern CAPTCHAs, solving the visible challenge is only part of the process. While the user is interacting with the CAPTCHA (in this case, typing the characters shown in the image), the page collects additional interaction and browser data. That includes metrics such as timing, mouse or pointer movements, typing behavior, browser characteristics, and more. These signals are used as part of a broader assessment of whether the traffic is automated. Learn more about [CAPTCHA bypass](https://scrape.do/blog/bypass-captcha/). At the time of writing (September 2026), that particular type of CAPTCHA appears to no longer be commonly deployed. Instead, what you may encounter is a simple one-click "Continue shopping" challenge: ![The new Amazon human-verification challenge](/uploads/blog/bypass-amazon-captcha-continue-shopping-challenge.webp) If you are familiar with other bot-detection providers, this approach will look familiar. It is conceptually similar to Cloudflare's "Verify you are human" challenge (powered by [Cloudflare Turnstile](https://www.cloudflare.com/products/turnstile/)). Discover [how to bypass Cloudflare](https://scrape.do/blog/bypass-cloudflare/). In both Cloudflare and Amazon's systems, the one-click interaction serves as one input into a broader bot-detection or risk-assessment process. Specifically, Amazon can consider signals related to the browser environment, interaction behavior, and other characteristics when determining whether additional verification is necessary. ## When is the Amazon CAPTCHA Deployed? The old Amazon CAPTCHA appeared to be triggered by a combination of aspects, including IP reputation, [TLS and HTTP characteristics](https://scrape.do/features/dynamic-tls-fingerprinting/), browser fingerprinting, CDP (Chrome DevTools Protocol) detection, and other indicators associated with automated or suspicious traffic. The newer "Continue shopping" test appears to build on the same general risk-based approach. As noted by [some users on Reddit](https://www.reddit.com/r/amazonprime/comments/1qngyf8/why_do_i_have_to_click_on_this_continue_shopping/), it can also be issued to legitimate users browsing in a completely new browser session. This suggests that the presence of certain cookies or previous Amazon browsing history is taken into consideration as well. As a result, you can sometimes trigger Amazon's new human-verification challenge simply by visiting an Amazon product page in an incognito browsing window: ![Note the "Continue shopping" Amazon verification challenge received in an incognito session](/uploads/blog/bypass-amazon-captcha-incognito-continue-shopping.webp) Remember that these systems are based on risk-scoring algorithms, rather than deterministic rules. The system evaluates multiple signals and assigns some level of confidence that a request is automated or suspicious. Thus, the outcome may not always be consistent. For example, you might receive the "Continue shopping" challenge on one request, while another request takes you directly to the page. Similar variability could also be observed with Amazon's older CAPTCHA system. ## How Does the Amazon "Continue shopping" Challenge Work? Assume you are actually presented with the newer iteration of Amazon's CAPTCHA. After clicking the "Continue shopping" button, you are redirected to Amazon's homepage rather than being returned directly to the page you originally attempted to visit: ![The Amazon human-verification workflow](/uploads/blog/bypass-amazon-captcha-verification-workflow.webp) An important effect of this workflow is that an automated system that completes the visible challenge does not immediately receive the page it originally requested. Instead, it has to make additional requests before reaching its intended destination. The resulting navigation would therefore look roughly like this: 1. Amazon's human-verification challenge page instead of the originally requested page. 2. Redirect to Amazon's homepage. 