# Cloudflare Challenge Loop: Why 'Just a moment...' Repeats

> Why a Cloudflare 'Just a moment...' page keeps coming back: the documented causes, IP changes mid-solve, lost cookies, clocks, and fixes for code.

- Source: https://zerocaptcha.io/blog/cloudflare-challenge-loop
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

A Cloudflare challenge loop is a "Just a moment..." page that comes back after every attempt
instead of letting you through. Cloudflare lists five causes: network issues, browser configuration
(settings or extensions that block its scripts), unsupported browsers, JavaScript disabled, and
detection errors. Automated clients meet a few more: a solve sent from a different IP than the one
the challenge was issued to, a `cf_clearance` cookie that is never sent back (CORS preflight
requests never carry it), a wrong device clock, and a clearance whose Challenge Passage time has
run out.

Only automate sites you are allowed to: your own, a client's, or one whose terms permit it. See
[responsible captcha automation](https://zerocaptcha.io/guides/responsible-captcha-automation).

## How a challenge is supposed to end

A challenge page is issued by a WAF rule (custom, rate limiting or IP Access), by Bot Fight Mode or
Super Bot Fight Mode, by Under Attack mode, or by HTTP DDoS protection. The browser runs Cloudflare's scripts, passes, and receives a
`cf_clearance` cookie, which Cloudflare's cookie list describes as storing "the proof of challenge
passed. It is used to no longer issue a challenge if present." A loop means that last step keeps
failing: the solve is rejected, or the cookie is missing or not accepted on the next request.

## The causes Cloudflare lists

Cloudflare's challenge troubleshooting page (checked 1 October 2026) names these:

- **Network issues:** "Poor or unstable network connections can prevent the challenge from being
  completed."
- **Browser configuration:** "Some browser settings or extensions may block the scripts needed to
  execute the challenge." Cloudflare also says it can't support extensions "that modify the
  browser's `User-Agent` value or Web APIs such as `Canvas` and `WebGL`."
- **Unsupported browsers.** Cloudflare's supported-browsers page rules out Internet Explorer,
  "Command-line tools such as `wget`, `curl`, or others that lack JavaScript execution
  capabilities", and "Browser automation frameworks, such as Selenium, Puppeteer, Playwright, and
  Cypress", which "are not supported for solving production challenges."
- **JavaScript disabled:** "Visitors must enable JavaScript and cookies on their browser to be able
  to pass any type of Challenge."
- **Detection errors:** "If Turnstile suspects bot-like behavior, you may encounter repeated
  challenges for verification." (Challenge pages run on the same Challenge Platform as Cloudflare Turnstile, which
  is why the page names it.)

Cloudflare adds one owner-side cause on its challenge pages overview: "Using Cloudflare Challenges
along with Rules features may cause challenge loops."

## Causes automated clients hit

### The solve came from a different IP address

Cloudflare's docs are specific: when "the solve request of a Managed Challenge comes from a
different IP than the original IP a Challenge request was issued to", the solve is not valid, and
"you may encounter a Challenge loop." A proxy that rotates its exit address per connection does
exactly this. Use a sticky session that lasts for the whole visit;
[choosing proxies](https://zerocaptcha.io/blog/proxies-for-cloudflare-turnstile) explains the settings.

### The cookie never comes back

The clearance only works if the next request carries it. Common ways to lose it:

- A client with no cookie jar, or a new session for each request.
- **CORS preflight requests.** Cloudflare's troubleshooting page notes that "Cross-origin resource
  sharing (CORS) preflight requests, or `OPTIONS`, exclude user credentials that include cookies",
  so a preflight is challenged even when the visitor holds a clearance.
- **Fetch and XHR calls.** Challenge pages don't work as answers to non-HTML requests, which is why
  Cloudflare recommends [Cloudflare Turnstile pre-clearance](https://zerocaptcha.io/blog/cloudflare-turnstile-pre-clearance)
  for single-page apps and APIs.
- **Cookie attributes.** Cloudflare sets `cf_clearance` with `SameSite=None; Secure; Partitioned`,
  and over plain HTTP it defaults to `SameSite=Lax`. A cookie store that mishandles these may not
  send it back. Cloudflare also doesn't support challenge pages inside cross-origin iframes.

### The user agent changed

Cloudflare describes the cookie as "securely tied to the specific visitor and device it was issued
to", and lists "a User Agent that changes during the session" among the causes of failed challenges
in WebViews. Keep one user agent for the whole session, including every request that uses the
cookie.

### The clock is wrong

A live challenge page we loaded on 30 September 2026 carries the strings "Incorrect device time"
and "This error occurs when your device's clock or calendar is inaccurate." Cloudflare Turnstile's
error codes, from the same Challenge Platform, include `200100`: "The visitor's clock is wrong or
the challenge was cached by an intermediary." If your client runs in a container or a virtual
machine, check its clock and keep it synchronized with NTP.

