# Cloudflare Managed vs Non-Interactive vs Interactive Challenge

> Cloudflare's three challenge types, including the one called JS Challenge: what each does, who issues it, which clearance passes which, and what bots meet.

- Source: https://zerocaptcha.io/blog/cloudflare-challenge-types
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

Cloudflare has three challenge types. A **Non-Interactive Challenge** (API value `js_challenge`,
which is why it is often still called the JS Challenge) needs nothing from the visitor but the JavaScript their browser runs,
which "typically takes less than five seconds." A **Managed Challenge** (`managed_challenge`) lets
Cloudflare choose the challenge for each request, and "Most human visitors are automatically
verified." An **Interactive Challenge** (`challenge`) requires the visitor to interact. Cloudflare
recommends the Managed Challenge for most rules, and passing any of them earns a `cf_clearance`
cookie at that challenge's level.

Only automate sites you are allowed to: your own, a client's, or one whose terms permit it. See
[responsible captcha automation](https://zerocaptcha.io/guides/responsible-captcha-automation).

## The three types side by side

All three are shown as an interstitial challenge page, which Cloudflare describes as "a full-page
screen that appears before the visitor reaches the destination URL". Cloudflare also states that it
"does not use CAPTCHA puzzles or visual tests like selecting objects or typing distorted
characters."

| | Non-Interactive Challenge | Managed Challenge | Interactive Challenge |
| --- | --- | --- | --- |
| API value | `js_challenge` | `managed_challenge` | `challenge` |
| Also called | JS Challenge, after its API value | | |
| What the visitor does | Waits while the browser runs JavaScript | Usually nothing; sometimes an interaction such as a click | Interacts with the challenge |
| Cloudflare's advice | Use only for specific compatibility needs | "Cloudflare recommends Managed Challenges for most WAF rules" | "Cloudflare always recommends using a Managed Challenge" |

In Cloudflare's rules-language docs, the Non-Interactive Challenge means "The client that made the
request must pass a non-interactive Cloudflare challenge before proceeding", and the Managed
Challenge can "Show a non-interactive challenge page" or "Show a custom interactive challenge (such
as click a button)", chosen "based on the characteristics of a request". Cloudflare says the Managed
Challenge "Helps reduce the lifetimes of human time spent solving CAPTCHAs across the Internet."

## Who issues a challenge

Cloudflare's "How challenges work" page (checked 1 October 2026) maps products to challenge types:

| Product | What it issues |
| --- | --- |
| WAF: custom rules, rate limiting rules, IP Access rules | Interstitial Challenge Page |
| Bot Fight Mode, Super Bot Fight Mode | Interstitial Challenge Page |
| Under Attack mode | Managed Challenge |
| HTTP DDoS attack protection | Any challenge |
| Bot Management | JavaScript Detections |
| Cloudflare Turnstile | An embedded widget |

In a WAF rule, the owner picks the challenge type as the rule's action. Bot Fight Mode, on the Free
plan, "Issues computationally expensive challenges". Under Attack mode, which Cloudflare calls one of
the last resorts for a zone under attack, presents a Managed Challenge page. Browser Integrity
Check challenges visitors "without a user agent or with a non-standard user agent".

Two items in that table are not challenge pages. JavaScript Detections run quietly inside HTML
pages and don't stop a request unless a WAF rule uses their result. Cloudflare Turnstile is a
widget a site puts in its own pages; see [Cloudflare challenge page vs Cloudflare
Turnstile](https://zerocaptcha.io/guides/cloudflare-challenge-vs-turnstile). "Challenge Pages and Turnstile rely on the
same underlying mechanism", Cloudflare's Challenge Platform.

## Clearance levels

Passing a challenge gives the browser a `cf_clearance` cookie, which "proves to Cloudflare that the
visitor is a verified human and has passed Cloudflare's client-side verifications." The cookie
carries a clearance level, and a higher level passes lower challenges:

| Clearance earned | Passes these challenges without a new one |
| --- | --- |
| Interactive (high) | Interactive, Managed, Non-Interactive |
| Managed (medium) | Managed, Non-Interactive |
| Non-Interactive (low) | Non-Interactive only |

A lower clearance does not pass a higher challenge: a visitor cleared by a Non-Interactive
Challenge who then requests a path protected by a Managed Challenge rule is challenged again.

How long a clearance lasts is the zone's **Challenge Passage** setting: "By default, the
`cf_clearance` cookie has a lifetime of 30 minutes. Cloudflare recommends a setting between 15 and
45 minutes." Clearance can end earlier: it "remains valid for the duration configured by the
customer (Challenge Passage), unless Precursor determines the session is suspicious." And "The
Challenge Passage does not apply to rate limiting rules."

A site can also hand out clearance from a Cloudflare Turnstile widget, with pre-clearance. The
widget's clearance level is set to `interactive`, `managed`, `jschallenge` or `no_clearance`, the
default. See [Cloudflare Turnstile pre-clearance](https://zerocaptcha.io/blog/cloudflare-turnstile-pre-clearance).

