Skip to content

Explainer

Cloudflare Managed vs Non-Interactive vs Interactive Challenge

Cloudflare's three challenge types, including the one called JS Challenge: what each does, who issues it, which clearance passes which, and what bots meet.

By 6 min readPublished Updated

Cloudflare has three challenge types. A Non-Interactive Challenge (API value js_challenge, which is why it is often still called the JS Challenge) needs nothing from the visitor but the JavaScript their browser runs, which “typically takes less than five seconds.” A Managed Challenge (managed_challenge) lets Cloudflare choose the challenge for each request, and “Most human visitors are automatically verified.” An Interactive Challenge (challenge) requires the visitor to interact. Cloudflare recommends the Managed Challenge for most rules, and passing any of them earns a cf_clearance cookie at that challenge’s level.

Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.

The three types side by side

All three are shown as an interstitial challenge page, which Cloudflare describes as “a full-page screen that appears before the visitor reaches the destination URL”. Cloudflare also states that it “does not use CAPTCHA puzzles or visual tests like selecting objects or typing distorted characters.”

Non-Interactive Challenge Managed Challenge Interactive Challenge
API value js_challenge managed_challenge challenge
Also called JS Challenge, after its API value
What the visitor does Waits while the browser runs JavaScript Usually nothing; sometimes an interaction such as a click Interacts with the challenge
Cloudflare’s advice Use only for specific compatibility needs “Cloudflare recommends Managed Challenges for most WAF rules” “Cloudflare always recommends using a Managed Challenge”

In Cloudflare’s rules-language docs, the Non-Interactive Challenge means “The client that made the request must pass a non-interactive Cloudflare challenge before proceeding”, and the Managed Challenge can “Show a non-interactive challenge page” or “Show a custom interactive challenge (such as click a button)”, chosen “based on the characteristics of a request”. Cloudflare says the Managed Challenge “Helps reduce the lifetimes of human time spent solving CAPTCHAs across the Internet.”

Who issues a challenge

Cloudflare’s “How challenges work” page (checked 1 October 2026) maps products to challenge types:

Product What it issues
WAF: custom rules, rate limiting rules, IP Access rules Interstitial Challenge Page
Bot Fight Mode, Super Bot Fight Mode Interstitial Challenge Page
Under Attack mode Managed Challenge
HTTP DDoS attack protection Any challenge
Bot Management JavaScript Detections
Cloudflare Turnstile An embedded widget

In a WAF rule, the owner picks the challenge type as the rule’s action. Bot Fight Mode, on the Free plan, “Issues computationally expensive challenges”. Under Attack mode, which Cloudflare calls one of the last resorts for a zone under attack, presents a Managed Challenge page. Browser Integrity Check challenges visitors “without a user agent or with a non-standard user agent”.

Two items in that table are not challenge pages. JavaScript Detections run quietly inside HTML pages and don’t stop a request unless a WAF rule uses their result. Cloudflare Turnstile is a widget a site puts in its own pages; see Cloudflare challenge page vs Cloudflare Turnstile. “Challenge Pages and Turnstile rely on the same underlying mechanism”, Cloudflare’s Challenge Platform.

Clearance levels

Passing a challenge gives the browser a cf_clearance cookie, which “proves to Cloudflare that the visitor is a verified human and has passed Cloudflare’s client-side verifications.” The cookie carries a clearance level, and a higher level passes lower challenges:

Clearance earned Passes these challenges without a new one
Interactive (high) Interactive, Managed, Non-Interactive
Managed (medium) Managed, Non-Interactive
Non-Interactive (low) Non-Interactive only

A lower clearance does not pass a higher challenge: a visitor cleared by a Non-Interactive Challenge who then requests a path protected by a Managed Challenge rule is challenged again.

How long a clearance lasts is the zone’s Challenge Passage setting: “By default, the cf_clearance cookie has a lifetime of 30 minutes. Cloudflare recommends a setting between 15 and 45 minutes.” Clearance can end earlier: it “remains valid for the duration configured by the customer (Challenge Passage), unless Precursor determines the session is suspicious.” And “The Challenge Passage does not apply to rate limiting rules.”

A site can also hand out clearance from a Cloudflare Turnstile widget, with pre-clearance. The widget’s clearance level is set to interactive, managed, jschallenge or no_clearance, the default. See Cloudflare Turnstile pre-clearance.

What each type means for an automated client

Some points apply to all three:

  • The response is recognizable. Every Challenge Page response has “the cf-mitigated header present and set to challenge”, with content type text/html whatever you requested. In a live check on 30 September 2026 (our observation, not a documented guarantee), a Managed Challenge page came back with HTTP 403 and the title “Just a moment…”.
  • A JavaScript engine is required. Cloudflare lists “Command-line tools such as wget, curl, or others that lack JavaScript execution capabilities” as unsupported, and says “Browser automation frameworks, such as Selenium, Puppeteer, Playwright, and Cypress, are not supported for solving production challenges.”
  • Non-HTML requests break. Challenge pages don’t work as answers to fetch or XHR calls, so an API client that meets one gets an HTML page it can’t use.
  • The address must stay the same. A Managed Challenge solve sent from a different IP than the one the challenge was issued to is not valid, and can cause a challenge loop.

And by type:

  • Non-Interactive Challenge: no click, but the page’s scripts must run to completion in a browser environment Cloudflare accepts. The resulting clearance is the lowest level.
  • Managed Challenge: the outcome depends on the request. The same client may pass without interaction one time and be asked to click another. The clearance covers Managed and Non-Interactive rules.
  • Interactive Challenge: always needs an interaction, and its clearance is the only one that covers every challenge type.

None of the three is a block. A Block action denies matching requests outright, and no clearance lifts it; see Cloudflare WAF rules explained for how the actions differ. A Cloudflare Turnstile token doesn’t pass a challenge page either: it belongs in a site’s own form.

For sites you may automate, ZeroCaptcha’s challenge task passes a challenge page through your proxy and returns the cf_clearance cookie with the user agent it is bound to. See the Cloudflare WAF and 5-second challenge solver and the cf_clearance cookie explained.

Try each type

The Cloudflare WAF managed challenge test page, the Cloudflare 5-second JS challenge test page and the Cloudflare WAF interactive challenge test page each sit behind a rule of that type, and show whether your browser holds a clearance.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

Is the Cloudflare Non-Interactive Challenge the same as the JS Challenge?

Yes. Cloudflare's docs call it the Non-Interactive Challenge, and its API value is js_challenge, which is why many tools still say JS Challenge.

Which Cloudflare challenge type should a site use?

Cloudflare recommends the Managed Challenge for most WAF rules and says not to use the other challenge types unless there are specific compatibility issues.

Does passing one Cloudflare challenge clear the others?

Only at the same level or lower. An Interactive clearance passes Interactive, Managed and Non-Interactive challenges; a Managed clearance passes Managed and Non-Interactive; a Non-Interactive clearance passes only Non-Interactive.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key