Explainer
Cloudflare Turnstile Ephemeral IDs: What Site Owners See
What a Cloudflare Turnstile ephemeral ID is, who gets it, how it shows in siteverify, how sites use it against fake sign-ups, and what it means for automation.
By ZeroCaptcha Engineering4 min readPublished
A Cloudflare Turnstile ephemeral ID is a short-lived device identifier that Turnstile returns to
the site in its siteverify response, as metadata.ephemeral_id. Cloudflare says ephemeral IDs “link
visitor behavior to a specific client device without relying on cookies or client-side storage”,
“expire within a few days and cannot be used to identify individual users”, and are “scoped to your
Cloudflare account”. They are for Enterprise customers only, and sites use them to spot one
device making many sign-ups or logins while rotating IP addresses. A normal widget’s siteverify
reply does not include one.
This explainer covers where the ID appears, how Cloudflare suggests using it, its limits, and what it means for automated clients, as documented on 1 October 2026.
Who gets ephemeral IDs
“Ephemeral IDs are available to Enterprise Bot Management customers with the Enterprise Turnstile add-on or standalone Enterprise Turnstile customers.” And: “This feature requires Enterprise-level access and cannot be self-activated.” So on the Free plan, and on most sites you meet, the siteverify response has no ephemeral ID at all.
Where it appears
“Once enabled, Ephemeral IDs are included in Siteverify API responses”, in the metadata object,
next to the usual fields. Cloudflare’s example of the field:
{ "success": true, "challenge_ts": "2026-10-01T09:30:00.000Z", "hostname": "shop.example.com", "error-codes": [], "action": "signup", "cdata": "", "metadata": { "ephemeral_id": "x:9f78e0ed210960d7693b167e" }}The metadata block is Cloudflare’s example; the fields around it are the standard siteverify
reply, filled in for illustration. Only the site’s server sees this reply, since siteverify is
called with the widget’s secret key. The browser never gets the ID. What the rest of the reply
means is in the Cloudflare Turnstile token explained.
What sites do with it
Cloudflare’s use case is abuse that rotates addresses: “This approach is particularly effective against credential stuffing and fake account creation attacks, where attackers rotate IP addresses to evade detection.” Its fraud-detection tutorial:
- logs each protected action (such as a sign-up) with its ephemeral ID;
- counts actions per ID over a one-hour sliding window, and treats “More than 3 signups” from one ID as suspicious;
- adds suspicious IDs to a blocklist, checked on later requests, and can find every account created from the same ID for review.
A site’s own check, in Python, reading the ID from a siteverify reply and counting sign-ups per ID in memory, looks like this. A real site would keep the counts in its database, as the tutorial does.
import timefrom collections import defaultdict, deque
WINDOW_SECONDS = 3600MAX_SIGNUPS_PER_DEVICE = 3recent = defaultdict(deque)
def signup_allowed(siteverify_reply, now=None): now = time.time() if now is None else now ephemeral_id = (siteverify_reply.get("metadata") or {}).get("ephemeral_id") if not ephemeral_id: return True # no ID on this plan, or none returned: decide on other signals events = recent[ephemeral_id] while events and now - events[0] > WINDOW_SECONDS: events.popleft() events.append(now) return len(events) <= MAX_SIGNUPS_PER_DEVICEIts limits, in Cloudflare’s words
- Not unique per device. “Not every unique device will produce a unique Ephemeral ID. Privacy-focused devices and browsers (such as iPhones and Safari) limit the signals available for fingerprinting, which means multiple legitimate users may share the same Ephemeral ID.”
- Patterns, not people. “Use Ephemeral IDs to detect high-volume abuse patterns, not to uniquely identify individual devices.” The tutorial suggests combining them with other signals such as IP reputation and behaviour.
- Short-lived. “Ephemeral IDs are dynamically generated for each Turnstile solve attempt”, and they expire within days, so they cannot track a visitor over time.
What it means for automation
For a legitimate automated client on an Enterprise site, the ID changes little: the site sees a device identifier alongside the token, as it would for any visitor, and a site that limits actions per device may refuse the fourth sign-up in an hour from the same one. The practical rules are the ones that apply anyway:
- Automate only what the site allows. Ephemeral IDs exist to stop fake accounts and credential stuffing. Those are not uses anyone should automate, and ZeroCaptcha’s acceptable use rules them out.
- Stay within the site’s limits. An action a site caps per device is capped for your client too.
- Don’t expect IP rotation to reset anything. That is precisely the pattern the ID was built to see through.
A token from a solving API is verified by the site with siteverify like any other, and on an Enterprise site its reply carries an ephemeral ID like any other. ZeroCaptcha does not read, change or promise anything about that ID. How tokens are made for a page you name is on the Cloudflare Turnstile solver page.
Sources
- Cloudflare Turnstile: ephemeral IDs (checked 1 October 2026).
- Cloudflare Turnstile: fraud detection with ephemeral IDs (checked 1 October 2026).
- Cloudflare Turnstile: server-side validation, for the siteverify reply’s fields (checked 1 October 2026).
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.