Comparison
Cloudflare Bot Management vs Turnstile vs Challenge Pages
What an automated client meets on a Cloudflare site: Bot Management scores, Bot Fight Mode, Turnstile widgets and challenge pages, and what each one needs.
By ZeroCaptcha Engineering5 min readPublished Updated
Cloudflare has three layers an automated client can meet, and each needs something different.
Bot Management scores every request from 1 to 99 and lets the site owner’s rules block,
challenge or allow by score; nothing is shown unless a rule acts. A challenge page (“Just a
moment…”) is what such a rule, or Bot Fight Mode, or a WAF rule, shows instead of the page; it
ends in a cf_clearance cookie. A Cloudflare Turnstile widget sits inside the site’s own form
and ends in a token the site’s server verifies. Knowing which one you are looking at decides
whether you need a token, a clearance, or a conversation with the site owner.
The three side by side
| Bot Management and Bot Fight Mode | Challenge page | Cloudflare Turnstile widget | |
|---|---|---|---|
| What it is | Scoring of every request, and the rules that act on the score | A full page shown before the site’s page | A widget in the site’s own HTML form |
| Who decides it is used | The site’s plan and settings | A WAF rule, rate limiting rule, Bot Fight Mode, Super Bot Fight Mode or Under Attack mode | The site’s developer, per form |
| Needs the site on Cloudflare’s network | Yes | Yes | No: “Turnstile can be used independently” |
| What passing produces | Nothing visible; a better score | A cf_clearance cookie |
A token for cf-turnstile-response |
| Checked by | Cloudflare, on every request | Cloudflare, on every request while the cookie lasts | The site’s own server, through siteverify |
| What automation needs | Requests that look like the browser they claim to be | A browser that passes, or a cf_clearance cookie with its user agent |
A token for the widget’s sitekey |
Bot Management: the score behind the scenes
Cloudflare’s bot score “is a score from 1 to 99 that indicates how likely that request came from a bot”: 1 means Cloudflare “is quite certain the request was automated”, 99 that it came from a human. Cloudflare groups scores as automated (1), likely automated (2 to 29) and likely human (30 to 99), with verified bots, such as search engine crawlers, in a group of their own.
The score comes from several detection engines:
- Heuristics give high-confidence automated requests a score of 1. A request “with a missing or
empty
User-Agentheader” is scored 1 immediately. - Machine learning produces most scores between 2 and 99 and accounts for most detections.
- JavaScript detections identify headless browsers and other malicious fingerprints; they run in
HTML page responses and store their result in the
cf_clearancecookie for 15 minutes. - JA3 and JA4 fingerprints identify TLS clients by how they start a connection. They, and the granular scores, are available to Enterprise customers who bought Bot Management.
A score does nothing by itself. The site owner writes rules on it, such as “challenge requests
scoring below 30”. The __cf_bm cookie, set on sites with Bot Management or Bot Fight Mode, keeps
the score steady across a visitor’s requests; it expires after 30 minutes of inactivity.
Bot Fight Mode and Super Bot Fight Mode
Sites without Enterprise Bot Management get simpler versions:
- Bot Fight Mode (the Free plan) detects “simple bots from cloud hosting providers and headless browsers” and “issues computationally expensive challenges”. It cannot be bypassed or skipped with WAF custom rules.
- Super Bot Fight Mode (Pro, Business, and Enterprise without Bot Management) lets the owner choose to allow, block or challenge each category. Pro detects simple bots and headless browsers; Business adds “many sophisticated bots” and a likely-automated category.
For a scraper, the consequence is plain: requests from a cloud server, or from a headless browser, may be challenged on a site that turned these features on, whatever the rest of the request looks like. Choosing proxies covers the network side.
Challenge pages: when a rule acts
When a rule’s action is a challenge, Cloudflare returns an interstitial page instead of the site’s
page: HTTP 403 with a cf-mitigated: challenge header. Its type is a Managed Challenge (Cloudflare
picks what to show), a Non-Interactive Challenge (js_challenge, often called the JS Challenge) or an Interactive
Challenge. Passing it earns a cf_clearance cookie, valid for the site’s Challenge Passage time, 30
minutes by default, which later requests carry instead of being challenged again. Cloudflare says
the cookie “is securely tied to the specific visitor and device it was issued to”.
Cloudflare challenge types compares the three.
For automation, ZeroCaptcha’s challenge task passes the page through your own proxy and returns the cf_clearance cookie with the user agent to send it with. See the Cloudflare WAF and 5-second challenge solver.
Cloudflare Turnstile: a widget in the site’s own form
Turnstile runs on the same challenge platform (“the same underlying technology powering
Turnstile”), but the site places it inside its own page, usually a login, sign-up or contact form.
The widget produces a token that the form posts as cf-turnstile-response, and the site’s server
checks it with Cloudflare’s siteverify API. The token is valid for 300 seconds and for one check.
The site does not need to be on Cloudflare’s network at all.
A site can combine the two with pre-clearance: its Turnstile widget then also issues a
cf_clearance cookie that lets later requests skip challenge rules. See
Cloudflare Turnstile pre-clearance.
For automation, the widget needs a token for its sitekey. A solving API produces one without a browser passing the widget: see the Cloudflare Turnstile solver and Cloudflare Turnstile token explained.
Which one are you facing?
- The response is the site’s page, with a widget in a form: Turnstile. Look for
class="cf-turnstile"or a script fromchallenges.cloudflare.com/turnstile. - The response is a “Just a moment…” page with HTTP 403 and
cf-mitigated: challenge: a challenge page. - The response is an error page with a code such as 1020, 1015 or 1010: a rule blocked the request outright. No token or clearance helps; see Cloudflare error 1020, error 1015 and error 1010.
- Everything loads, but results are thinner or slower than in a browser: Bot Management may be scoring your requests low and the site treating them differently. Only the site owner can see the score.
Automate only sites you are allowed to: see responsible captcha automation.
Sources
- Cloudflare bots: bot score, detection engines, JA3 and JA4 fingerprints, Bot Fight Mode, Super Bot Fight Mode and what each plan detects: Free, Pro and Business (checked 1 October 2026).
- Cloudflare challenges: overview, challenge pages, Challenge Passage, clearance and JavaScript detections, detecting a challenge response, Error 403 and Under Attack mode (checked 1 October 2026).
- Cloudflare cookies,
for
__cf_bmandcf_clearance(checked 1 October 2026). - Cloudflare Turnstile overview and plans (checked 1 October 2026).
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.