# Cloudflare Error 1010: Banned Based on Your Browser's Signature

> Cloudflare error 1010 comes from Browser Integrity Check. What it looks for, what an HTTP client should send, and what only the site owner can change.

- Source: https://zerocaptcha.io/blog/cloudflare-error-1010
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

Cloudflare error 1010, "The owner of this website has banned your access based on your browser's
signature", means the site's Browser Integrity Check refused your request. The check is on by
default; it "looks for common HTTP headers abused most commonly by spammers and denies access to
your page", and "challenges visitors without a user agent or with a non-standard user agent". For an
HTTP client, the fix is to send a real, consistent `User-Agent` with ordinary headers. Beyond that,
only the site owner can change it, by turning the check off or skipping it for some paths.

Only automate sites you are allowed to: your own, a client's, or one whose terms permit it. See
[responsible captcha automation](https://zerocaptcha.io/guides/responsible-captcha-automation).

## What Browser Integrity Check looks at

Cloudflare's documentation for error 1010 (checked 1 October 2026) gives the cause as "A website
owner blocked your request based on your client's web browser." The feature behind it is Browser
Integrity Check, and Cloudflare describes it in two sentences:

- It "looks for common HTTP headers abused most commonly by spammers and denies access to your
  page."
- It "also challenges visitors without a user agent or with a non-standard user agent such as
  commonly used by abusive bots, crawlers, or visitors."

Cloudflare does not publish which headers it looks for, or what counts as a non-standard user
agent. So a request can meet the check in two ways: a refusal with error 1010, or a challenge page.

A separate Cloudflare product points the same way. Bot Management's documentation says "Requests
with a missing or empty `User-Agent` header are immediately assigned a bot score of **1**", the
score for a request Cloudflare is "quite certain" was automated. That is a different feature from
Browser Integrity Check, with its own rules, but both treat a missing user agent as a strong
signal.

## What an HTTP client sends by default

Your HTTP library sends headers of its own unless you set them. Print what it sends before you
guess. In Python with `requests`:

```python
import requests

print(requests.Session().headers)
```

With requests 2.32.5 on our machine, that printed a `User-Agent` of `python-requests/2.32.5`, an
`Accept` of `*/*`, and two other headers. Whether Cloudflare counts a library's own user agent as
non-standard isn't documented, but it is not a browser's. With curl, `curl -v` prints each request
header on a line that starts with `>`:

```sh
curl -sv -o /dev/null https://example.com/ 2>&1 | grep '^> '
```

## What to send instead

- **A real `User-Agent`, never an empty one.** Use the user agent of the browser you actually run,
  or, for an HTTP client, one you send deliberately and can defend. If you drive a real browser
  with Playwright or Selenium, leave its own user agent alone.
- **The same user agent for the whole session.** Cloudflare lists "a User Agent that changes during
  the session" among the causes of failed challenges in WebViews, and describes the `cf_clearance`
  cookie as "securely tied to the specific visitor and device it was issued to." Pick one and keep
  it.
- **Ordinary headers that agree with it.** A request that claims to be a browser but sends none of
  the headers a browser sends is a mixed signal. Set `Accept` and `Accept-Language` the way a
  browser would for the page you request, and don't invent headers.
- **No forged identities.** Don't claim to be a search engine's crawler or another verified bot.
  Cloudflare's verified bots are ones it has confirmed are "transparent about who it is and what it
  does"; impersonating one is dishonest, whatever it does to your request.

If you run an honest crawler that names itself in its user agent, the check may still refuse it.
In that case the fix is not a disguise but the owner's exemption, described next.

## What the site owner can change

Browser Integrity Check "is enabled by default". Cloudflare documents three ways for an owner to
change it:

1. Turn it off for the whole zone under **Security > Settings**, with the Browser integrity check
   toggle.
2. Skip it for some traffic with a WAF custom rule using the Skip action.
3. Turn it on or off for parts of a site with a configuration rule, matching on hostname or URL
   path.

Cloudflare's 1010 page sends visitors to the site owner, suggesting a Whois lookup to find a
contact, not to Cloudflare. For a partner integration or your own monitor, ask the owner for option
2 or 3 on the paths you use, rather than asking them to turn the check off for everyone.

## When the problem is not error 1010

- **Error 1020** is a firewall rule the owner wrote, which may match the user agent among other
  things. See [Cloudflare error 1020](https://zerocaptcha.io/blog/cloudflare-error-1020) and [Cloudflare WAF rules
  explained](https://zerocaptcha.io/blog/cloudflare-waf-rules-explained).
- **A "Just a moment..." page** is a challenge, not a block, and Browser Integrity Check is one of
  the features that issue them. A browser can pass it; a plain HTTP client can't, because it runs no
  JavaScript. See [Cloudflare challenge types](https://zerocaptcha.io/blog/cloudflare-challenge-types) and the [Cloudflare
  challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver).

A Cloudflare Turnstile token does not change your client's signature, so a CAPTCHA solver,
ZeroCaptcha included, does nothing for error 1010. If your scraper also submits forms protected by
Cloudflare Turnstile, [Cloudflare Turnstile for web scraping](https://zerocaptcha.io/guides/cloudflare-turnstile-web-scraping)
covers that part, and the [httpx tutorial](https://zerocaptcha.io/blog/python-httpx-cloudflare-turnstile) shows a Python
client that keeps one session and one set of headers.

## Sources

- [Cloudflare: Error 1010](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-1xxx-errors/error-1010/) (checked 1 October 2026)
- [Cloudflare: Browser Integrity Check](https://developers.cloudflare.com/waf/tools/browser-integrity-check/) (checked 1 October 2026)
- [Cloudflare: Bot detection engines](https://developers.cloudflare.com/bots/concepts/bot-detection-engines/) and [bot score](https://developers.cloudflare.com/bots/concepts/bot-score/) (checked 1 October 2026)
- [Cloudflare: Verified bots](https://developers.cloudflare.com/bots/concepts/bot/verified-bots/) (checked 1 October 2026)
- [Cloudflare: Challenge solve issues](https://developers.cloudflare.com/cloudflare-challenges/troubleshooting/challenge-solve-issues/) (checked 1 October 2026)
- [Cloudflare: Clearance](https://developers.cloudflare.com/cloudflare-challenges/concepts/clearance/) (checked 1 October 2026)

## Questions

### What causes Cloudflare error 1010?

The site's Browser Integrity Check refused your request based on your client's signature. The check looks for HTTP headers commonly abused by spammers and challenges clients with no user agent or a non-standard one.

### How do I fix Cloudflare error 1010 in Python requests or curl?

Send a real, consistent User-Agent and ordinary request headers, and never an empty User-Agent. If the site still refuses your client, only the owner can change that.

### Can the site owner turn off Browser Integrity Check?

Yes. It is on by default and can be turned off under Security > Settings, or skipped for chosen hostnames or paths with a custom rule's Skip action or a configuration rule.
