# Cloudflare Turnstile vs reCAPTCHA vs hCaptcha: Full Comparison

> Cloudflare Turnstile, Google reCAPTCHA and hCaptcha side by side: how each checks visitors, tokens, siteverify, prices and limits, and what automation meets.

- Source: https://zerocaptcha.io/blog/cloudflare-turnstile-vs-recaptcha-vs-hcaptcha
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

Cloudflare Turnstile, Google reCAPTCHA and hCaptcha all put a widget on a form, give the browser
a token, and have the site's server check that token with the provider. They differ in what the
visitor sees and what they cost. Turnstile runs non-interactive browser checks, at most asks for a
checkbox, and is free for up to 20 widgets. reCAPTCHA v2 shows a checkbox and sometimes image
challenges, v3 returns a score from 0.0 to 1.0, and Google's tiers are free up to 10,000
assessments a month. hCaptcha is free on its Basic plan, with passive modes on paid plans. Their
tokens last 300 seconds, two minutes and 120 seconds respectively, and each works once. All facts
below were checked on 1 October 2026.

## At a glance

| | Cloudflare Turnstile | Google reCAPTCHA | hCaptcha |
| --- | --- | --- | --- |
| Script | `challenges.cloudflare.com/turnstile/v0/api.js` | `www.google.com/recaptcha/api.js` | `js.hcaptcha.com/1/api.js` |
| Widget element | `class="cf-turnstile"` | `class="g-recaptcha"` | `class="h-captcha"` |
| Token form field | `cf-turnstile-response` | `g-recaptcha-response` | `h-captcha-response` |
| What visitors do | Nothing, or tick a checkbox (Managed mode) | v2: checkbox, sometimes image challenges; v3: nothing | Checkbox and image challenges; passive modes on paid plans |
| Result | A token | A token; v3 adds a score from 0.0 to 1.0 | A token; Enterprise adds a risk score |
| Token lifetime | 300 seconds, one verification | Two minutes, one verification | 120 seconds by default, one verification |
| Server check | `POST challenges.cloudflare.com/turnstile/v0/siteverify` | `POST www.google.com/recaptcha/api/siteverify` | `POST api.hcaptcha.com/siteverify` |
| Free use | Up to 20 widgets, unlimited challenges | Essentials: up to 10,000 assessments a month | Basic: $0 |
| Paid plans | Enterprise: contact sales | Premium: $8 flat from 10,001 to 100,000 a month, then $1 per 1,000 | Pro: $139 a month, or $99 billed yearly, 100,000 evaluations then $0.99 per 1,000 |

## How each one decides

**Cloudflare Turnstile** runs "a series of small non-interactive JavaScript challenges to gather
signals about the visitor or browser environment": proof-of-work, proof-of-space, probing for web
APIs, and checks for browser quirks and human behavior. A site owner picks one of three modes per
widget: Managed (Cloudflare decides whether to show a checkbox), Non-Interactive (a visible widget
with a spinner, never a prompt) and Invisible (nothing visible). Cloudflare says it uses "no images
or text to decipher". See [Cloudflare Turnstile widget modes](https://zerocaptcha.io/guides/cloudflare-turnstile-widget-modes).

**Google reCAPTCHA** is now documented as part of Google Cloud Fraud Defense. Version 2 shows the
"I'm not a robot" checkbox, with an invisible variant that runs when the visitor clicks an existing
button. Version 3 shows nothing and returns a score, where "1.0 is very likely a good interaction,
0.0 is very likely a bot"; Google suggests starting with a threshold of 0.5, and the site decides
what to do below it.

**hCaptcha** shows a checkbox and image challenges by default, can run invisibly when called with
`hcaptcha.execute()`, and offers a "Low Friction 99.9% Passive Mode" on Pro and a "Passive
(No-CAPTCHA) Mode" and risk scores on Enterprise.

## Privacy and data

- **Turnstile** can be used without routing a site through Cloudflare. Its privacy addendum lists
  the signals it collects (the client IP address, TLS fingerprint, User-Agent header, and the
  sitekey with its origin) and says they are used "solely to detect and block bots". Sites that use
  Invisible mode must reference that addendum in their own privacy policy.
- **reCAPTCHA** and **hCaptcha** each publish their own terms; compare them with your privacy
  policy and your visitors' jurisdictions before choosing.

## Server-side verification compared

All three follow the same pattern: the server posts its secret key and the token, and reads a JSON
reply with `success` and `error-codes`. The details differ:

- **Turnstile** accepts form data or JSON, only by `POST`, and returns the `hostname`, `action` and
  `cdata` the token was issued for, plus an `ephemeral_id` on Enterprise. An expired or reused
  token fails with `timeout-or-duplicate`.
- **reCAPTCHA** takes `secret`, `response` and an optional `remoteip`, and v3 adds `score` and
  `action` to the reply. A stale or reused token also fails with `timeout-or-duplicate`.
- **hCaptcha** takes form data only ("Do not send JSON data"), recommends `remoteip`, and has its
  own codes for expired and replayed tokens: `expired-input-response` and `already-seen-response`.

[Cloudflare Turnstile siteverify errors](https://zerocaptcha.io/blog/cloudflare-turnstile-siteverify-errors) lists every
code Turnstile returns.

