CAPTCHA Solving 16 min read

EndCaptcha Review: Prices, Speed and Coverage

EndCaptcha review with figures read from the vendor's own pages on 10 August 2026: $4.00–$4.79 per 1,000 credits, three supported challenge types, an SLA that excludes reCAPTCHA v2, and a plain-HTTP API.

ST
Scraping.Pro Team
Data collection for business needs
Published: 21 February 2026

Cloudflare serves its Turnstile widget and challenge pages 7.67 billion times a day. The figure is Cloudflare's own, published on 27 February 2026, and it has climbed steeply: 2.14 billion a day in 2023, 3 billion in 2024, 5.35 billion in 2025. None of them is a picture of warped letters, because Cloudflare stopped issuing visual puzzles in 2023. EndCaptcha cannot solve a single one of them.

That is the awkward shape of an EndCaptcha review in 2026. The service solves three things: text images, reCAPTCHA v2, and reCAPTCHA v3. Its published API specification documents exactly two values for the type parameter, 4 for v2 and 5 for v3, on top of the plain image upload. There is no fourth thing.

Where these numbers come from. Everything below was read on 10 August 2026 from EndCaptcha's own site, its API specification, the extension stores, and public DNS. We did not fund an account, so nothing here measures live solving performance. Where the vendor publishes nothing, we say so instead of guessing.

What a credit costs

EndCaptcha sells credits in four packages, and publishes no per-solve rate, no per-type rate, and no statement of how many credits any particular challenge consumes. The packages are the only prices on the site:

Package Price Credits Per 1,000 credits
Starter $11.99 3,000 $4.00
Big Dreams $43.99 10,000 $4.40
Pro-Marketer $149.99 35,000 $4.29
Guru $479.01 100,000 $4.79

The right-hand column is division, not a vendor claim, and it produces the first surprise. The volume discount runs backwards. The cheapest credit sits in the smallest package, the most expensive in the largest, twenty percent above Starter. Committing $479 up front costs more per unit than spending $11.99.

Now the rest of the market, in USD per 1,000 solves, read from each vendor's own pricing or API documentation on 10 August 2026. A dash means the type is not offered at all.

Service Image / text reCAPTCHA v2 reCAPTCHA v3 Turnstile
CapMonster Cloud $0.30 $0.60 $0.90 $1.30
CapSolver $0.40 $0.80 $1.00 $1.20
Anti-Captcha $0.50–0.70 $0.95–2.00 $1.00–2.00 $2.00
2Captcha $0.50–1.00 $1.00–2.99 $1.45–2.99 $1.45
DeathByCaptcha $0.99–2.00 $2.89 $2.89 $2.89
EndCaptcha $4.00–4.79 $4.00–4.79 $4.00–4.79

The EndCaptcha row assumes one credit per solve, which the site never confirms. If a reCAPTCHA token costs more, that row is generous.

Read across the first column and the marketing story does not survive. On plain image work EndCaptcha is about thirteen times CapMonster Cloud and four to ten times 2Captcha. Distorted text is the most commoditized job in this market, and no argument about quality supports that spread.

Read down the reCAPTCHA v3 column and be fairer. 2Captcha charges $1.45 for a v3 token at a score threshold of 0.3 or below and $2.99 above it, and Anti-Captcha tiers the same way. EndCaptcha charges one flat price whatever score you ask for, and its API makes min_score a required parameter rather than a pricing tier. Against a target that demands a high score, the premium narrows to roughly one and a half times. That is the one column where the pricing has a rationale.

Three challenge types, and what that leaves out

Absent entirely: Cloudflare Turnstile, hCaptcha, GeeTest, DataDome, Arkose Labs FunCaptcha, AWS WAF, and every regional engine. That is not a gap at the edge of the product. It is most of the modern web.

Turnstile. Cloudflare's managed mode is free with no volume cap, and the widget embeds on sites that do not route traffic through Cloudflare at all. That combination is why it reached 7.67 billion daily impressions in three years. If your target sits behind it, EndCaptcha has nothing to sell you.

hCaptcha. Still an independent product of Intuition Machines, at $139 a month, or $99 billed annually, for 100,000 evaluations with $0.99 per 1,000 overage. One claim that keeps circulating in competing roundups deserves killing here: hCaptcha has not been the Cloudflare default since 2023. Cloudflare's own Turnstile GA announcement of 29 September 2023 says it had "finished replacing every CAPTCHA issued by Cloudflare with Turnstile" and would "never issue another visual puzzle to anyone, for any reason." A site showing you hCaptcha chose hCaptcha.

reCAPTCHA, which EndCaptcha does cover, is itself moving. Google's classic verification documentation now carries a deprecation banner pointing at reCAPTCHA Enterprise, and the product sells as Essentials, Premium and Enterprise: free to 10,000 assessments per organization, then $8 flat to 100,000, then $1 per 1,000. Site owners are being steered into Google Cloud, and the solver market follows whatever comes out of that.

