# Cloudflare Bot Management vs Turnstile vs Challenge Pages

> What an automated client meets on a Cloudflare site: Bot Management scores, Bot Fight Mode, Turnstile widgets and challenge pages, and what each one needs.

- Source: https://zerocaptcha.io/blog/cloudflare-bot-management-vs-turnstile
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

Cloudflare has three layers an automated client can meet, and each needs something different.
**Bot Management** scores every request from 1 to 99 and lets the site owner's rules block,
challenge or allow by score; nothing is shown unless a rule acts. A **challenge page** ("Just a
moment...") is what such a rule, or Bot Fight Mode, or a WAF rule, shows instead of the page; it
ends in a `cf_clearance` cookie. A **Cloudflare Turnstile widget** sits inside the site's own form
and ends in a token the site's server verifies. Knowing which one you are looking at decides
whether you need a token, a clearance, or a conversation with the site owner.

## The three side by side

| | Bot Management and Bot Fight Mode | Challenge page | Cloudflare Turnstile widget |
| --- | --- | --- | --- |
| What it is | Scoring of every request, and the rules that act on the score | A full page shown before the site's page | A widget in the site's own HTML form |
| Who decides it is used | The site's plan and settings | A WAF rule, rate limiting rule, Bot Fight Mode, Super Bot Fight Mode or Under Attack mode | The site's developer, per form |
| Needs the site on Cloudflare's network | Yes | Yes | No: "Turnstile can be used independently" |
| What passing produces | Nothing visible; a better score | A `cf_clearance` cookie | A token for `cf-turnstile-response` |
| Checked by | Cloudflare, on every request | Cloudflare, on every request while the cookie lasts | The site's own server, through siteverify |
| What automation needs | Requests that look like the browser they claim to be | A browser that passes, or a `cf_clearance` cookie with its user agent | A token for the widget's sitekey |

## Bot Management: the score behind the scenes

Cloudflare's bot score "is a score from 1 to 99 that indicates how likely that request came from a
bot": 1 means Cloudflare "is quite certain the request was automated", 99 that it came from a
human. Cloudflare groups scores as automated (1), likely automated (2 to 29) and likely human (30
to 99), with verified bots, such as search engine crawlers, in a group of their own.

The score comes from several detection engines:

- **Heuristics** give high-confidence automated requests a score of 1. A request "with a missing or
  empty `User-Agent` header" is scored 1 immediately.
- **Machine learning** produces most scores between 2 and 99 and accounts for most detections.
- **JavaScript detections** identify headless browsers and other malicious fingerprints; they run in
  HTML page responses and store their result in the `cf_clearance` cookie for 15 minutes.
- **JA3 and JA4 fingerprints** identify TLS clients by how they start a connection. They, and the
  granular scores, are available to Enterprise customers who bought Bot Management.

A score does nothing by itself. The site owner writes rules on it, such as "challenge requests
scoring below 30". The `__cf_bm` cookie, set on sites with Bot Management or Bot Fight Mode, keeps
the score steady across a visitor's requests; it expires after 30 minutes of inactivity.

## Bot Fight Mode and Super Bot Fight Mode

Sites without Enterprise Bot Management get simpler versions:

- **Bot Fight Mode** (the Free plan) detects "simple bots from cloud hosting providers and headless
  browsers" and "issues computationally expensive challenges". It cannot be bypassed or skipped
  with WAF custom rules.
- **Super Bot Fight Mode** (Pro, Business, and Enterprise without Bot Management) lets the owner
  choose to allow, block or challenge each category. Pro detects simple bots and headless
  browsers; Business adds "many sophisticated bots" and a likely-automated category.

For a scraper, the consequence is plain: requests from a cloud server, or from a headless browser,
may be challenged on a site that turned these features on, whatever the rest of the request looks
like. [Choosing proxies](https://zerocaptcha.io/blog/proxies-for-cloudflare-turnstile) covers the network side.

## Challenge pages: when a rule acts

When a rule's action is a challenge, Cloudflare returns an interstitial page instead of the site's
page: HTTP 403 with a `cf-mitigated: challenge` header. Its type is a Managed Challenge (Cloudflare
picks what to show), a Non-Interactive Challenge (`js_challenge`, often called the JS Challenge) or an Interactive
Challenge. Passing it earns a `cf_clearance` cookie, valid for the site's Challenge Passage time, 30
minutes by default, which later requests carry instead of being challenged again. Cloudflare says
the cookie "is securely tied to the specific visitor and device it was issued to".
[Cloudflare challenge types](https://zerocaptcha.io/blog/cloudflare-challenge-types) compares the three.

