Skip to content

Troubleshooting

Cloudflare "Just a Moment" and "Checking Your Browser" Pages

What Cloudflare's "Just a moment..." and "Checking your browser" pages are, why they appear, what visitors can do, and how automation passes them.

By 5 min readPublished

“Just a moment…” is the title of Cloudflare’s interstitial challenge page, and “Checking your browser before accessing…” is its older wording, which Cloudflare’s reference still uses for the Under Attack mode page. Both mean the same thing: the site’s Cloudflare setup wants your browser to pass a challenge before the page loads. A supported browser with JavaScript and cookies on usually passes it by itself in a few seconds and gets a cf_clearance cookie, which lets it through until the site’s Challenge Passage time runs out, 30 minutes by default. A script that runs no JavaScript never passes it, however often it retries.

This article explains why the page appears, what a visitor can do, what a site owner can change, and how an automated client passes it, as Cloudflare documented it on 1 October 2026.

Why the page appears

Cloudflare shows the page when something in the site’s configuration challenges your request:

What issued it When What it shows
A WAF custom rule or rate limiting rule The request matches a rule whose action is Managed, Non-Interactive (JS) or Interactive Challenge The challenge the action names
Bot Fight Mode Cloudflare’s bot detection flags the request; it “Issues computationally expensive challenges” An interstitial challenge page
Under Attack mode The owner turned it on, usually during an attack: every visitor is challenged A Managed Challenge page
Browser Integrity Check The request has no user agent or a non-standard one A challenge

Whatever issued it, the response is the same from the outside: status 403, the header cf-mitigated: challenge, and an HTML page that loads its scripts from the site’s own /cdn-cgi/challenge-platform/ path. In our checks its title was “Just a moment…”. The old name for this page, from its JavaScript-challenge days, is the Cloudflare 5-second challenge.

A page that shows a Cloudflare error code such as 1020, with no cf-mitigated header, is not this page: it is a Block, which no browser or task can pass. The Cloudflare WAF bypass article sorts the two apart.

If you are a visitor

  • Wait a few seconds. Most browsers pass without doing anything; Cloudflare’s Managed Challenge asks for a click only some of the time.
  • Turn JavaScript and cookies on for the site. The page runs a script, and the pass is stored as the cf_clearance cookie.
  • Let the challenge’s script load. An ad blocker or a network filter that blocks challenges.cloudflare.com stops the page; see “Please unblock challenges.cloudflare.com to proceed”.
  • If it keeps coming back, Cloudflare lists network issues, browser settings or extensions that block its scripts, unsupported browsers and disabled JavaScript as the causes. The challenge loop article covers each, and the ones automated clients add.

If you run the site

The page is the owner’s own setting, so the owner can narrow it. Under Attack mode can be kept off an API or any other path with a configuration rule, as Cloudflare suggests, and a WAF custom rule with the Skip action can exempt known traffic from later rules. Partners who call your API should get a way in that needs no browser, rather than a challenge they cannot pass. Cloudflare WAF rules explained lists every action and the order they run in.

If you are automating

A client that meets “Just a moment…” should check for it, pass it once, and reuse the clearance. Only automate sites you are allowed to: see responsible captcha automation.

Detect it. The header is the reliable sign, since the status alone is shared with blocks:

// Is this response Cloudflare's "Just a moment..." page? Node.js 22 or later, as an ES module.
const response = await fetch("https://shop.example.com/", { redirect: "manual" });
if (response.headers.get("cf-mitigated") === "challenge") {
console.log("Challenge page: pass it once, then reuse the cf_clearance cookie.");
} else {
console.log(`No challenge: HTTP ${response.status}`);
}

Pass it once. ZeroCaptcha’s CloudflareChallengeTask passes the page through your own proxy and returns the cf_clearance cookie with the user agent it was issued for. Here it is in the createTask format, the one CapSolver-style clients already send, with every field a real integration sends:

// Pass a Cloudflare "Just a moment..." page with the createTask format. Node.js 22 or later,
// as an ES module (solve.mjs). Use the result through the same proxy, with the same user agent.
import { randomUUID } from "node:crypto";
const API = process.env.ZEROCAPTCHA_API ?? "https://api.zerocaptcha.io";
const KEY = process.env.ZEROCAPTCHA_KEY;
const PROXY = process.env.PROXY_URL; // such as http://user:pass@proxy.example.net:8080
if (!KEY || !PROXY) throw new Error("Set ZEROCAPTCHA_KEY and PROXY_URL.");
const post = async (path, body, headers = {}) => {
const reply = await fetch(`${API}${path}`, {
method: "POST",
headers: { "Content-Type": "application/json", ...headers },
body: JSON.stringify(body),
});
return reply.json();
};
// 1. Create the task: the page behind the challenge (websiteURL), your proxy, where to POST the
// result when the task ends (callbackUrl), and an Idempotency-Key, so a retry returns the same
// task instead of a second, paid one. A challenge page has no sitekey: there is no websiteKey.
const created = await post(
"/createTask",
{
clientKey: KEY,
task: { type: "CloudflareChallengeTask", websiteURL: "https://shop.example.com/", proxy: PROXY },
callbackUrl: "https://example.com/zerocaptcha/callback",
},
{ "Idempotency-Key": randomUUID() },
);
if (created.errorId !== 0) throw new Error(`${created.errorCode}: ${created.errorDescription}`);
// 2. Ask every 2 seconds until the task is ready.
let result;
do {
await new Promise((resolve) => setTimeout(resolve, 2000));
result = await post("/getTaskResult", { clientKey: KEY, taskId: created.taskId });
} while (result.errorId === 0 && result.status === "processing");
if (result.errorId !== 0) throw new Error(`${result.errorCode}: ${result.errorDescription}`);
// 3. The cookie and the user agent it was issued for.
const { userAgent, cookies } = result.solution;
console.log(JSON.stringify({ userAgent, cf_clearance: cookies.cf_clearance }));

Reuse it. Send the cookie with exactly that user agent, through the same proxy, on every request until the site challenges you again:

Terminal window
curl "https://shop.example.com/" \
--proxy "$PROXY_URL" \
-H "User-Agent: $USER_AGENT" \
-H "Cookie: cf_clearance=$CF_CLEARANCE"

A task is charged only when it succeeds, at the price on the pricing page, and there is no free tier. The REST version and samples in Python, Go and PHP are in the Cloudflare WAF and 5-second challenges docs; the Cloudflare WAF and 5-second challenge solver has one that runs as copied against our Cloudflare WAF managed challenge test page.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

What does "Just a moment..." mean on a Cloudflare site?

The site's Cloudflare setup, usually a WAF rule, Bot Fight Mode or Under Attack mode, wants your browser to pass a challenge before the page loads. A supported browser with JavaScript and cookies on usually passes it by itself and gets a cf_clearance cookie.

Is "Checking your browser before accessing" the same page?

Yes, in older wording. Cloudflare's reference still names the Under Attack mode page that way, and current challenge pages show "Just a moment...". Both are interstitial challenge pages, answered with HTTP 403 and the header cf-mitigated: challenge.

How does a scraper get past "Just a moment..."?

It cannot by waiting or retrying, since the page needs JavaScript. On sites it may automate, it passes the challenge once, in a browser or with a challenge task through its own proxy, then sends the cf_clearance cookie with the same user agent through the same proxy.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key