Explainer
Cloudflare Managed vs Non-Interactive vs Interactive Challenge
Cloudflare's three challenge types, including the one called JS Challenge: what each does, who issues it, which clearance passes which, and what bots meet.
By ZeroCaptcha Engineering6 min readPublished Updated
Cloudflare has three challenge types. A Non-Interactive Challenge (API value js_challenge,
which is why it is often still called the JS Challenge) needs nothing from the visitor but the JavaScript their browser runs,
which “typically takes less than five seconds.” A Managed Challenge (managed_challenge) lets
Cloudflare choose the challenge for each request, and “Most human visitors are automatically
verified.” An Interactive Challenge (challenge) requires the visitor to interact. Cloudflare
recommends the Managed Challenge for most rules, and passing any of them earns a cf_clearance
cookie at that challenge’s level.
Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.
The three types side by side
All three are shown as an interstitial challenge page, which Cloudflare describes as “a full-page screen that appears before the visitor reaches the destination URL”. Cloudflare also states that it “does not use CAPTCHA puzzles or visual tests like selecting objects or typing distorted characters.”
| Non-Interactive Challenge | Managed Challenge | Interactive Challenge | |
|---|---|---|---|
| API value | js_challenge |
managed_challenge |
challenge |
| Also called | JS Challenge, after its API value | ||
| What the visitor does | Waits while the browser runs JavaScript | Usually nothing; sometimes an interaction such as a click | Interacts with the challenge |
| Cloudflare’s advice | Use only for specific compatibility needs | “Cloudflare recommends Managed Challenges for most WAF rules” | “Cloudflare always recommends using a Managed Challenge” |
In Cloudflare’s rules-language docs, the Non-Interactive Challenge means “The client that made the request must pass a non-interactive Cloudflare challenge before proceeding”, and the Managed Challenge can “Show a non-interactive challenge page” or “Show a custom interactive challenge (such as click a button)”, chosen “based on the characteristics of a request”. Cloudflare says the Managed Challenge “Helps reduce the lifetimes of human time spent solving CAPTCHAs across the Internet.”
Who issues a challenge
Cloudflare’s “How challenges work” page (checked 1 October 2026) maps products to challenge types:
| Product | What it issues |
|---|---|
| WAF: custom rules, rate limiting rules, IP Access rules | Interstitial Challenge Page |
| Bot Fight Mode, Super Bot Fight Mode | Interstitial Challenge Page |
| Under Attack mode | Managed Challenge |
| HTTP DDoS attack protection | Any challenge |
| Bot Management | JavaScript Detections |
| Cloudflare Turnstile | An embedded widget |
In a WAF rule, the owner picks the challenge type as the rule’s action. Bot Fight Mode, on the Free plan, “Issues computationally expensive challenges”. Under Attack mode, which Cloudflare calls one of the last resorts for a zone under attack, presents a Managed Challenge page. Browser Integrity Check challenges visitors “without a user agent or with a non-standard user agent”.
Two items in that table are not challenge pages. JavaScript Detections run quietly inside HTML pages and don’t stop a request unless a WAF rule uses their result. Cloudflare Turnstile is a widget a site puts in its own pages; see Cloudflare challenge page vs Cloudflare Turnstile. “Challenge Pages and Turnstile rely on the same underlying mechanism”, Cloudflare’s Challenge Platform.
Clearance levels
Passing a challenge gives the browser a cf_clearance cookie, which “proves to Cloudflare that the
visitor is a verified human and has passed Cloudflare’s client-side verifications.” The cookie
carries a clearance level, and a higher level passes lower challenges:
| Clearance earned | Passes these challenges without a new one |
|---|---|
| Interactive (high) | Interactive, Managed, Non-Interactive |
| Managed (medium) | Managed, Non-Interactive |
| Non-Interactive (low) | Non-Interactive only |
A lower clearance does not pass a higher challenge: a visitor cleared by a Non-Interactive Challenge who then requests a path protected by a Managed Challenge rule is challenged again.
How long a clearance lasts is the zone’s Challenge Passage setting: “By default, the
cf_clearance cookie has a lifetime of 30 minutes. Cloudflare recommends a setting between 15 and
45 minutes.” Clearance can end earlier: it “remains valid for the duration configured by the
customer (Challenge Passage), unless Precursor determines the session is suspicious.” And “The
Challenge Passage does not apply to rate limiting rules.”
A site can also hand out clearance from a Cloudflare Turnstile widget, with pre-clearance. The
widget’s clearance level is set to interactive, managed, jschallenge or no_clearance, the
default. See Cloudflare Turnstile pre-clearance.
What each type means for an automated client
Some points apply to all three:
- The response is recognizable. Every Challenge Page response has “the
cf-mitigatedheader present and set tochallenge”, with content typetext/htmlwhatever you requested. In a live check on 30 September 2026 (our observation, not a documented guarantee), a Managed Challenge page came back with HTTP 403 and the title “Just a moment…”. - A JavaScript engine is required. Cloudflare lists “Command-line tools such as
wget,curl, or others that lack JavaScript execution capabilities” as unsupported, and says “Browser automation frameworks, such as Selenium, Puppeteer, Playwright, and Cypress, are not supported for solving production challenges.” - Non-HTML requests break. Challenge pages don’t work as answers to fetch or XHR calls, so an API client that meets one gets an HTML page it can’t use.
- The address must stay the same. A Managed Challenge solve sent from a different IP than the one the challenge was issued to is not valid, and can cause a challenge loop.
And by type:
- Non-Interactive Challenge: no click, but the page’s scripts must run to completion in a browser environment Cloudflare accepts. The resulting clearance is the lowest level.
- Managed Challenge: the outcome depends on the request. The same client may pass without interaction one time and be asked to click another. The clearance covers Managed and Non-Interactive rules.
- Interactive Challenge: always needs an interaction, and its clearance is the only one that covers every challenge type.
None of the three is a block. A Block action denies matching requests outright, and no clearance lifts it; see Cloudflare WAF rules explained for how the actions differ. A Cloudflare Turnstile token doesn’t pass a challenge page either: it belongs in a site’s own form.
For sites you may automate, ZeroCaptcha’s challenge task passes a challenge page through your proxy and returns the cf_clearance cookie with the user agent it is bound to. See the Cloudflare WAF and 5-second challenge solver and the cf_clearance cookie explained.
Try each type
The Cloudflare WAF managed challenge test page, the Cloudflare 5-second JS challenge test page and the Cloudflare WAF interactive challenge test page each sit behind a rule of that type, and show whether your browser holds a clearance.
Sources
- Cloudflare: Challenges overview (checked 1 October 2026)
- Cloudflare: Interstitial Challenge Pages (checked 1 October 2026)
- Cloudflare: How challenges work (checked 1 October 2026)
- Cloudflare: Clearance (checked 1 October 2026)
- Cloudflare: Challenge Passage (checked 1 October 2026)
- Cloudflare: Detect a Challenge Page response (checked 1 October 2026)
- Cloudflare: Supported browsers (checked 1 October 2026)
- Cloudflare: Rules language actions (checked 1 October 2026)
- Cloudflare: Bot Fight Mode (checked 1 October 2026)
- Cloudflare: Under Attack mode (checked 1 October 2026)
- Cloudflare: Browser Integrity Check (checked 1 October 2026)
- Cloudflare Turnstile: Pre-clearance (checked 1 October 2026)
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.