3. Manual navigation to the Amazon page of interest. This adds additional requests and latency. It also consumes more bandwidth, which can raise costs when routing requests through proxies that charge based on the amount of data transferred. After successfully clicking the "Continue shopping" button, two cookies are set: - `x-amz-captcha-1` - `x-amz-captcha-2` ![Note the Amazon CAPTCHA cookies](/uploads/blog/bypass-amazon-captcha-captcha-cookies-devtools.webp) For subsequent requests, having these cookies may reduce the likelihood of being presented with the Amazon verification challenge. Still, Amazon's anti-automation systems can reassess a session as it continues. Consequently, a new challenge may still appear if the overall risk assessment changes (e.g., due to changes in the network, browser environment, session state, or other signals). ## Top 3 Amazon CAPTCHA Bypass and Avoidance Techniques In the following sections, you will be guided through three different approaches for either implementing a CAPTCHA solver or avoiding Amazon's human-verification challenge altogether. Compare them in the table below: | **Approach** | **Who Handles Amazon CAPTCHA Bypass** | **Description** | **Ideal for** | **Cost** | | ----------------------------------- | ------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------- | -------------------- | | **"Continue shopping" Click Logic** | You | Automate Amazon's human-verification button directly using Playwright or another browser automation framework. | Very small-scale Amazon scraping and browser automation pipelines | Free | | **Browser Automation with Proxy** | Provider | Combine browser automation with rotating proxies and integrated CAPTCHA handling. | Larger-scale Amazon browser automation operations | Free plan, then paid | | **All-in-One Amazon Scraper API** | Provider | Retrieve structured Amazon data directly through an API without managing browsers, proxies, or CAPTCHA handling. | Data-focused Amazon workflows | Free plan, then paid | **Important**: The best way to deal with Amazon CAPTCHA bypass is to avoid triggering it in the first place rather than trying to solve it afterward. That involves maintaining a consistent browser fingerprint and realistic browsing sessions. ### Prerequisites Make sure you have the following: - [Python 3.10+](https://www.python.org/downloads/) installed locally. - Basic knowledge of browser automation and automated HTTP requests. For the last two approaches, you will also need a [Scrape.do API token](https://scrape.do/documentation/#generate-api-token). To get one, start by [logging in to your Scrape.do account](https://dashboard.scrape.do/login). If you do not have an account yet, [create one](https://dashboard.scrape.do/sign-up). After logging in, you will be redirected to the "Playground" section of your account. To retrieve your API token, click "Copy to clipboard" in the "Your API Token" section in the bottom-left corner: ![Copying your Scrape.do API token](/uploads/blog/bypass-amazon-captcha-copy-scrape-do-api-token.webp) A Scrape.do API token is required to authenticate requests to the Web Scraping API (directly or via Proxy Mode) and Amazon Scraper API. [See the Scrape.do documentation for more details](https://scrape.do/documentation/). ## Approach #1: Automated "Continue shopping" Click Logic From an automation perspective, the new Amazon "Continue shopping" challenge is a simple button click. So, in principle, you can instruct your favorite browser automation tool to just click the button when it appears. That may sound trivial, as it generally would not be sufficient for anti-bot systems such as Cloudflare Turnstile. However, based on my tests with Amazon's current human-verification flow, this approach seems to work (at least at the time of writing!). ### Implementation Below is how to automate the "Continue shopping" click interaction with Playwright: ```python # pip install playwright # playwright install from playwright.sync_api import sync_playwright, TimeoutError # Target Amazon product page AMAZON_PRODUCT_PAGE_URL = "https://www.amazon.com/PEHAEL-iPhone-18-Pro-Max/dp/B0H71RGBQ3/" with sync_playwright() as p: # Initialize the browser session browser = p.chromium.launch( headless=True ) page = browser.new_page() # Visit the target page page.goto(AMAZON_PRODUCT_PAGE_URL) try: # Click "Continue shopping" if the button appears continue_button = page.get_by_role( "button", name="Continue shopping" ) continue_button.wait_for( state="visible", timeout=5000 ) continue_button.click() print("Clicked 'Continue shopping'") # Visiting the target page again after being redirected to the Amazon homepage page.goto(AMAZON_PRODUCT_PAGE_URL) except TimeoutError: pass # Your scraping / browser automation logic... # Close the browser and release its resources browser.close() ``` The flow is fairly straightforward: 1. Playwright opens the target Amazon product page. 2. If the "Continue shopping" challenge appears, the script waits for the button and clicks it. 3. The browser will be redirected to Amazon's homepage, so it navigates back to the original product page. 4. You can now continue with your