Comparison
Cloudflare Turnstile vs reCAPTCHA vs hCaptcha: Full Comparison
Cloudflare Turnstile, Google reCAPTCHA and hCaptcha side by side: how each checks visitors, tokens, siteverify, prices and limits, and what automation meets.
By ZeroCaptcha Engineering5 min readPublished Updated
Cloudflare Turnstile, Google reCAPTCHA and hCaptcha all put a widget on a form, give the browser a token, and have the site’s server check that token with the provider. They differ in what the visitor sees and what they cost. Turnstile runs non-interactive browser checks, at most asks for a checkbox, and is free for up to 20 widgets. reCAPTCHA v2 shows a checkbox and sometimes image challenges, v3 returns a score from 0.0 to 1.0, and Google’s tiers are free up to 10,000 assessments a month. hCaptcha is free on its Basic plan, with passive modes on paid plans. Their tokens last 300 seconds, two minutes and 120 seconds respectively, and each works once. All facts below were checked on 1 October 2026.
At a glance
| Cloudflare Turnstile | Google reCAPTCHA | hCaptcha | |
|---|---|---|---|
| Script | challenges.cloudflare.com/turnstile/v0/api.js |
www.google.com/recaptcha/api.js |
js.hcaptcha.com/1/api.js |
| Widget element | class="cf-turnstile" |
class="g-recaptcha" |
class="h-captcha" |
| Token form field | cf-turnstile-response |
g-recaptcha-response |
h-captcha-response |
| What visitors do | Nothing, or tick a checkbox (Managed mode) | v2: checkbox, sometimes image challenges; v3: nothing | Checkbox and image challenges; passive modes on paid plans |
| Result | A token | A token; v3 adds a score from 0.0 to 1.0 | A token; Enterprise adds a risk score |
| Token lifetime | 300 seconds, one verification | Two minutes, one verification | 120 seconds by default, one verification |
| Server check | POST challenges.cloudflare.com/turnstile/v0/siteverify |
POST www.google.com/recaptcha/api/siteverify |
POST api.hcaptcha.com/siteverify |
| Free use | Up to 20 widgets, unlimited challenges | Essentials: up to 10,000 assessments a month | Basic: $0 |
| Paid plans | Enterprise: contact sales | Premium: $8 flat from 10,001 to 100,000 a month, then $1 per 1,000 | Pro: $139 a month, or $99 billed yearly, 100,000 evaluations then $0.99 per 1,000 |
How each one decides
Cloudflare Turnstile runs “a series of small non-interactive JavaScript challenges to gather signals about the visitor or browser environment”: proof-of-work, proof-of-space, probing for web APIs, and checks for browser quirks and human behavior. A site owner picks one of three modes per widget: Managed (Cloudflare decides whether to show a checkbox), Non-Interactive (a visible widget with a spinner, never a prompt) and Invisible (nothing visible). Cloudflare says it uses “no images or text to decipher”. See Cloudflare Turnstile widget modes.
Google reCAPTCHA is now documented as part of Google Cloud Fraud Defense. Version 2 shows the “I’m not a robot” checkbox, with an invisible variant that runs when the visitor clicks an existing button. Version 3 shows nothing and returns a score, where “1.0 is very likely a good interaction, 0.0 is very likely a bot”; Google suggests starting with a threshold of 0.5, and the site decides what to do below it.
hCaptcha shows a checkbox and image challenges by default, can run invisibly when called with
hcaptcha.execute(), and offers a “Low Friction 99.9% Passive Mode” on Pro and a “Passive
(No-CAPTCHA) Mode” and risk scores on Enterprise.
Privacy and data
- Turnstile can be used without routing a site through Cloudflare. Its privacy addendum lists the signals it collects (the client IP address, TLS fingerprint, User-Agent header, and the sitekey with its origin) and says they are used “solely to detect and block bots”. Sites that use Invisible mode must reference that addendum in their own privacy policy.
- reCAPTCHA and hCaptcha each publish their own terms; compare them with your privacy policy and your visitors’ jurisdictions before choosing.
Server-side verification compared
All three follow the same pattern: the server posts its secret key and the token, and reads a JSON
reply with success and error-codes. The details differ:
- Turnstile accepts form data or JSON, only by
POST, and returns thehostname,actionandcdatathe token was issued for, plus anephemeral_idon Enterprise. An expired or reused token fails withtimeout-or-duplicate. - reCAPTCHA takes
secret,responseand an optionalremoteip, and v3 addsscoreandactionto the reply. A stale or reused token also fails withtimeout-or-duplicate. - hCaptcha takes form data only (“Do not send JSON data”), recommends
remoteip, and has its own codes for expired and replayed tokens:expired-input-responseandalready-seen-response.
Cloudflare Turnstile siteverify errors lists every code Turnstile returns.
Switching between them
Turnstile is designed to replace the other two with little code:
- From reCAPTCHA: load
api.js?compat=recaptchaand Turnstile renders reCAPTCHA’s markup, posts the token asg-recaptcha-responseand registers itself asgrecaptcha. The server switches to Turnstile’s siteverify URL. Cloudflare says compatibility covers “up to reCAPTCHA v2” and that siteverify does not acceptGET. - From hCaptcha: replace the siteverify URL, the
h-captcha-responsefield withcf-turnstile-response, andhcaptcha.render()withturnstile.render().
hCaptcha also inserts a window.grecaptcha compatibility hook by default, which is why pages that
moved between the three sometimes keep another provider’s field name. Check the actual field the
form posts before automating it.
What automation meets
For a developer who tests or automates pages they are allowed to, the work has the same shape for all three: find the sitekey, obtain a token, and submit it in the field the page expects before it expires. What differs:
- Which widget is on the page.
challenges.cloudflare.comorclass="cf-turnstile"means Turnstile;google.com/recaptcha,recaptcha.netorclass="g-recaptcha"means reCAPTCHA;hcaptcha.comorclass="h-captcha"means hCaptcha. A full-page “Just a moment…” screen is none of them: it is a Cloudflare challenge page. See Cloudflare challenge page vs Turnstile. - Time budget. A Turnstile token leaves five minutes to submit the form; reCAPTCHA and hCaptcha leave two. See Cloudflare Turnstile token expiry.
- Extra parameters. Turnstile widgets may set an
actionandcDatathat a solving task should repeat: see Cloudflare Turnstile action and cData. reCAPTCHA v3 has an action too, and its score matters as much as its token. - Browser automation. Cloudflare says automated testing suites such as Selenium, Cypress and Playwright “are detected as bots by Turnstile”. Testing your own forms is easier with each provider’s test keys: test Cloudflare Turnstile in CI lists Cloudflare’s.
What ZeroCaptcha solves
ZeroCaptcha solves Cloudflare Turnstile: a task needs the page URL and the widget’s sitekey, and
returns a token with the time it expires, charged only when the token is ready. It does not solve
reCAPTCHA or hCaptcha: their task types are refused at no charge, with ERROR_TASK_NOT_SUPPORTED
in the createTask format.
The Cloudflare Turnstile solver shows the flow in ten languages and
tools, and pricing lists the price per 1,000 solved tasks.
Sources
- Cloudflare Turnstile: overview, widget modes, plans, server-side validation, migrating from reCAPTCHA, migrating from hCaptcha, testing and the privacy addendum (checked 1 October 2026).
- Google reCAPTCHA: versions, v3, verifying the response and tiers and pricing (checked 1 October 2026).
- hCaptcha: developer guide, configuration and pricing (checked 1 October 2026).
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.