Troubleshooting
Cloudflare Challenge Loop: Why 'Just a moment...' Repeats
Why a Cloudflare 'Just a moment...' page keeps coming back: the documented causes, IP changes mid-solve, lost cookies, clocks, and fixes for code.
By ZeroCaptcha Engineering6 min readPublished Updated
A Cloudflare challenge loop is a “Just a moment…” page that comes back after every attempt
instead of letting you through. Cloudflare lists five causes: network issues, browser configuration
(settings or extensions that block its scripts), unsupported browsers, JavaScript disabled, and
detection errors. Automated clients meet a few more: a solve sent from a different IP than the one
the challenge was issued to, a cf_clearance cookie that is never sent back (CORS preflight
requests never carry it), a wrong device clock, and a clearance whose Challenge Passage time has
run out.
Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.
How a challenge is supposed to end
A challenge page is issued by a WAF rule (custom, rate limiting or IP Access), by Bot Fight Mode or
Super Bot Fight Mode, by Under Attack mode, or by HTTP DDoS protection. The browser runs Cloudflare’s scripts, passes, and receives a
cf_clearance cookie, which Cloudflare’s cookie list describes as storing “the proof of challenge
passed. It is used to no longer issue a challenge if present.” A loop means that last step keeps
failing: the solve is rejected, or the cookie is missing or not accepted on the next request.
The causes Cloudflare lists
Cloudflare’s challenge troubleshooting page (checked 1 October 2026) names these:
- Network issues: “Poor or unstable network connections can prevent the challenge from being completed.”
- Browser configuration: “Some browser settings or extensions may block the scripts needed to
execute the challenge.” Cloudflare also says it can’t support extensions “that modify the
browser’s
User-Agentvalue or Web APIs such asCanvasandWebGL.” - Unsupported browsers. Cloudflare’s supported-browsers page rules out Internet Explorer,
“Command-line tools such as
wget,curl, or others that lack JavaScript execution capabilities”, and “Browser automation frameworks, such as Selenium, Puppeteer, Playwright, and Cypress”, which “are not supported for solving production challenges.” - JavaScript disabled: “Visitors must enable JavaScript and cookies on their browser to be able to pass any type of Challenge.”
- Detection errors: “If Turnstile suspects bot-like behavior, you may encounter repeated challenges for verification.” (Challenge pages run on the same Challenge Platform as Cloudflare Turnstile, which is why the page names it.)
Cloudflare adds one owner-side cause on its challenge pages overview: “Using Cloudflare Challenges along with Rules features may cause challenge loops.”
Causes automated clients hit
The solve came from a different IP address
Cloudflare’s docs are specific: when “the solve request of a Managed Challenge comes from a different IP than the original IP a Challenge request was issued to”, the solve is not valid, and “you may encounter a Challenge loop.” A proxy that rotates its exit address per connection does exactly this. Use a sticky session that lasts for the whole visit; choosing proxies explains the settings.
The cookie never comes back
The clearance only works if the next request carries it. Common ways to lose it:
- A client with no cookie jar, or a new session for each request.
- CORS preflight requests. Cloudflare’s troubleshooting page notes that “Cross-origin resource
sharing (CORS) preflight requests, or
OPTIONS, exclude user credentials that include cookies”, so a preflight is challenged even when the visitor holds a clearance. - Fetch and XHR calls. Challenge pages don’t work as answers to non-HTML requests, which is why Cloudflare recommends Cloudflare Turnstile pre-clearance for single-page apps and APIs.
- Cookie attributes. Cloudflare sets
cf_clearancewithSameSite=None; Secure; Partitioned, and over plain HTTP it defaults toSameSite=Lax. A cookie store that mishandles these may not send it back. Cloudflare also doesn’t support challenge pages inside cross-origin iframes.
The user agent changed
Cloudflare describes the cookie as “securely tied to the specific visitor and device it was issued to”, and lists “a User Agent that changes during the session” among the causes of failed challenges in WebViews. Keep one user agent for the whole session, including every request that uses the cookie.
The clock is wrong
A live challenge page we loaded on 30 September 2026 carries the strings “Incorrect device time”
and “This error occurs when your device’s clock or calendar is inaccurate.” Cloudflare Turnstile’s
error codes, from the same Challenge Platform, include 200100: “The visitor’s clock is wrong or
the challenge was cached by an intermediary.” If your client runs in a container or a virtual
machine, check its clock and keep it synchronized with NTP.
The clearance ran out
A clearance lasts for the zone’s Challenge Passage: “By default, the cf_clearance cookie has a
lifetime of 30 minutes. Cloudflare recommends a setting between 15 and 45 minutes.” It can end
sooner: the challenge clearance “remains valid for the duration configured by the customer
(Challenge Passage), unless Precursor determines the session is suspicious.” A clearance also only
covers challenges at or below its level, so a page that asks for a stricter challenge than the one
you passed challenges you again. See Cloudflare challenge types.
Fixes for people
Cloudflare’s own list, for a person stuck in a browser:
- Use a supported browser and update it.
- Disable browser extensions, ad blockers first.
- Enable JavaScript and cookies.
- Try an incognito or private window.
- Try a different browser or device.
- Turn off a VPN or proxy temporarily to test.
- Switch to a different network.
If none of that works, the challenge is the site’s setting: “Cloudflare employees cannot remove that Challenge. Only the website owner can”. A related message has its own article: Please unblock challenges.cloudflare.com.
Fixes for automated clients
- One IP address and one user agent per session, from the first request to the last one that uses the cookie.
- Keep cookies. Use one session object with a cookie jar for the whole visit.
- Detect challenges by header, not by HTML. Cloudflare documents that every Challenge Page
response has “the
cf-mitigatedheader present and set tochallenge”, and that “the content-type of a challenge will betext/html” regardless of what was requested. - Stop on a challenge. Without a clearance, the rule that challenged the request matches the next one too. Treat a challenge as a signal to fix the session, not to retry in a loop.
A minimal check in Python with requests:
import requests
def is_cloudflare_challenge(response): return response.headers.get("cf-mitigated") == "challenge"
session = requests.Session()response = session.get("https://shop.example.com/", timeout=30)if is_cloudflare_challenge(response): print("Cloudflare challenge page, HTTP", response.status_code)else: print("Page served, HTTP", response.status_code)When a challenge appears on a site you may automate, you need a clearance earned from the same address and user agent you will use. ZeroCaptcha’s challenge task passes the page through your proxy and returns the cf_clearance cookie with the user agent it is bound to, so you can keep one address and one user agent throughout. See the Cloudflare WAF and 5-second challenge solver and the cf_clearance cookie explained. If you drive a real browser, Playwright and the Cloudflare challenge covers what changes there.
Sources
- Cloudflare: Challenge solve issues (checked 1 October 2026)
- Cloudflare: Challenges troubleshooting (checked 1 October 2026)
- Cloudflare: How challenges work (checked 1 October 2026)
- Cloudflare: Interstitial Challenge Pages (checked 1 October 2026)
- Cloudflare: Detect a Challenge Page response (checked 1 October 2026)
- Cloudflare: Challenge Passage (checked 1 October 2026)
- Cloudflare: Clearance (checked 1 October 2026)
- Cloudflare: Supported browsers (checked 1 October 2026)
- Cloudflare: Resolve a challenge (checked 1 October 2026)
- Cloudflare: Cookies (checked 1 October 2026)
- Cloudflare: SameSite cookie interaction (checked 1 October 2026)
- Cloudflare Turnstile: Client-side error codes (checked 1 October 2026)
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.