normal browser automation or [Amazon scraping](https://scrape.do/blog/amazon-scraping/) logic. Keep in mind that the challenge is not necessarily loaded on every request. If it does not show up within the five-second timeout, the script simply continues. This makes the same code usable whether Amazon presents the challenge or takes the browser directly to the requested page. **Note:** I tested the script above on more than 100 Amazon product pages in both headless and headful mode and did not observe a significant difference in success rates. Thus, I recommend using headless mode (`headless=True`) to reduce resource usage. ### Alternatives Selenium, Puppeteer, or [any other browser automation framework](https://scrape.do/blog/javascript-headless-browser/) that allows you to implement the same click interaction should work as well. In my tests, using open-source anti-detect browser automation libraries such as Patchright, `invisible_playwright`, or Camoufox did not provide any noticeable advantage. The "Continue shopping" button still appeared at roughly the same frequency as it did with vanilla Playwright. That said, these solutions used to be more useful with Amazon's previous CAPTCHA system. If you already have an established pipeline built around one of them, there is little reason to migrate to a different framework solely for this reason. Plus, their realistic browser fingerprints help reduce CAPTCHAs on other sites, or potentially on Amazon again if its detection mechanism changes in the future. ### Pros - Simple to implement yet effective (for now). - No OCR or image-recognition logic is required. - Fully free, with no third-party integrations required. ### Cons - Amazon can change its challenge or detection logic at any time, breaking your automation. - Waiting for the challenge to appear adds unnecessary latency to each request. - It is not scalable due to Amazon rate limits. ## Approach #2: Amazon Browser Automation with a Proxy The biggest limitation of the previous approach is scalability. Regardless of whether the custom logic for interacting with Amazon's new CAPTCHA works, you will eventually run into Amazon's request limits if you send too many requests from the same IP within a given time window. When that happens, Amazon will return a generic [`503 Service Unavailable`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/503) error page like this: ![Example of an Amazon 503 error page](/uploads/blog/bypass-amazon-captcha-503-error-page.webp) In other words, for rate-limiting scenarios, Amazon responds with a generic `503` instead of the standard [`429 Too Many Requests`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/429). The status code is different, but the practical effect is similar: Amazon is [limiting or blocking your requests](https://scrape.do/blog/web-scraping-rate-limit/)! One way to avoid this issue is to distribute your Amazon browser-automation or scraping traffic across multiple IP addresses using a rotating proxy service, such as [Scrape.do's Web Scraping API via Proxy Mode](https://scrape.do/documentation/proxy-mode/). Compared with a regular proxy, Scrape.do's Proxy Mode also provides additional [anti-bot capabilities](https://scrape.do/features/anti-bot-bypass/), including [CAPTCHA solving](https://scrape.do/features/captcha-handling/) and other features. By routing your Playwright traffic through the Scrape.do Web Scraping API in Proxy Mode, you get: - Built-in Amazon anti-bot detection and CAPTCHA handling. - Automatic IP rotation for Amazon scraping and automation at scale. ### Implementation Route your Playwright requests for Amazon scraping or automation through [Scrape.do's Web Scraping API](https://scrape.do/products/web-scraping-api/) in Proxy Mode: ```python # pip install playwright # playwright install from playwright.sync_api import sync_playwright, TimeoutError # Target Amazon product page AMAZON_PRODUCT_PAGE_URL = "https://www.amazon.com/PEHAEL-iPhone-18-Pro-Max/dp/B0H71RGBQ3/" # Replace with your Scrape.do API token SCRAPE_DO_API_TOKEN = "" # Configuration to route Playwright requests through Scrape.do Proxy Mode proxy = { "server": "http://proxy.scrape.do:8080", "username": SCRAPE_DO_API_TOKEN, "password": "super=true&geoCode=us", } with sync_playwright() as p: # Initialize the browser session browser = p.chromium.launch( headless=True, proxy=proxy ) page = browser.new_page() # Visit the target page # (Scrape.do takes care of IP rotation and Amazon CAPTCHA handling) page.goto( AMAZON_PRODUCT_PAGE_URL, timeout=60000 ) # Your scraping / browser automation logic... # Close the browser and release its resources browser.close() ``` Notice how: - Each Playwright request is automatically routed through Scrape.do's Web Scraping API, which can also operate as a proxy through [Proxy Mode](https://scrape.do/documentation/proxy-mode/). - The logic for clicking the "Continue shopping" button is no longer required. With Scrape.do's anti-bot technology, the human-verification challenge should not appear. **Notes**: 1. For the script to work on your machine, you [must install the Scrape.do SSL certificate](https://scrape.do/scrapedo_ca.crt). 