Bypassing reCAPTCHA and hCaptcha for Automated Testing in Okta is Not Supported
Last Updated:
Overview
Okta does not support bypassing the Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) for automation and security scan testing because the security feature applies universally to all traffic. Workarounds include temporarily disabling CAPTCHA during test runs or configuring a separate test environment without CAPTCHA enabled.
Applies To
- Okta Identity Engine (OIE)
- reCAPTCHA (Google)
- hCaptcha
- Automated Testing
Cause
Okta CAPTCHA is a core security feature that applies universally to all traffic. Okta does not offer a configuration to exclude automation tools while selectively maintaining security for end-user traffic.
Solution
What are the workarounds for automated testing?
Implement one of the following workarounds to allow automated testing.
- Temporarily disable CAPTCHA during test runs.
- Configure a separate test environment without CAPTCHA enabled.
NOTE: Test any changes in a preview environment before applying them to production.
How can Okta Administrators submit a feature request through the Okta Ideas portal?
Submit an idea for consideration in the Okta Product Roadmap to request a feature that allows bypassing CAPTCHA for automated testing. For more information, refer to How to Submit a Feature or Enhancement Request using Okta Ideas.