### The clearance ran out

A clearance lasts for the zone's Challenge Passage: "By default, the `cf_clearance` cookie has a
lifetime of 30 minutes. Cloudflare recommends a setting between 15 and 45 minutes." It can end
sooner: the challenge clearance "remains valid for the duration configured by the customer
(Challenge Passage), unless Precursor determines the session is suspicious." A clearance also only
covers challenges at or below its level, so a page that asks for a stricter challenge than the one
you passed challenges you again. See [Cloudflare challenge types](https://zerocaptcha.io/blog/cloudflare-challenge-types).

## Fixes for people

Cloudflare's own list, for a person stuck in a browser:

1. Use a supported browser and update it.
2. Disable browser extensions, ad blockers first.
3. Enable JavaScript and cookies.
4. Try an incognito or private window.
5. Try a different browser or device.
6. Turn off a VPN or proxy temporarily to test.
7. Switch to a different network.

If none of that works, the challenge is the site's setting: "Cloudflare employees cannot remove
that Challenge. Only the website owner can". A related message has its own article: [Please
unblock challenges.cloudflare.com](https://zerocaptcha.io/blog/please-unblock-challenges-cloudflare-com).

## Fixes for automated clients

- **One IP address and one user agent per session**, from the first request to the last one that
  uses the cookie.
- **Keep cookies.** Use one session object with a cookie jar for the whole visit.
- **Detect challenges by header, not by HTML.** Cloudflare documents that every Challenge Page
  response has "the `cf-mitigated` header present and set to `challenge`", and that "the
  content-type of a challenge will be `text/html`" regardless of what was requested.
- **Stop on a challenge.** Without a clearance, the rule that challenged the request matches the
  next one too. Treat a challenge as a signal to fix the session, not to retry in a loop.

A minimal check in Python with `requests`:

```python
import requests


def is_cloudflare_challenge(response):
    return response.headers.get("cf-mitigated") == "challenge"


session = requests.Session()
response = session.get("https://shop.example.com/", timeout=30)
if is_cloudflare_challenge(response):
    print("Cloudflare challenge page, HTTP", response.status_code)
else:
    print("Page served, HTTP", response.status_code)
```

When a challenge appears on a site you may automate, you need a clearance earned from the same
address and user agent you will use. ZeroCaptcha's challenge task passes the page through your proxy and returns the cf_clearance cookie with the user agent it is bound to, so you can keep one address and one user agent throughout.
See the [Cloudflare WAF and 5-second challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver) and [the cf_clearance cookie
explained](https://zerocaptcha.io/guides/cf-clearance-cookie-explained). If you drive a real browser, [Playwright and the
Cloudflare challenge](https://zerocaptcha.io/blog/playwright-cloudflare-challenge) covers what changes there.

## Sources

- [Cloudflare: Challenge solve issues](https://developers.cloudflare.com/cloudflare-challenges/troubleshooting/challenge-solve-issues/) (checked 1 October 2026)
- [Cloudflare: Challenges troubleshooting](https://developers.cloudflare.com/cloudflare-challenges/troubleshooting/) (checked 1 October 2026)
- [Cloudflare: How challenges work](https://developers.cloudflare.com/cloudflare-challenges/concepts/how-challenges-work/) (checked 1 October 2026)
- [Cloudflare: Interstitial Challenge Pages](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/) (checked 1 October 2026)
- [Cloudflare: Detect a Challenge Page response](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/detect-response/) (checked 1 October 2026)
- [Cloudflare: Challenge Passage](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/challenge-passage/) (checked 1 October 2026)
- [Cloudflare: Clearance](https://developers.cloudflare.com/cloudflare-challenges/concepts/clearance/) (checked 1 October 2026)
- [Cloudflare: Supported browsers](https://developers.cloudflare.com/cloudflare-challenges/reference/supported-browsers/) (checked 1 October 2026)
- [Cloudflare: Resolve a challenge](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/resolve-challenge/) (checked 1 October 2026)
- [Cloudflare: Cookies](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/) (checked 1 October 2026)
- [Cloudflare: SameSite cookie interaction](https://developers.cloudflare.com/waf/troubleshooting/samesite-cookie-interaction/) (checked 1 October 2026)
- [Cloudflare Turnstile: Client-side error codes](https://developers.cloudflare.com/turnstile/troubleshooting/client-side-errors/error-codes/) (checked 1 October 2026)

## Questions

### Why does the Cloudflare 'Just a moment...' page keep coming back?

Cloudflare lists network issues, browser settings or extensions that block its scripts, unsupported browsers, disabled JavaScript and detection errors. Automated clients add their own causes: a solve sent from a different IP, a lost cf_clearance cookie, a wrong clock, or an expired clearance.

### How do I detect a Cloudflare challenge page in code?

Check the cf-mitigated response header. Cloudflare sets it to challenge on every Challenge Page response, whatever the challenge type, and the content type is text/html whatever you requested.

### Can changing IP address cause a Cloudflare challenge loop?

Yes. Cloudflare's docs say that when the solve request of a Managed Challenge comes from a different IP than the one the challenge was issued to, the solve is not valid and you may encounter a challenge loop.