2. In production, avoid hardcoding your Scrape.do API token in the script. Instead, read it from an environment variable. ### Alternatives Any other browser automation solution that supports proxy integration will work as well. ### Pros - Highly scalable (150M+ proxy IPs across 150 countries). - Integrated Amazon CAPTCHA handling. - No custom workarounds required. ### Cons - Paid solution for large projects (refer to [Scrape.do's pricing page](https://scrape.do/pricing/)). - Managing multiple browser instances at scale is challenging. ## Approach #3: All-in-One Amazon Scraper API Setting up Playwright and dealing with browser automation may be more than you need, especially if you are only interested in Amazon data. In that case, you can skip browser automation, browser rendering, CAPTCHA solving, IP blocks, fingerprinting, and other related [scraping challenges](https://scrape.do/blog/prevent-web-scraping/) and go directly with an Amazon web scraping API. For example, [Scrape.do's Amazon Scraper API](https://scrape.do/products/ready-api/amazon-scraper/) provides several endpoints for retrieving different types of Amazon data: | **Endpoint** | **Description** | | ------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | | GET [`/plugin/amazon/pdp`](https://scrape.do/documentation/amazon-scraper-api/pdp/) | Extract product details, pricing, images, ratings, and specifications | | GET [`/plugin/amazon/offer-listing`](https://scrape.do/documentation/amazon-scraper-api/offer-listing/) | Retrieve seller offers, prices, shipping details, and availability | | GET [`/plugin/amazon/search`](https://scrape.do/documentation/amazon-scraper-api/search/) | Retrieve search results, product listings, rankings, and prices | | GET [`/plugin/amazon/deals`](https://scrape.do/documentation/amazon-scraper-api/deals/) | Retrieve discounted products, prices, categories, and deal information | | GET [`/plugin/amazon/bestsellers`](https://scrape.do/documentation/amazon-scraper-api/bestsellers/) | Retrieve bestseller products, rankings, prices, ratings, and releases | | GET [`/plugin/amazon/seller`](https://scrape.do/documentation/amazon-scraper-api/seller/) | Retrieve seller profiles, business details, feedback, and related information | You send a request to the Amazon Scraper API with the target product, search, seller, or other resource, and get structured JSON data in response. Scrape.do handles the underlying infrastructure while offering a 99.98% success rate. ### Implementation Use `requests` (or any other HTTP client) to connect to Scrape.do's Amazon Scraper API. For example, retrieve structured product data from an Amazon product page with: ```python # pip install requests import requests import json # Target Amazon product page AMAZON_PRODUCT_PAGE_URL = "https://www.amazon.com/PEHAEL-iPhone-18-Pro-Max/dp/B0H71RGBQ3/" # Replace with your Scrape.do API token SCRAPE_DO_API_TOKEN = "" # API parameters params = { "token": SCRAPE_DO_API_TOKEN, "asin": "B0H71RGBQ3", # Amazon ASIN of the target product "super": True, "geocode": "us", } # Send the request response = requests.get( "https://api.scrape.do/plugin/amazon/pdp", params=params, ) # Raise an exception for HTTP errors response.raise_for_status() # Parse the structured response product_data = response.json() # Save the retrieved data to a JSON file with open("amazon_product.json", "w", encoding="utf-8") as file: json.dump(product_data, file, indent=2, ensure_ascii=False) ``` For more information, refer to the [Scrape.do Amazon Scraper API documentation](https://scrape.do/documentation/amazon-scraper-api/). The flow is much simpler than the Playwright version: 1. The script sends the ASIN to [Scrape.do's Amazon PDP API](https://scrape.do/documentation/amazon-scraper-api/pdp/). 