Troubleshooting
Cloudflare "Just a Moment" and "Checking Your Browser" Pages
What Cloudflare's "Just a moment..." and "Checking your browser" pages are, why they appear, what visitors can do, and how automation passes them.
By ZeroCaptcha Engineering5 min readPublished
“Just a moment…” is the title of Cloudflare’s interstitial challenge page, and “Checking
your browser before accessing…” is its older wording, which Cloudflare’s reference still uses
for the Under Attack mode page. Both mean the same thing: the site’s Cloudflare setup wants your
browser to pass a challenge before the page loads. A supported browser with JavaScript and cookies
on usually passes it by itself in a few seconds and gets a cf_clearance cookie, which lets it
through until the site’s Challenge Passage time runs out, 30 minutes by default. A script that runs
no JavaScript never passes it, however often it retries.
This article explains why the page appears, what a visitor can do, what a site owner can change, and how an automated client passes it, as Cloudflare documented it on 1 October 2026.
Why the page appears
Cloudflare shows the page when something in the site’s configuration challenges your request:
| What issued it | When | What it shows |
|---|---|---|
| A WAF custom rule or rate limiting rule | The request matches a rule whose action is Managed, Non-Interactive (JS) or Interactive Challenge | The challenge the action names |
| Bot Fight Mode | Cloudflare’s bot detection flags the request; it “Issues computationally expensive challenges” | An interstitial challenge page |
| Under Attack mode | The owner turned it on, usually during an attack: every visitor is challenged | A Managed Challenge page |
| Browser Integrity Check | The request has no user agent or a non-standard one | A challenge |
Whatever issued it, the response is the same from the outside: status 403, the header
cf-mitigated: challenge, and an HTML page that loads its scripts from the site’s own
/cdn-cgi/challenge-platform/ path. In our checks its title was “Just a moment…”. The old name
for this page, from its JavaScript-challenge days, is the Cloudflare 5-second
challenge.
A page that shows a Cloudflare error code such as 1020, with no
cf-mitigated header, is not this page: it is a Block, which no browser or task can pass. The Cloudflare WAF bypass article sorts the two apart.
If you are a visitor
- Wait a few seconds. Most browsers pass without doing anything; Cloudflare’s Managed Challenge asks for a click only some of the time.
- Turn JavaScript and cookies on for the site. The page runs a script, and the pass is stored as
the
cf_clearancecookie. - Let the challenge’s script load. An ad blocker or a network filter that blocks
challenges.cloudflare.comstops the page; see “Please unblock challenges.cloudflare.com to proceed”. - If it keeps coming back, Cloudflare lists network issues, browser settings or extensions that block its scripts, unsupported browsers and disabled JavaScript as the causes. The challenge loop article covers each, and the ones automated clients add.
If you run the site
The page is the owner’s own setting, so the owner can narrow it. Under Attack mode can be kept off an API or any other path with a configuration rule, as Cloudflare suggests, and a WAF custom rule with the Skip action can exempt known traffic from later rules. Partners who call your API should get a way in that needs no browser, rather than a challenge they cannot pass. Cloudflare WAF rules explained lists every action and the order they run in.
If you are automating
A client that meets “Just a moment…” should check for it, pass it once, and reuse the clearance. Only automate sites you are allowed to: see responsible captcha automation.
Detect it. The header is the reliable sign, since the status alone is shared with blocks:
// Is this response Cloudflare's "Just a moment..." page? Node.js 22 or later, as an ES module.const response = await fetch("https://shop.example.com/", { redirect: "manual" });if (response.headers.get("cf-mitigated") === "challenge") { console.log("Challenge page: pass it once, then reuse the cf_clearance cookie.");} else { console.log(`No challenge: HTTP ${response.status}`);}Pass it once. ZeroCaptcha’s CloudflareChallengeTask passes the page through your own proxy and returns the cf_clearance cookie with the user agent it was issued for. Here it is in the createTask format, the one CapSolver-style clients already send, with every field a real integration sends:
// Pass a Cloudflare "Just a moment..." page with the createTask format. Node.js 22 or later,// as an ES module (solve.mjs). Use the result through the same proxy, with the same user agent.import { randomUUID } from "node:crypto";
const API = process.env.ZEROCAPTCHA_API ?? "https://api.zerocaptcha.io";const KEY = process.env.ZEROCAPTCHA_KEY;const PROXY = process.env.PROXY_URL; // such as http://user:pass@proxy.example.net:8080if (!KEY || !PROXY) throw new Error("Set ZEROCAPTCHA_KEY and PROXY_URL.");
const post = async (path, body, headers = {}) => { const reply = await fetch(`${API}${path}`, { method: "POST", headers: { "Content-Type": "application/json", ...headers }, body: JSON.stringify(body), }); return reply.json();};
// 1. Create the task: the page behind the challenge (websiteURL), your proxy, where to POST the// result when the task ends (callbackUrl), and an Idempotency-Key, so a retry returns the same// task instead of a second, paid one. A challenge page has no sitekey: there is no websiteKey.const created = await post( "/createTask", { clientKey: KEY, task: { type: "CloudflareChallengeTask", websiteURL: "https://shop.example.com/", proxy: PROXY }, callbackUrl: "https://example.com/zerocaptcha/callback", }, { "Idempotency-Key": randomUUID() },);if (created.errorId !== 0) throw new Error(`${created.errorCode}: ${created.errorDescription}`);
// 2. Ask every 2 seconds until the task is ready.let result;do { await new Promise((resolve) => setTimeout(resolve, 2000)); result = await post("/getTaskResult", { clientKey: KEY, taskId: created.taskId });} while (result.errorId === 0 && result.status === "processing");if (result.errorId !== 0) throw new Error(`${result.errorCode}: ${result.errorDescription}`);
// 3. The cookie and the user agent it was issued for.const { userAgent, cookies } = result.solution;console.log(JSON.stringify({ userAgent, cf_clearance: cookies.cf_clearance }));Reuse it. Send the cookie with exactly that user agent, through the same proxy, on every request until the site challenges you again:
curl "https://shop.example.com/" \ --proxy "$PROXY_URL" \ -H "User-Agent: $USER_AGENT" \ -H "Cookie: cf_clearance=$CF_CLEARANCE"A task is charged only when it succeeds, at the price on the pricing page, and there is no free tier. The REST version and samples in Python, Go and PHP are in the Cloudflare WAF and 5-second challenges docs; the Cloudflare WAF and 5-second challenge solver has one that runs as copied against our Cloudflare WAF managed challenge test page.
Sources
- Cloudflare: Interstitial Challenge Pages (checked 1 October 2026)
- Cloudflare challenges: detect a challenge response (checked 1 October 2026)
- Cloudflare: Under Attack mode (checked 1 October 2026)
- Cloudflare challenges: how challenges work, for which products issue a challenge (checked 1 October 2026)
- Cloudflare: Bot Fight Mode and Browser Integrity Check (checked 1 October 2026)
- Cloudflare: Clearance and Challenge Passage (checked 1 October 2026)
- Cloudflare: Rules language actions (checked 1 October 2026)
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.