Three supported types in a market with a dozen live ones decides most purchases before price enters the conversation.

The SLA, read line by line

The hero line reads, verbatim: "The only Captcha solution with a service level agreement." Close enough to true among solving services, and the reason anyone would consider paying four dollars a thousand. So read the terms, not the headline.

The speed standard. "Approximately 70% of all images are decoded with-in 7-8 seconds on average. The remainder is also guaranteed to be decoded with-in 11 seconds max." Slowness Insurance triggers above 11 seconds.

The compensation. "The amount of Compensatory Credits will be the result of multiplying the Compensation Coverage Level percentage with the amount of quantifiable times the Quality Standards are not met." Compensation is credits, never money. A service that fails to deliver repays you in more of the thing it failed to deliver.

The coverage ladder. Starter buys no Slowness Insurance and no Outage Insurance at all. Big Dreams buys 50% of each, Pro-Marketer 60% slowness and 80% outage, and only the $479.01 Guru package reaches 80% and 100%. The differentiator you are paying for does not exist on the entry plan.

The exclusions. Outage Insurance skips maintenance announced at least 12 hours ahead and "deliberate attacks to our service," and claims must be opened at outage@endcaptcha.com "with-in 72 hours of the outage occurring." Compensatory, promotional and free credits sit outside the agreement, so the 1,000 free trial credits carry no guarantee.

And the exclusion that matters. Slowness Insurance does not cover what EndCaptcha calls Unsupported Images: challenges that are "usually unreadable, math problems, or have a lengthy amount of characters." Then the site adds one more sentence. "The same exception applies for the Recaptcha V2 challenges."

The speed guarantee, the entire reason for the premium, covers easy distorted text and explicitly excludes reCAPTCHA v2, the type most buyers are shopping for. Nothing published bounds how long a reCAPTCHA solve may take.

Seven seconds against a market that moved

Treat the 11-second ceiling generously first. A pipeline that finishes in 11 seconds every time is easier to size than one averaging 5 seconds with a long tail, and timeouts, retry budgets and worker pools all get simpler when the worst case is a published number.

Now compare it. Anti-Captcha's homepage shows a flat "5 s" against every challenge type. CapSolver's documentation advertises under 1 second for image-to-text and under 3 seconds for reCAPTCHA v3 and Turnstile. DeathByCaptcha publishes a live status endpoint; on 10 August 2026 https://api.dbcapi.me/api/status returned is_service_overloaded=0&todays_accuracy=1.0&solved_in=10&status=0. Every one of those is self-reported marketing, EndCaptcha's included, and none is an independent measurement. What can be said is that a 7-to-11-second band is mid-pack against what competitors advertise, not the front of the field.

The arithmetic matters more than the ranking. Ten thousand image solves at the 11-second ceiling, run strictly one at a time, is 30.6 hours. Run twenty in parallel and it is 92 minutes. The ceiling is a concurrency budget, not a latency figure, and it sets how many browser sessions you keep warm while you wait. On a crawl where every page carries a challenge, solver latency rather than bandwidth decides your machine count.

The API, and the part that should stop you

The interface is small and old-fashioned in a way that is mostly fine. POST /upload with multipart/form-data, GET /poll/<captcha_id>, plus /balance and /report. Responses are plain text with string prefixes: an unsolved job returns UNSOLVED_YET:/poll/captcha_id, failures ERROR:NOT ENOUGH BALANCE, ERROR:SERVICE EXTREMELY LOADED, ERROR:INVALD CREDENTIALS and eight others. The misspelling in that last one is the specification's, not ours. Do not poll faster than once every three seconds.

Every documented endpoint is http://. Not one URL on the API specification page uses TLS, and the page never mentions SSL, TLS or HTTPS. Requesting https://api.endcaptcha.com/ on 10 August 2026 gets a TLS handshake and then a certificate that is not valid for that hostname. The main site's certificate is fine. The API host's is not.

Authentication is your account username and password. No API key, no revocable token, no authtoken parameter. DeathByCaptcha, whose API EndCaptcha mirrors, added exactly such a token years ago; 2Captcha has used a plain key over HTTPS from the start. Here the credentials that log into your billing dashboard travel in the clear on every solve, from every machine in your fleet.

This is not an oversight. It is load-bearing. EndCaptcha's migration feature works by pointing a competitor's hostname at EndCaptcha's servers through an "API Tunneler" download or a hosts-file edit. Certificate validation would break that instantly, because the certificate presented would not match the name the client thinks it is calling. Plain HTTP is what makes the headline feature possible. A coherent trade, and one no security review in 2026 signs off on.