## Switching between them

Turnstile is designed to replace the other two with little code:

- **From reCAPTCHA:** load `api.js?compat=recaptcha` and Turnstile renders reCAPTCHA's markup,
  posts the token as `g-recaptcha-response` and registers itself as `grecaptcha`. The server
  switches to Turnstile's siteverify URL. Cloudflare says compatibility covers "up to reCAPTCHA v2"
  and that siteverify does not accept `GET`.
- **From hCaptcha:** replace the siteverify URL, the `h-captcha-response` field with
  `cf-turnstile-response`, and `hcaptcha.render()` with `turnstile.render()`.

hCaptcha also inserts a `window.grecaptcha` compatibility hook by default, which is why pages that
moved between the three sometimes keep another provider's field name. Check the actual field the
form posts before automating it.

## What automation meets

For a developer who tests or automates pages they are allowed to, the work has the same shape for
all three: find the sitekey, obtain a token, and submit it in the field the page expects before it
expires. What differs:

- **Which widget is on the page.** `challenges.cloudflare.com` or `class="cf-turnstile"` means
  Turnstile; `google.com/recaptcha`, `recaptcha.net` or `class="g-recaptcha"` means reCAPTCHA;
  `hcaptcha.com` or `class="h-captcha"` means hCaptcha. A full-page "Just a moment..." screen is
  none of them: it is a Cloudflare challenge page. See [Cloudflare challenge page vs
  Turnstile](https://zerocaptcha.io/guides/cloudflare-challenge-vs-turnstile).
- **Time budget.** A Turnstile token leaves five minutes to submit the form; reCAPTCHA and hCaptcha
  leave two. See [Cloudflare Turnstile token expiry](https://zerocaptcha.io/guides/cloudflare-turnstile-token-expiry).
- **Extra parameters.** Turnstile widgets may set an `action` and `cData` that a solving task should
  repeat: see [Cloudflare Turnstile action and cData](https://zerocaptcha.io/guides/cloudflare-turnstile-action-and-cdata).
  reCAPTCHA v3 has an action too, and its score matters as much as its token.
- **Browser automation.** Cloudflare says automated testing suites such as Selenium, Cypress and
  Playwright "are detected as bots by Turnstile". Testing your own forms is easier with each
  provider's test keys: [test Cloudflare Turnstile in CI](https://zerocaptcha.io/guides/test-cloudflare-turnstile-in-ci)
  lists Cloudflare's.

## What ZeroCaptcha solves

ZeroCaptcha solves Cloudflare Turnstile: a task needs the page URL and the widget's sitekey, and
returns a token with the time it expires, charged only when the token is ready. It does not solve
reCAPTCHA or hCaptcha: their task types are refused at no charge, with `ERROR_TASK_NOT_SUPPORTED`
in the createTask format.
The [Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver) shows the flow in ten languages and
tools, and [pricing](https://zerocaptcha.io/pricing) lists the price per 1,000 solved tasks.

## Sources

- Cloudflare Turnstile: [overview](https://developers.cloudflare.com/turnstile/),
  [widget modes](https://developers.cloudflare.com/turnstile/concepts/widget/),
  [plans](https://developers.cloudflare.com/turnstile/plans/),
  [server-side validation](https://developers.cloudflare.com/turnstile/get-started/server-side-validation/),
  [migrating from reCAPTCHA](https://developers.cloudflare.com/turnstile/migration/recaptcha/),
  [migrating from hCaptcha](https://developers.cloudflare.com/turnstile/migration/hcaptcha/),
  [testing](https://developers.cloudflare.com/turnstile/troubleshooting/testing/) and the
  [privacy addendum](https://www.cloudflare.com/turnstile-privacy-policy/) (checked 1 October
  2026).
- Google reCAPTCHA: [versions](https://developers.google.com/recaptcha/docs/versions),
  [v3](https://developers.google.com/recaptcha/docs/v3),
  [verifying the response](https://developers.google.com/recaptcha/docs/verify) and
  [tiers and pricing](https://docs.cloud.google.com/recaptcha/docs/compare-tiers) (checked 1
  October 2026).
- hCaptcha: [developer guide](https://docs.hcaptcha.com/),
  [configuration](https://docs.hcaptcha.com/configuration) and
  [pricing](https://www.hcaptcha.com/pricing) (checked 1 October 2026).

## Questions

### What is the difference between Cloudflare Turnstile and reCAPTCHA?

Turnstile runs non-interactive browser checks and at most asks for a checkbox, with no image puzzles, and is free for up to 20 widgets. reCAPTCHA v2 shows a checkbox and sometimes image challenges, v3 returns a score, and Google's Fraud Defense tiers are free up to 10,000 assessments a month.

### How long are Turnstile, reCAPTCHA and hCaptcha tokens valid?

A Cloudflare Turnstile token is valid for 300 seconds, a reCAPTCHA token for two minutes, and an hCaptcha token for 120 seconds by default. All three can be verified only once.

### Does ZeroCaptcha solve reCAPTCHA or hCaptcha?

No. ZeroCaptcha solves Cloudflare Turnstile and Cloudflare challenge pages. Task types for reCAPTCHA or hCaptcha are refused at no charge, with ERROR_TASK_NOT_SUPPORTED in the createTask format.
