Skip to content

Explainer

Cloudflare Turnstile Ephemeral IDs: What Site Owners See

What a Cloudflare Turnstile ephemeral ID is, who gets it, how it shows in siteverify, how sites use it against fake sign-ups, and what it means for automation.

By 4 min readPublished

A Cloudflare Turnstile ephemeral ID is a short-lived device identifier that Turnstile returns to the site in its siteverify response, as metadata.ephemeral_id. Cloudflare says ephemeral IDs “link visitor behavior to a specific client device without relying on cookies or client-side storage”, “expire within a few days and cannot be used to identify individual users”, and are “scoped to your Cloudflare account”. They are for Enterprise customers only, and sites use them to spot one device making many sign-ups or logins while rotating IP addresses. A normal widget’s siteverify reply does not include one.

This explainer covers where the ID appears, how Cloudflare suggests using it, its limits, and what it means for automated clients, as documented on 1 October 2026.

Who gets ephemeral IDs

“Ephemeral IDs are available to Enterprise Bot Management customers with the Enterprise Turnstile add-on or standalone Enterprise Turnstile customers.” And: “This feature requires Enterprise-level access and cannot be self-activated.” So on the Free plan, and on most sites you meet, the siteverify response has no ephemeral ID at all.

Where it appears

“Once enabled, Ephemeral IDs are included in Siteverify API responses”, in the metadata object, next to the usual fields. Cloudflare’s example of the field:

{
"success": true,
"challenge_ts": "2026-10-01T09:30:00.000Z",
"hostname": "shop.example.com",
"error-codes": [],
"action": "signup",
"cdata": "",
"metadata": {
"ephemeral_id": "x:9f78e0ed210960d7693b167e"
}
}

The metadata block is Cloudflare’s example; the fields around it are the standard siteverify reply, filled in for illustration. Only the site’s server sees this reply, since siteverify is called with the widget’s secret key. The browser never gets the ID. What the rest of the reply means is in the Cloudflare Turnstile token explained.

What sites do with it

Cloudflare’s use case is abuse that rotates addresses: “This approach is particularly effective against credential stuffing and fake account creation attacks, where attackers rotate IP addresses to evade detection.” Its fraud-detection tutorial:

  • logs each protected action (such as a sign-up) with its ephemeral ID;
  • counts actions per ID over a one-hour sliding window, and treats “More than 3 signups” from one ID as suspicious;
  • adds suspicious IDs to a blocklist, checked on later requests, and can find every account created from the same ID for review.

A site’s own check, in Python, reading the ID from a siteverify reply and counting sign-ups per ID in memory, looks like this. A real site would keep the counts in its database, as the tutorial does.

import time
from collections import defaultdict, deque
WINDOW_SECONDS = 3600
MAX_SIGNUPS_PER_DEVICE = 3
recent = defaultdict(deque)
def signup_allowed(siteverify_reply, now=None):
now = time.time() if now is None else now
ephemeral_id = (siteverify_reply.get("metadata") or {}).get("ephemeral_id")
if not ephemeral_id:
return True # no ID on this plan, or none returned: decide on other signals
events = recent[ephemeral_id]
while events and now - events[0] > WINDOW_SECONDS:
events.popleft()
events.append(now)
return len(events) <= MAX_SIGNUPS_PER_DEVICE

Its limits, in Cloudflare’s words

  • Not unique per device. “Not every unique device will produce a unique Ephemeral ID. Privacy-focused devices and browsers (such as iPhones and Safari) limit the signals available for fingerprinting, which means multiple legitimate users may share the same Ephemeral ID.”
  • Patterns, not people. “Use Ephemeral IDs to detect high-volume abuse patterns, not to uniquely identify individual devices.” The tutorial suggests combining them with other signals such as IP reputation and behaviour.
  • Short-lived. “Ephemeral IDs are dynamically generated for each Turnstile solve attempt”, and they expire within days, so they cannot track a visitor over time.

What it means for automation

For a legitimate automated client on an Enterprise site, the ID changes little: the site sees a device identifier alongside the token, as it would for any visitor, and a site that limits actions per device may refuse the fourth sign-up in an hour from the same one. The practical rules are the ones that apply anyway:

  • Automate only what the site allows. Ephemeral IDs exist to stop fake accounts and credential stuffing. Those are not uses anyone should automate, and ZeroCaptcha’s acceptable use rules them out.
  • Stay within the site’s limits. An action a site caps per device is capped for your client too.
  • Don’t expect IP rotation to reset anything. That is precisely the pattern the ID was built to see through.

A token from a solving API is verified by the site with siteverify like any other, and on an Enterprise site its reply carries an ephemeral ID like any other. ZeroCaptcha does not read, change or promise anything about that ID. How tokens are made for a page you name is on the Cloudflare Turnstile solver page.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

What is a Cloudflare Turnstile ephemeral ID?

It is a short-lived device identifier that Turnstile generates for each solve attempt and returns to the site in the siteverify response as metadata.ephemeral_id. It needs no cookies or local storage, expires within a few days, and cannot identify an individual user.

Who can use Cloudflare Turnstile ephemeral IDs?

Enterprise Bot Management customers with the Enterprise Turnstile add-on, and standalone Enterprise Turnstile customers. It cannot be self-activated; Cloudflare's account team enables it.

Can many people share one ephemeral ID?

Yes. Cloudflare warns that not every device produces a unique ephemeral ID: privacy-focused devices and browsers such as iPhones and Safari limit the signals available, so several legitimate users may share one.

Read next

This article is part of the Cloudflare Turnstile solver hub. Every task is charged only when a token is ready.

Get an API key