## What each type means for an automated client

Some points apply to all three:

- **The response is recognizable.** Every Challenge Page response has "the `cf-mitigated` header
  present and set to `challenge`", with content type `text/html` whatever you requested. In a live
  check on 30 September 2026 (our observation, not a documented guarantee), a Managed Challenge
  page came back with HTTP 403 and the title "Just a moment...".
- **A JavaScript engine is required.** Cloudflare lists "Command-line tools such as `wget`, `curl`,
  or others that lack JavaScript execution capabilities" as unsupported, and says "Browser
  automation frameworks, such as Selenium, Puppeteer, Playwright, and Cypress, are not supported
  for solving production challenges."
- **Non-HTML requests break.** Challenge pages don't work as answers to fetch or XHR calls, so an
  API client that meets one gets an HTML page it can't use.
- **The address must stay the same.** A Managed Challenge solve sent from a different IP than the
  one the challenge was issued to is not valid, and can cause a [challenge
  loop](https://zerocaptcha.io/blog/cloudflare-challenge-loop).

And by type:

- **Non-Interactive Challenge:** no click, but the page's scripts must run to completion in a
  browser environment Cloudflare accepts. The resulting clearance is the lowest level.
- **Managed Challenge:** the outcome depends on the request. The same client may pass without
  interaction one time and be asked to click another. The clearance covers Managed and
  Non-Interactive rules.
- **Interactive Challenge:** always needs an interaction, and its clearance is the only one that
  covers every challenge type.

None of the three is a block. A Block action denies matching requests outright, and no clearance
lifts it; see [Cloudflare WAF rules explained](https://zerocaptcha.io/blog/cloudflare-waf-rules-explained) for how the
actions differ. A Cloudflare Turnstile token doesn't pass a challenge page either: it belongs in a
site's own form.

For sites you may automate,
ZeroCaptcha's challenge task passes a challenge page through your proxy and returns the cf_clearance cookie with the user agent it is bound to.
See the [Cloudflare WAF and 5-second challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver) and [the cf_clearance cookie
explained](https://zerocaptcha.io/guides/cf-clearance-cookie-explained).

## Try each type

The [Cloudflare WAF managed challenge test page](https://zerocaptcha.io/captcha-test/cloudflare-managed-challenge), the
[Cloudflare 5-second JS challenge test page](https://zerocaptcha.io/captcha-test/cloudflare-js-challenge) and the
[Cloudflare WAF interactive challenge test page](https://zerocaptcha.io/captcha-test/cloudflare-interactive-challenge) each
sit behind a rule of that type, and show whether your browser holds a clearance.

## Sources

- [Cloudflare: Challenges overview](https://developers.cloudflare.com/cloudflare-challenges/) (checked 1 October 2026)
- [Cloudflare: Interstitial Challenge Pages](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/) (checked 1 October 2026)
- [Cloudflare: How challenges work](https://developers.cloudflare.com/cloudflare-challenges/concepts/how-challenges-work/) (checked 1 October 2026)
- [Cloudflare: Clearance](https://developers.cloudflare.com/cloudflare-challenges/concepts/clearance/) (checked 1 October 2026)
- [Cloudflare: Challenge Passage](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/challenge-passage/) (checked 1 October 2026)
- [Cloudflare: Detect a Challenge Page response](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/detect-response/) (checked 1 October 2026)
- [Cloudflare: Supported browsers](https://developers.cloudflare.com/cloudflare-challenges/reference/supported-browsers/) (checked 1 October 2026)
- [Cloudflare: Rules language actions](https://developers.cloudflare.com/ruleset-engine/rules-language/actions/) (checked 1 October 2026)
- [Cloudflare: Bot Fight Mode](https://developers.cloudflare.com/bots/get-started/bot-fight-mode/) (checked 1 October 2026)
- [Cloudflare: Under Attack mode](https://developers.cloudflare.com/fundamentals/reference/under-attack-mode/) (checked 1 October 2026)
- [Cloudflare: Browser Integrity Check](https://developers.cloudflare.com/waf/tools/browser-integrity-check/) (checked 1 October 2026)
- [Cloudflare Turnstile: Pre-clearance](https://developers.cloudflare.com/turnstile/additional-configuration/hostname-management/pre-clearance/) (checked 1 October 2026)

## Questions

### Is the Cloudflare Non-Interactive Challenge the same as the JS Challenge?

Yes. Cloudflare's docs call it the Non-Interactive Challenge, and its API value is js_challenge, which is why many tools still say JS Challenge.

### Which Cloudflare challenge type should a site use?

Cloudflare recommends the Managed Challenge for most WAF rules and says not to use the other challenge types unless there are specific compatibility issues.

### Does passing one Cloudflare challenge clear the others?

Only at the same level or lower. An Interactive clearance passes Interactive, Managed and Non-Interactive challenges; a Managed clearance passes Managed and Non-Interactive; a Non-Interactive clearance passes only Non-Interactive.
