Unlike the self-hosted math/code/grid challenges, the answer here never lives in your DOM โ hCaptcha hands back an opaque token that only the vendor can validate server-side. Your automation cannot forge it; it has to drive the real widget and then read the token it produces.
This is the second vendor in the set. The pattern generalizes across providers: switch into the widget iframe, trigger the challenge, then extract the response token from the host page โ the exact same shape you used for reCAPTCHA. Only the iframe origin and the global name (window.hcaptcha vs window.grecaptcha) change.
Mode: practice โ the published TEST sitekey always passes, so the flow is fully automatable end to end.