2. Scrape.do retrieves and parses the Amazon product page. 3. The API returns structured product data as JSON. 4. The script saves the complete response to disk. Execute the script, and you will receive the following `amazon_product.json` file: ![The output "amazon_product.json" file produced by the script](/uploads/blog/bypass-amazon-captcha-product-json-output.webp) This contains all the data from the Amazon product page, but in a structured format. For production, remember to read the API token from an environment variable. If you want to retrieve multiple products, the same approach can be extended to loop over a list of Amazon URLs and save all results into a single JSON array. ### Alternatives Explore other [Amazon web scraping APIs](https://scrape.do/blog/best-amazon-scraper-api/) if you need different features, pricing, or coverage. ### Pros - No browser automation required. - Works with any HTTP client or tool that supports HTTP requests. - Automatic proxy rotation, CAPTCHA handling, and data parsing. - Multiple endpoints covering different Amazon scraping use cases. - Free plan available. - Pay only for successful requests. - Geotargeting available across 150 countries. ### Cons - A paid plan is required after the free allowance is used. ## Amazon CAPTCHA Bypass Techniques: Which One Should I Choose? The right approach to Amazon CAPTCHA bypass depends mainly on your scraping volume, whether you need browser automation, and how much infrastructure you want to manage yourself. As a rule of thumb: - **Small-scale scraping and existing Playwright workflows** → Automated "Continue shopping" click logic - **You already use Selenium, Puppeteer, or Playwright** → Automated "Continue shopping" click logic, Browser automation with a proxy - **Need browser automation at higher volumes** → Browser automation with a proxy - **Need full control over the browser and page interaction** → Browser automation with a proxy - **Only need structured Amazon product data** → All-in-one Amazon Scraper API - **Need Amazon search, product, seller, deals, or bestseller data** → All-in-one Amazon Scraper API - **Want to avoid managing browsers, fingerprints, and CAPTCHA logic** → All-in-one Amazon Scraper API - **Building a data pipeline or AI agent that only needs Amazon data** → All-in-one Amazon Scraper API - **Looking for a free solution with no third-party service** → Automated "Continue shopping" click logic - **Looking for the simplest implementation** → All-in-one Amazon Scraper API In practice, the choice comes down to how much control you need. If you already have a working browser-automation pipeline and only occasionally encounter Amazon's current "Continue shopping" challenge, adding the click logic may be enough. If you need browser automation but are running into IP-based limits as your volume grows, adding a rotating proxy can address part of the scalability problem. If your main objective is to retrieve Amazon data rather than interact with the website itself, an Amazon Scraper API removes most of the browser-automation overhead altogether. ## Conclusion Here, you learned what Amazon CAPTCHA is, why it has evolved into the "Continue shopping" single-click challenge, and how these human-verification mechanisms work. In detail, you saw how to bypass Amazon CAPTCHA with three different approaches: 1. Automated "Continue shopping" click logic 2. Browser automation with a proxy 3. All-in-one Amazon Scraper API Scrape.do simplifies this process by providing rotating proxies with [integrated CAPTCHA handling](https://scrape.do/features/captcha-handling/), along with dedicated [Amazon Scraper APIs](https://scrape.do/products/ready-api/amazon-scraper/) for retrieving Amazon data. Create an account today and test these solutions for free! ## FAQ ### Is Scrape.do an Amazon CAPTCHA solver? Yes, Scrape.do also acts as an Amazon CAPTCHA solver. Its scraping infrastructure can handle Amazon's anti-bot challenges as part of the scraping process, without writing CAPTCHA-solving logic yourself. ### What is the difference between Amazon CAPTCHA and Amazon WAF CAPTCHA? Amazon CAPTCHA is a human-verification challenge shown when Amazon detects suspicious traffic. [Amazon WAF CAPTCHA](https://docs.aws.amazon.com/waf/latest/developerguide/waf-captcha-and-challenge.html) is part of AWS WAF's bot-management and security capabilities. They can serve similar purposes, but they belong to different Amazon security systems. ### What is the difference between Amazon CAPTCHA and Amazon "Continue shopping" challenge? Amazon's traditional CAPTCHA required solving a visual challenge, such as entering distorted text. The newer "Continue shopping" challenge uses a simple button interaction to verify the session.