Code below transcribes the published specification against Python 3.11 and requests, and has not been run against a funded account.

python
import requests, time

API  = "http://api.endcaptcha.com"      # the spec documents no https endpoint
AUTH = {"username": "USER", "password": "PASS"}

def solve_image(path, poll_every=3, deadline=60):
    with open(path, "rb") as f:
        body = requests.post(f"{API}/upload", data=AUTH,
                             files={"image": f}, timeout=30).text.strip()
    started = time.time()
    while True:
        if body.startswith("ERROR:"):
            raise RuntimeError(body)
        if not body.startswith("UNSOLVED_YET:"):
            return body                 # the answer, as plain text
        if time.time() - started > deadline:
            raise TimeoutError(f"no answer after {deadline}s")
        time.sleep(poll_every)           # the spec forbids polling faster
        poll_path = body.split(":", 1)[1]        # "/poll/<captcha_id>"
        body = requests.get(f"{API}{poll_path}", timeout=30).text.strip()

For reCAPTCHA the image field gives way to type and a token_params document carrying googlekey and pageurl, with action and min_score also required for v3, plus optional proxy and proxytype. Read that last note twice: "for now only http proxies are supported." If your residential pool speaks SOCKS5, you cannot bind a token to it here.

The migration path, and the hostname that is not there

The most quoted feature is drop-in compatibility, and the API page states it plainly: "EndCaptcha supports the API specs defined to work with DeathByCaptcha, Decaptcher, and Antigate." DeathByCaptcha users are told to "reconfigure your client scripts with your EndCaptcha credentials" and point them at dbc.endcaptcha.com.

On 10 August 2026 that hostname does not resolve. A query to Google Public DNS returns Status: 3, NXDOMAIN, for both the A and CNAME records, and the authority section shows the answer coming from cloe.ns.cloudflare.com, the zone's own nameserver. That is the authoritative answer, not a resolver artifact, and the check takes one command anyone can repeat. Meanwhile api.endcaptcha.com resolves normally, to 185.141.165.4 and 93.127.141.130, the same pair the website answers on.

So the documented DeathByCaptcha path is broken, and what is left is the hosts-file route: resolve the competitor's hostname to those two IPs yourself. That works, and it is exactly why the API cannot use TLS.

The third emulated API deserves a sentence of its own. DeCaptcher, one of the founding names of this market, is gone: its domain now serves unrelated filler about survey rewards, and the www host presents a certificate that does not match its own name. The scheme outlived the company that invented it, and DeathByCaptcha still ships a DeCaptcher layer. That is what compatibility here really buys. Not loyalty, portability.

Corrections to the earlier version of this review

Older write-ups repeat things about EndCaptcha the vendor's own pages do not support. This article's previous version repeated three of them.

  • "Single-digit second solving times." The published guarantee is 7 to 8 seconds for roughly 70% of images and a ceiling of 11 seconds for the rest. The number carrying the SLA is double-digit, and reCAPTCHA v2 sits outside it.
  • "Case-sensitive and picture challenges at no surcharge." The site offers case-sensitive decoding "upon request" and publishes nothing about a surcharge either way. No "confident" challenge type appears on the site or in the API specification.
  • "We are deliberately not quoting exact figures." They are published, on the front page, and have been the whole time. Declining to quote a price is a disservice when the price is the finding.

An SLA is not a guarantee until you read what it excludes, and this one excludes the challenge type most people buy a solver for.

Signs of life

A review should say whether anyone is home. The evidence points two ways at once.

Moving: the blog carries posts dated 5 October 2025, 20 November 2025, 17 December 2025, 18 March 2026 and 12 April 2026. The site answers, the main certificate is valid, login and registration work.

Not moving: sitemap.xml stamps every one of its six URLs with a lastmod of 2024-05-10, and the API page describes itself as "Latest EndCaptcha API version: 1.1 - Last modified by 06/01/23." SDKs are zip files downloaded from the site, not packages: Python v3, .NET Core v6, Java, Node.js, and an iMacros client still at v1.0. There is no endcaptcha package on npm, which returns a plain 404, while 2Captcha's official Node client published version 1.3.8 on 25 June 2026. The iMacros SDK is a period piece in itself: the newest release on Progress's own iMacros page is called iMacros 2021.

The browser extensions are the least flattering datum. The Firefox add-on is at 2.0.3, updated 18 November 2025, with 2 users. The Chrome extension is at 2.0.2, updated 20 November 2025, with 58 users and one rating of one star. Take that for what it is worth and no more: an extension is not an API business, and those counters say nothing about server-side volume. They are also the only usage numbers visible from outside, and the site's claim to be "ready to sustain tens of millions of submissions per day" has nothing public behind it.

