Skip to content

Comparison

Cloudflare Turnstile vs reCAPTCHA vs hCaptcha: Full Comparison

Cloudflare Turnstile, Google reCAPTCHA and hCaptcha side by side: how each checks visitors, tokens, siteverify, prices and limits, and what automation meets.

By 5 min readPublished Updated

Cloudflare Turnstile, Google reCAPTCHA and hCaptcha all put a widget on a form, give the browser a token, and have the site’s server check that token with the provider. They differ in what the visitor sees and what they cost. Turnstile runs non-interactive browser checks, at most asks for a checkbox, and is free for up to 20 widgets. reCAPTCHA v2 shows a checkbox and sometimes image challenges, v3 returns a score from 0.0 to 1.0, and Google’s tiers are free up to 10,000 assessments a month. hCaptcha is free on its Basic plan, with passive modes on paid plans. Their tokens last 300 seconds, two minutes and 120 seconds respectively, and each works once. All facts below were checked on 1 October 2026.

At a glance

Cloudflare Turnstile Google reCAPTCHA hCaptcha
Script challenges.cloudflare.com/turnstile/v0/api.js www.google.com/recaptcha/api.js js.hcaptcha.com/1/api.js
Widget element class="cf-turnstile" class="g-recaptcha" class="h-captcha"
Token form field cf-turnstile-response g-recaptcha-response h-captcha-response
What visitors do Nothing, or tick a checkbox (Managed mode) v2: checkbox, sometimes image challenges; v3: nothing Checkbox and image challenges; passive modes on paid plans
Result A token A token; v3 adds a score from 0.0 to 1.0 A token; Enterprise adds a risk score
Token lifetime 300 seconds, one verification Two minutes, one verification 120 seconds by default, one verification
Server check POST challenges.cloudflare.com/turnstile/v0/siteverify POST www.google.com/recaptcha/api/siteverify POST api.hcaptcha.com/siteverify
Free use Up to 20 widgets, unlimited challenges Essentials: up to 10,000 assessments a month Basic: $0
Paid plans Enterprise: contact sales Premium: $8 flat from 10,001 to 100,000 a month, then $1 per 1,000 Pro: $139 a month, or $99 billed yearly, 100,000 evaluations then $0.99 per 1,000

How each one decides

Cloudflare Turnstile runs “a series of small non-interactive JavaScript challenges to gather signals about the visitor or browser environment”: proof-of-work, proof-of-space, probing for web APIs, and checks for browser quirks and human behavior. A site owner picks one of three modes per widget: Managed (Cloudflare decides whether to show a checkbox), Non-Interactive (a visible widget with a spinner, never a prompt) and Invisible (nothing visible). Cloudflare says it uses “no images or text to decipher”. See Cloudflare Turnstile widget modes.

Google reCAPTCHA is now documented as part of Google Cloud Fraud Defense. Version 2 shows the “I’m not a robot” checkbox, with an invisible variant that runs when the visitor clicks an existing button. Version 3 shows nothing and returns a score, where “1.0 is very likely a good interaction, 0.0 is very likely a bot”; Google suggests starting with a threshold of 0.5, and the site decides what to do below it.

hCaptcha shows a checkbox and image challenges by default, can run invisibly when called with hcaptcha.execute(), and offers a “Low Friction 99.9% Passive Mode” on Pro and a “Passive (No-CAPTCHA) Mode” and risk scores on Enterprise.

Privacy and data

  • Turnstile can be used without routing a site through Cloudflare. Its privacy addendum lists the signals it collects (the client IP address, TLS fingerprint, User-Agent header, and the sitekey with its origin) and says they are used “solely to detect and block bots”. Sites that use Invisible mode must reference that addendum in their own privacy policy.
  • reCAPTCHA and hCaptcha each publish their own terms; compare them with your privacy policy and your visitors’ jurisdictions before choosing.

