# Cloudflare Turnstile Ephemeral IDs: What Site Owners See

> What a Cloudflare Turnstile ephemeral ID is, who gets it, how it shows in siteverify, how sites use it against fake sign-ups, and what it means for automation.

- Source: https://zerocaptcha.io/blog/cloudflare-turnstile-ephemeral-id
- Published: 2026-10-01
- Author: ZeroCaptcha Engineering

A **Cloudflare Turnstile ephemeral ID** is a short-lived device identifier that Turnstile returns to
the site in its siteverify response, as `metadata.ephemeral_id`. Cloudflare says ephemeral IDs "link
visitor behavior to a specific client device without relying on cookies or client-side storage",
"expire within a few days and cannot be used to identify individual users", and are "scoped to your
Cloudflare account". They are for **Enterprise** customers only, and sites use them to spot one
device making many sign-ups or logins while rotating IP addresses. A normal widget's siteverify
reply does not include one.

This explainer covers where the ID appears, how Cloudflare suggests using it, its limits, and what
it means for automated clients, as documented on 1 October 2026.

## Who gets ephemeral IDs

"Ephemeral IDs are available to Enterprise Bot Management customers with the Enterprise Turnstile
add-on or standalone Enterprise Turnstile customers." And: "This feature requires Enterprise-level
access and cannot be self-activated." So on the Free plan, and on most sites you meet, the
siteverify response has no ephemeral ID at all.

## Where it appears

"Once enabled, Ephemeral IDs are included in Siteverify API responses", in the `metadata` object,
next to the usual fields. Cloudflare's example of the field:

```json
{
  "success": true,
  "challenge_ts": "2026-10-01T09:30:00.000Z",
  "hostname": "shop.example.com",
  "error-codes": [],
  "action": "signup",
  "cdata": "",
  "metadata": {
    "ephemeral_id": "x:9f78e0ed210960d7693b167e"
  }
}
```

The `metadata` block is Cloudflare's example; the fields around it are the standard siteverify
reply, filled in for illustration. Only the site's server sees this reply, since siteverify is
called with the widget's secret key. The browser never gets the ID. What the rest of the reply
means is in [the Cloudflare Turnstile token explained](https://zerocaptcha.io/blog/cloudflare-turnstile-token).

## What sites do with it

Cloudflare's use case is abuse that rotates addresses: "This approach is particularly effective
against credential stuffing and fake account creation attacks, where attackers rotate IP addresses
to evade detection." Its fraud-detection tutorial:

- logs each protected action (such as a sign-up) with its ephemeral ID;
- counts actions per ID over a one-hour sliding window, and treats "More than 3 signups" from one
  ID as suspicious;
- adds suspicious IDs to a blocklist, checked on later requests, and can find every account created
  from the same ID for review.

A site's own check, in Python, reading the ID from a siteverify reply and counting sign-ups per ID
in memory, looks like this. A real site would keep the counts in its database, as the tutorial does.

```python
import time
from collections import defaultdict, deque

WINDOW_SECONDS = 3600
MAX_SIGNUPS_PER_DEVICE = 3
recent = defaultdict(deque)


def signup_allowed(siteverify_reply, now=None):
    now = time.time() if now is None else now
    ephemeral_id = (siteverify_reply.get("metadata") or {}).get("ephemeral_id")
    if not ephemeral_id:
        return True  # no ID on this plan, or none returned: decide on other signals
    events = recent[ephemeral_id]
    while events and now - events[0] > WINDOW_SECONDS:
        events.popleft()
    events.append(now)
    return len(events) <= MAX_SIGNUPS_PER_DEVICE
```

## Its limits, in Cloudflare's words

- **Not unique per device.** "Not every unique device will produce a unique Ephemeral ID.
  Privacy-focused devices and browsers (such as iPhones and Safari) limit the signals available for
  fingerprinting, which means multiple legitimate users may share the same Ephemeral ID."
- **Patterns, not people.** "Use Ephemeral IDs to detect high-volume abuse patterns, not to uniquely
  identify individual devices." The tutorial suggests combining them with other signals such as IP
  reputation and behaviour.
- **Short-lived.** "Ephemeral IDs are dynamically generated for each Turnstile solve attempt", and
  they expire within days, so they cannot track a visitor over time.

## What it means for automation

For a legitimate automated client on an Enterprise site, the ID changes little: the site sees a
device identifier alongside the token, as it would for any visitor, and a site that limits actions
per device may refuse the fourth sign-up in an hour from the same one. The practical rules are the
ones that apply anyway:

- **Automate only what the site allows.** Ephemeral IDs exist to stop fake accounts and credential
  stuffing. Those are not uses anyone should automate, and ZeroCaptcha's
  [acceptable use](https://zerocaptcha.io/guides/responsible-captcha-automation) rules them out.
- **Stay within the site's limits.** An action a site caps per device is capped for your client too.
- **Don't expect IP rotation to reset anything.** That is precisely the pattern the ID was built to
  see through.

A token from a solving API is verified by the site with siteverify like any other, and on an
Enterprise site its reply carries an ephemeral ID like any other. ZeroCaptcha does not read, change
or promise anything about that ID. How tokens are made for a page you name is on the
[Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver) page.

## Sources

- [Cloudflare Turnstile: ephemeral IDs](https://developers.cloudflare.com/turnstile/additional-configuration/ephemeral-id/)
  (checked 1 October 2026).
- [Cloudflare Turnstile: fraud detection with ephemeral IDs](https://developers.cloudflare.com/turnstile/tutorials/fraud-detection-with-ephemeral-ids/)
  (checked 1 October 2026).
- [Cloudflare Turnstile: server-side validation](https://developers.cloudflare.com/turnstile/get-started/server-side-validation/),
  for the siteverify reply's fields (checked 1 October 2026).

## Questions

### What is a Cloudflare Turnstile ephemeral ID?

It is a short-lived device identifier that Turnstile generates for each solve attempt and returns to the site in the siteverify response as metadata.ephemeral_id. It needs no cookies or local storage, expires within a few days, and cannot identify an individual user.

### Who can use Cloudflare Turnstile ephemeral IDs?

Enterprise Bot Management customers with the Enterprise Turnstile add-on, and standalone Enterprise Turnstile customers. It cannot be self-activated; Cloudflare's account team enables it.

### Can many people share one ephemeral ID?

Yes. Cloudflare warns that not every device produces a unique ephemeral ID: privacy-focused devices and browsers such as iPhones and Safari limit the signals available, so several legitimate users may share one.