Support runs through help@endcaptcha.com with a target of "48 business hours or less" and a live chat staffed Monday to Friday, 10:00–16:00 GMT-4. Six working days is a long time to sit on a stalled pipeline.

The lights are on and the storefront is maintained. The product surface has not moved in two years.

Where it still fits, and where it stops

It fits in a narrow place, and the place is real.

You have a legacy target that throws classic distorted text, volume is modest, and you own an integration written years ago against the DeathByCaptcha or Antigate scheme that you would rather not reopen. The price gap is then small in absolute terms: 20,000 solves a month is about $88 at EndCaptcha against about $6 at CapMonster Cloud's text rate, and $82 a month is less than an hour of engineering. Take the 1,000 free credits and measure your own targets.

It stops in four places, each a hard stop rather than a preference.

  • Any target using Turnstile, hCaptcha, GeeTest, DataDome, Arkose or AWS WAF. Not slower or dearer. Absent.
  • Anywhere a password cannot cross the network in the clear. That rules out most workplaces with a security review, and all of them with a compliance one.
  • Volume. At a million solves a month the gap is roughly $4,400 against $300. The rounding error becomes the budget.
  • Tight token deadlines. A reCAPTCHA response token is valid for two minutes and verifiable only once, per Google's own documentation, and a stale one returns timeout-or-duplicate. EndCaptcha publishes no ceiling on reCAPTCHA solve time and excludes it from the speed guarantee, so under load you are running an unbounded number against a 120-second clock.

Buying the outcome instead of the token

Most CAPTCHA comparisons skip the product category that often wins. Unblocker APIs take a URL and return rendered HTML, absorbing proxy rotation, JavaScript, fingerprinting and challenges internally. You never handle a token.

The arithmetic is public. Scrapfly sells 200,000 credits for $30, and an anti-scraping-protection request over datacenter IPs costs 5 credits, so a thousand successful pages is $0.75 at the entry tier and $0.45 at the $500 plan, with failed requests unbilled. Compare that with a $4.40 EndCaptcha credit plus the proxies, browser and retry logic you still have to build around it.

The token API wins in one common situation: when the solved challenge has to travel inside a session you control. Logins, checkouts, form posts. If you need the page and not the token, price the unblockers first.

Before you buy any solver

A solver removes the challenge in front of you and does nothing about why it appeared. The 2024 COMPSAC paper Breaking reCAPTCHAv2, by Plesner, Vontobel and Wattenhofer at ETH Zurich, solved 100% of challenges with YOLO-based segmentation against 68–71% in earlier work, and found reCAPTCHA v2 "heavily based on cookie and browser history data," with no meaningful difference in how many challenges humans and bots must work through. The puzzle is theatre layered over a fingerprint check.

A site challenging you constantly is describing your request profile, not your eyesight. Well-managed rotating proxies, a browser fingerprint that matches the traffic it claims to be, and pacing that does not spike keep most challenges from firing. Reading how the target's anti-scraping protection scores you is cheaper than paying four dollars a thousand to lose the argument afterwards. Rotate inside a session, though, and you break the IP binding those tokens depend on.

The direction of travel makes this more pressing. The IETF chartered a Web Bot Auth working group to standardize cryptographic authentication of automated clients, with milestones dated 30 April 2026 and 31 August 2026. Cloudflare's April 2026 post Moving past bots vs. humans argues the framing itself is wrong: "What the origin cares about is not humanity in the abstract, but whether the client is behaving in ways the site can support." A signed, well-behaved client is starting to get through the front door with no challenge at all. That path runs through no solver of any brand.

Verdict

EndCaptcha is alive, small, honest about its own terms if you read them, and priced four to thirteen times the market for the work it does best. Its one genuine differentiator, the service level agreement, excludes reCAPTCHA v2 and does not exist on the entry package. Its second, drop-in compatibility with DeathByCaptcha, points at a hostname that no longer resolves, and the workaround depends on an API that cannot use TLS while your account password crosses the network on every request.

For classic image work on a legacy target with a DeathByCaptcha-shaped integration and low volume, it is defensible, and the free credits cost nothing to test. For anything else in 2026, 2Captcha covers more types, CapMonster Cloud and CapSolver cost a fraction, and all three use HTTPS with a revocable key. Our walkthrough of solving CAPTCHAs from C# through DeathByCaptcha covers the compatibility angle in code.

Solving is the symptom, not the strategy. Sites that fight back at scale are where a managed web scraping service earns its keep, because by then the solver bill is the smallest line in the budget, and where the finished dataset rather than the pipeline is the point, data as a service is the other way to buy it. Benchmark speed, accuracy and true cost per solve on your own targets before committing to anyone's rate card, this article's tables included.