Server-side verification compared

All three follow the same pattern: the server posts its secret key and the token, and reads a JSON reply with success and error-codes. The details differ:

  • Turnstile accepts form data or JSON, only by POST, and returns the hostname, action and cdata the token was issued for, plus an ephemeral_id on Enterprise. An expired or reused token fails with timeout-or-duplicate.
  • reCAPTCHA takes secret, response and an optional remoteip, and v3 adds score and action to the reply. A stale or reused token also fails with timeout-or-duplicate.
  • hCaptcha takes form data only (“Do not send JSON data”), recommends remoteip, and has its own codes for expired and replayed tokens: expired-input-response and already-seen-response.

Cloudflare Turnstile siteverify errors lists every code Turnstile returns.

Switching between them

Turnstile is designed to replace the other two with little code:

  • From reCAPTCHA: load api.js?compat=recaptcha and Turnstile renders reCAPTCHA’s markup, posts the token as g-recaptcha-response and registers itself as grecaptcha. The server switches to Turnstile’s siteverify URL. Cloudflare says compatibility covers “up to reCAPTCHA v2” and that siteverify does not accept GET.
  • From hCaptcha: replace the siteverify URL, the h-captcha-response field with cf-turnstile-response, and hcaptcha.render() with turnstile.render().

hCaptcha also inserts a window.grecaptcha compatibility hook by default, which is why pages that moved between the three sometimes keep another provider’s field name. Check the actual field the form posts before automating it.

What automation meets

For a developer who tests or automates pages they are allowed to, the work has the same shape for all three: find the sitekey, obtain a token, and submit it in the field the page expects before it expires. What differs:

  • Which widget is on the page. challenges.cloudflare.com or class="cf-turnstile" means Turnstile; google.com/recaptcha, recaptcha.net or class="g-recaptcha" means reCAPTCHA; hcaptcha.com or class="h-captcha" means hCaptcha. A full-page “Just a moment…” screen is none of them: it is a Cloudflare challenge page. See Cloudflare challenge page vs Turnstile.
  • Time budget. A Turnstile token leaves five minutes to submit the form; reCAPTCHA and hCaptcha leave two. See Cloudflare Turnstile token expiry.
  • Extra parameters. Turnstile widgets may set an action and cData that a solving task should repeat: see Cloudflare Turnstile action and cData. reCAPTCHA v3 has an action too, and its score matters as much as its token.
  • Browser automation. Cloudflare says automated testing suites such as Selenium, Cypress and Playwright “are detected as bots by Turnstile”. Testing your own forms is easier with each provider’s test keys: test Cloudflare Turnstile in CI lists Cloudflare’s.

What ZeroCaptcha solves

ZeroCaptcha solves Cloudflare Turnstile: a task needs the page URL and the widget’s sitekey, and returns a token with the time it expires, charged only when the token is ready. It does not solve reCAPTCHA or hCaptcha: their task types are refused at no charge, with ERROR_TASK_NOT_SUPPORTED in the createTask format. The Cloudflare Turnstile solver shows the flow in ten languages and tools, and pricing lists the price per 1,000 solved tasks.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

What is the difference between Cloudflare Turnstile and reCAPTCHA?

Turnstile runs non-interactive browser checks and at most asks for a checkbox, with no image puzzles, and is free for up to 20 widgets. reCAPTCHA v2 shows a checkbox and sometimes image challenges, v3 returns a score, and Google's Fraud Defense tiers are free up to 10,000 assessments a month.

How long are Turnstile, reCAPTCHA and hCaptcha tokens valid?

A Cloudflare Turnstile token is valid for 300 seconds, a reCAPTCHA token for two minutes, and an hCaptcha token for 120 seconds by default. All three can be verified only once.

Does ZeroCaptcha solve reCAPTCHA or hCaptcha?

No. ZeroCaptcha solves Cloudflare Turnstile and Cloudflare challenge pages. Task types for reCAPTCHA or hCaptcha are refused at no charge, with ERROR_TASK_NOT_SUPPORTED in the createTask format.

Read next

This article is part of the Cloudflare Turnstile solver hub. Every task is charged only when a token is ready.

Get an API key