For automation, ZeroCaptcha's challenge task passes the page through your own proxy and returns the cf_clearance cookie with the user agent to send it with.
See the [Cloudflare WAF and 5-second challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver).

## Cloudflare Turnstile: a widget in the site's own form

Turnstile runs on the same challenge platform ("the same underlying technology powering
Turnstile"), but the site places it inside its own page, usually a login, sign-up or contact form.
The widget produces a token that the form posts as `cf-turnstile-response`, and the site's server
checks it with Cloudflare's siteverify API. The token is valid for 300 seconds and for one check.
The site does not need to be on Cloudflare's network at all.

A site can combine the two with pre-clearance: its Turnstile widget then also issues a
`cf_clearance` cookie that lets later requests skip challenge rules. See
[Cloudflare Turnstile pre-clearance](https://zerocaptcha.io/blog/cloudflare-turnstile-pre-clearance).

For automation, the widget needs a token for its sitekey. A solving API produces one without a
browser passing the widget: see the [Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver) and
[Cloudflare Turnstile token explained](https://zerocaptcha.io/blog/cloudflare-turnstile-token).

## Which one are you facing?

1. **The response is the site's page, with a widget in a form:** Turnstile. Look for
   `class="cf-turnstile"` or a script from `challenges.cloudflare.com/turnstile`.
2. **The response is a "Just a moment..." page with HTTP 403 and `cf-mitigated: challenge`:** a
   challenge page.
3. **The response is an error page with a code such as 1020, 1015 or 1010:** a rule blocked the
   request outright. No token or clearance helps; see [Cloudflare error 1020](https://zerocaptcha.io/blog/cloudflare-error-1020),
   [error 1015](https://zerocaptcha.io/blog/cloudflare-error-1015) and [error 1010](https://zerocaptcha.io/blog/cloudflare-error-1010).
4. **Everything loads, but results are thinner or slower than in a browser:** Bot Management may be
   scoring your requests low and the site treating them differently. Only the site owner can see
   the score.

Automate only sites you are allowed to: see
[responsible captcha automation](https://zerocaptcha.io/guides/responsible-captcha-automation).

## Sources

- Cloudflare bots: [bot score](https://developers.cloudflare.com/bots/concepts/bot-score/),
  [detection engines](https://developers.cloudflare.com/bots/concepts/bot-detection-engines/),
  [JA3 and JA4 fingerprints](https://developers.cloudflare.com/bots/additional-configurations/ja3-ja4-fingerprint/),
  [Bot Fight Mode](https://developers.cloudflare.com/bots/get-started/bot-fight-mode/),
  [Super Bot Fight Mode](https://developers.cloudflare.com/bots/get-started/super-bot-fight-mode/)
  and what each plan detects: [Free](https://developers.cloudflare.com/bots/plans/free/),
  [Pro](https://developers.cloudflare.com/bots/plans/pro/) and
  [Business](https://developers.cloudflare.com/bots/plans/biz-and-ent/) (checked 1 October 2026).
- Cloudflare challenges: [overview](https://developers.cloudflare.com/cloudflare-challenges/),
  [challenge pages](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/),
  [Challenge Passage](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/challenge-passage/),
  [clearance](https://developers.cloudflare.com/cloudflare-challenges/concepts/clearance/) and
  [JavaScript detections](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/javascript-detections/),
  [detecting a challenge response](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/detect-response/),
  [Error 403](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/4xx-client-error/error-403/)
  and [Under Attack mode](https://developers.cloudflare.com/fundamentals/reference/under-attack-mode/)
  (checked 1 October 2026).
- [Cloudflare cookies](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/),
  for `__cf_bm` and `cf_clearance` (checked 1 October 2026).
- [Cloudflare Turnstile overview](https://developers.cloudflare.com/turnstile/) and
  [plans](https://developers.cloudflare.com/turnstile/plans/) (checked 1 October 2026).

## Questions

### What is the difference between Cloudflare Bot Management and Turnstile?

Bot Management scores every request to a site from 1 to 99 and lets the owner's rules act on the score. Turnstile is a widget a site puts in a form, which produces a token the site's server verifies. Bot Management works on the request; Turnstile works on one form submission.

### Is a Cloudflare challenge page the same as Turnstile?

They run on the same challenge platform, but a challenge page is shown by a rule before the site's page loads and ends in a cf_clearance cookie, while a Turnstile widget sits inside the site's own page and ends in a token.

### What does a bot score of 1 mean?

Cloudflare is quite certain the request was automated. A score of 99 means it is quite certain the request came from a human. Requests with a missing or empty User-Agent header get a score of 1.
