Skip to content

Troubleshooting

Cloudflare Challenge Loop: Why 'Just a moment...' Repeats

Why a Cloudflare 'Just a moment...' page keeps coming back: the documented causes, IP changes mid-solve, lost cookies, clocks, and fixes for code.

By 6 min readPublished Updated

A Cloudflare challenge loop is a “Just a moment…” page that comes back after every attempt instead of letting you through. Cloudflare lists five causes: network issues, browser configuration (settings or extensions that block its scripts), unsupported browsers, JavaScript disabled, and detection errors. Automated clients meet a few more: a solve sent from a different IP than the one the challenge was issued to, a cf_clearance cookie that is never sent back (CORS preflight requests never carry it), a wrong device clock, and a clearance whose Challenge Passage time has run out.

Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.

How a challenge is supposed to end

A challenge page is issued by a WAF rule (custom, rate limiting or IP Access), by Bot Fight Mode or Super Bot Fight Mode, by Under Attack mode, or by HTTP DDoS protection. The browser runs Cloudflare’s scripts, passes, and receives a cf_clearance cookie, which Cloudflare’s cookie list describes as storing “the proof of challenge passed. It is used to no longer issue a challenge if present.” A loop means that last step keeps failing: the solve is rejected, or the cookie is missing or not accepted on the next request.

The causes Cloudflare lists

Cloudflare’s challenge troubleshooting page (checked 1 October 2026) names these:

  • Network issues: “Poor or unstable network connections can prevent the challenge from being completed.”
  • Browser configuration: “Some browser settings or extensions may block the scripts needed to execute the challenge.” Cloudflare also says it can’t support extensions “that modify the browser’s User-Agent value or Web APIs such as Canvas and WebGL.”
  • Unsupported browsers. Cloudflare’s supported-browsers page rules out Internet Explorer, “Command-line tools such as wget, curl, or others that lack JavaScript execution capabilities”, and “Browser automation frameworks, such as Selenium, Puppeteer, Playwright, and Cypress”, which “are not supported for solving production challenges.”
  • JavaScript disabled: “Visitors must enable JavaScript and cookies on their browser to be able to pass any type of Challenge.”
  • Detection errors: “If Turnstile suspects bot-like behavior, you may encounter repeated challenges for verification.” (Challenge pages run on the same Challenge Platform as Cloudflare Turnstile, which is why the page names it.)

Cloudflare adds one owner-side cause on its challenge pages overview: “Using Cloudflare Challenges along with Rules features may cause challenge loops.”

Causes automated clients hit

The solve came from a different IP address

Cloudflare’s docs are specific: when “the solve request of a Managed Challenge comes from a different IP than the original IP a Challenge request was issued to”, the solve is not valid, and “you may encounter a Challenge loop.” A proxy that rotates its exit address per connection does exactly this. Use a sticky session that lasts for the whole visit; choosing proxies explains the settings.

The clearance only works if the next request carries it. Common ways to lose it:

  • A client with no cookie jar, or a new session for each request.
  • CORS preflight requests. Cloudflare’s troubleshooting page notes that “Cross-origin resource sharing (CORS) preflight requests, or OPTIONS, exclude user credentials that include cookies”, so a preflight is challenged even when the visitor holds a clearance.
  • Fetch and XHR calls. Challenge pages don’t work as answers to non-HTML requests, which is why Cloudflare recommends Cloudflare Turnstile pre-clearance for single-page apps and APIs.
  • Cookie attributes. Cloudflare sets cf_clearance with SameSite=None; Secure; Partitioned, and over plain HTTP it defaults to SameSite=Lax. A cookie store that mishandles these may not send it back. Cloudflare also doesn’t support challenge pages inside cross-origin iframes.

The user agent changed

Cloudflare describes the cookie as “securely tied to the specific visitor and device it was issued to”, and lists “a User Agent that changes during the session” among the causes of failed challenges in WebViews. Keep one user agent for the whole session, including every request that uses the cookie.

The clock is wrong

A live challenge page we loaded on 30 September 2026 carries the strings “Incorrect device time” and “This error occurs when your device’s clock or calendar is inaccurate.” Cloudflare Turnstile’s error codes, from the same Challenge Platform, include 200100: “The visitor’s clock is wrong or the challenge was cached by an intermediary.” If your client runs in a container or a virtual machine, check its clock and keep it synchronized with NTP.

The clearance ran out

A clearance lasts for the zone’s Challenge Passage: “By default, the cf_clearance cookie has a lifetime of 30 minutes. Cloudflare recommends a setting between 15 and 45 minutes.” It can end sooner: the challenge clearance “remains valid for the duration configured by the customer (Challenge Passage), unless Precursor determines the session is suspicious.” A clearance also only covers challenges at or below its level, so a page that asks for a stricter challenge than the one you passed challenges you again. See Cloudflare challenge types.

Fixes for people

Cloudflare’s own list, for a person stuck in a browser:

  1. Use a supported browser and update it.
  2. Disable browser extensions, ad blockers first.
  3. Enable JavaScript and cookies.
  4. Try an incognito or private window.
  5. Try a different browser or device.
  6. Turn off a VPN or proxy temporarily to test.
  7. Switch to a different network.

If none of that works, the challenge is the site’s setting: “Cloudflare employees cannot remove that Challenge. Only the website owner can”. A related message has its own article: Please unblock challenges.cloudflare.com.

Fixes for automated clients

  • One IP address and one user agent per session, from the first request to the last one that uses the cookie.
  • Keep cookies. Use one session object with a cookie jar for the whole visit.
  • Detect challenges by header, not by HTML. Cloudflare documents that every Challenge Page response has “the cf-mitigated header present and set to challenge”, and that “the content-type of a challenge will be text/html” regardless of what was requested.
  • Stop on a challenge. Without a clearance, the rule that challenged the request matches the next one too. Treat a challenge as a signal to fix the session, not to retry in a loop.

A minimal check in Python with requests:

import requests
def is_cloudflare_challenge(response):
return response.headers.get("cf-mitigated") == "challenge"
session = requests.Session()
response = session.get("https://shop.example.com/", timeout=30)
if is_cloudflare_challenge(response):
print("Cloudflare challenge page, HTTP", response.status_code)
else:
print("Page served, HTTP", response.status_code)

When a challenge appears on a site you may automate, you need a clearance earned from the same address and user agent you will use. ZeroCaptcha’s challenge task passes the page through your proxy and returns the cf_clearance cookie with the user agent it is bound to, so you can keep one address and one user agent throughout. See the Cloudflare WAF and 5-second challenge solver and the cf_clearance cookie explained. If you drive a real browser, Playwright and the Cloudflare challenge covers what changes there.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

Why does the Cloudflare 'Just a moment...' page keep coming back?

Cloudflare lists network issues, browser settings or extensions that block its scripts, unsupported browsers, disabled JavaScript and detection errors. Automated clients add their own causes: a solve sent from a different IP, a lost cf_clearance cookie, a wrong clock, or an expired clearance.

How do I detect a Cloudflare challenge page in code?

Check the cf-mitigated response header. Cloudflare sets it to challenge on every Challenge Page response, whatever the challenge type, and the content type is text/html whatever you requested.

Can changing IP address cause a Cloudflare challenge loop?

Yes. Cloudflare's docs say that when the solve request of a Managed Challenge comes from a different IP than the one the challenge was issued to, the solve is not valid and you may encounter a challenge loop.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key