Skip to content

Comparison

Cloudflare Bot Management vs Turnstile vs Challenge Pages

What an automated client meets on a Cloudflare site: Bot Management scores, Bot Fight Mode, Turnstile widgets and challenge pages, and what each one needs.

By 5 min readPublished Updated

Cloudflare has three layers an automated client can meet, and each needs something different. Bot Management scores every request from 1 to 99 and lets the site owner’s rules block, challenge or allow by score; nothing is shown unless a rule acts. A challenge page (“Just a moment…”) is what such a rule, or Bot Fight Mode, or a WAF rule, shows instead of the page; it ends in a cf_clearance cookie. A Cloudflare Turnstile widget sits inside the site’s own form and ends in a token the site’s server verifies. Knowing which one you are looking at decides whether you need a token, a clearance, or a conversation with the site owner.

The three side by side

Bot Management and Bot Fight Mode Challenge page Cloudflare Turnstile widget
What it is Scoring of every request, and the rules that act on the score A full page shown before the site’s page A widget in the site’s own HTML form
Who decides it is used The site’s plan and settings A WAF rule, rate limiting rule, Bot Fight Mode, Super Bot Fight Mode or Under Attack mode The site’s developer, per form
Needs the site on Cloudflare’s network Yes Yes No: “Turnstile can be used independently”
What passing produces Nothing visible; a better score A cf_clearance cookie A token for cf-turnstile-response
Checked by Cloudflare, on every request Cloudflare, on every request while the cookie lasts The site’s own server, through siteverify
What automation needs Requests that look like the browser they claim to be A browser that passes, or a cf_clearance cookie with its user agent A token for the widget’s sitekey

Bot Management: the score behind the scenes

Cloudflare’s bot score “is a score from 1 to 99 that indicates how likely that request came from a bot”: 1 means Cloudflare “is quite certain the request was automated”, 99 that it came from a human. Cloudflare groups scores as automated (1), likely automated (2 to 29) and likely human (30 to 99), with verified bots, such as search engine crawlers, in a group of their own.

The score comes from several detection engines:

  • Heuristics give high-confidence automated requests a score of 1. A request “with a missing or empty User-Agent header” is scored 1 immediately.
  • Machine learning produces most scores between 2 and 99 and accounts for most detections.
  • JavaScript detections identify headless browsers and other malicious fingerprints; they run in HTML page responses and store their result in the cf_clearance cookie for 15 minutes.
  • JA3 and JA4 fingerprints identify TLS clients by how they start a connection. They, and the granular scores, are available to Enterprise customers who bought Bot Management.

A score does nothing by itself. The site owner writes rules on it, such as “challenge requests scoring below 30”. The __cf_bm cookie, set on sites with Bot Management or Bot Fight Mode, keeps the score steady across a visitor’s requests; it expires after 30 minutes of inactivity.

Bot Fight Mode and Super Bot Fight Mode

Sites without Enterprise Bot Management get simpler versions:

  • Bot Fight Mode (the Free plan) detects “simple bots from cloud hosting providers and headless browsers” and “issues computationally expensive challenges”. It cannot be bypassed or skipped with WAF custom rules.
  • Super Bot Fight Mode (Pro, Business, and Enterprise without Bot Management) lets the owner choose to allow, block or challenge each category. Pro detects simple bots and headless browsers; Business adds “many sophisticated bots” and a likely-automated category.

For a scraper, the consequence is plain: requests from a cloud server, or from a headless browser, may be challenged on a site that turned these features on, whatever the rest of the request looks like. Choosing proxies covers the network side.

Challenge pages: when a rule acts

When a rule’s action is a challenge, Cloudflare returns an interstitial page instead of the site’s page: HTTP 403 with a cf-mitigated: challenge header. Its type is a Managed Challenge (Cloudflare picks what to show), a Non-Interactive Challenge (js_challenge, often called the JS Challenge) or an Interactive Challenge. Passing it earns a cf_clearance cookie, valid for the site’s Challenge Passage time, 30 minutes by default, which later requests carry instead of being challenged again. Cloudflare says the cookie “is securely tied to the specific visitor and device it was issued to”. Cloudflare challenge types compares the three.

For automation, ZeroCaptcha’s challenge task passes the page through your own proxy and returns the cf_clearance cookie with the user agent to send it with. See the Cloudflare WAF and 5-second challenge solver.

Cloudflare Turnstile: a widget in the site’s own form

Turnstile runs on the same challenge platform (“the same underlying technology powering Turnstile”), but the site places it inside its own page, usually a login, sign-up or contact form. The widget produces a token that the form posts as cf-turnstile-response, and the site’s server checks it with Cloudflare’s siteverify API. The token is valid for 300 seconds and for one check. The site does not need to be on Cloudflare’s network at all.

A site can combine the two with pre-clearance: its Turnstile widget then also issues a cf_clearance cookie that lets later requests skip challenge rules. See Cloudflare Turnstile pre-clearance.

For automation, the widget needs a token for its sitekey. A solving API produces one without a browser passing the widget: see the Cloudflare Turnstile solver and Cloudflare Turnstile token explained.

Which one are you facing?

  1. The response is the site’s page, with a widget in a form: Turnstile. Look for class="cf-turnstile" or a script from challenges.cloudflare.com/turnstile.
  2. The response is a “Just a moment…” page with HTTP 403 and cf-mitigated: challenge: a challenge page.
  3. The response is an error page with a code such as 1020, 1015 or 1010: a rule blocked the request outright. No token or clearance helps; see Cloudflare error 1020, error 1015 and error 1010.
  4. Everything loads, but results are thinner or slower than in a browser: Bot Management may be scoring your requests low and the site treating them differently. Only the site owner can see the score.

Automate only sites you are allowed to: see responsible captcha automation.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

What is the difference between Cloudflare Bot Management and Turnstile?

Bot Management scores every request to a site from 1 to 99 and lets the owner's rules act on the score. Turnstile is a widget a site puts in a form, which produces a token the site's server verifies. Bot Management works on the request; Turnstile works on one form submission.

Is a Cloudflare challenge page the same as Turnstile?

They run on the same challenge platform, but a challenge page is shown by a rule before the site's page loads and ends in a cf_clearance cookie, while a Turnstile widget sits inside the site's own page and ends in a token.

What does a bot score of 1 mean?

Cloudflare is quite certain the request was automated. A score of 99 means it is quite certain the request came from a human. Requests with a missing or empty User-Agent header get a score of 1.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key