Skip to content

Explainer

Choosing Proxies for Cloudflare Turnstile and Challenge Solving

When a Cloudflare Turnstile task needs a proxy at all, residential vs datacenter vs mobile, sticky sessions, regions, and the rules a proxy must meet.

By 5 min readPublished Updated

Most Cloudflare Turnstile tasks need no proxy at all: solve proxyless, submit the token, done. A proxy earns its cost in two cases: the site rejects tokens earned away from the visitor’s network, or it answers only visitors from some regions. For Cloudflare challenge pages it is different: Cloudflare ties the cf_clearance cookie to the visitor and device it was issued to, so solving and browsing should use the same proxy. This article covers when to add a proxy, which kind, and the settings that decide whether it works.

Step 1: try proxyless first

TurnstileTaskProxyless needs only the page URL and the sitekey. It has no proxy to fail, costs the proxyless price on the pricing page, and is the right default. Switch to TurnstileTask, which runs through your proxy, only when you see one of these:

  • The site’s form rejects proxyless tokens that are otherwise fresh and correct (the same token flow works when a person does it from your network).
  • The page with the widget is not reachable, or looks different, from outside a region.
  • The site’s own terms or setup require requests from a specific network, such as an allowlisted address you control.

Solve Cloudflare Turnstile with a proxy shows how to pass the proxy in each API format.

Step 2: pick the proxy type

Type Where the address comes from Strengths Weaknesses
Datacenter A hosting provider’s network Cheap, fast, stable Hosting networks are the first place security rules look
ISP (static residential) Addresses registered to a consumer ISP, hosted in a data center Stable like datacenter, looks like an ISP Fewer locations, more expensive
Residential Real household connections, through a proxy network Looks like ordinary visitors Priced by traffic, speed varies, sessions end without warning
Mobile Mobile carriers’ networks, shared by many phones Rarely blocked, since blocking hits many real users The most expensive; slower

How a site treats each type is the site’s own setting. Cloudflare lets site owners write WAF rules on the visitor’s network (its autonomous system number) and country, and its free Bot Fight Mode is documented as detecting “simple bots from cloud hosting providers and headless browsers”. A site that challenges hosting networks will challenge datacenter proxies whatever else you do. Match the type to what the site accepts, and measure: the cheapest type that gives accepted tokens is the right one.

Step 3: sticky sessions, not per-request rotation

A solving task opens several connections through your proxy over a few seconds. Proxy networks offer two modes:

  • Rotating: a new exit address for every connection. A task whose address changes mid-solve looks like several visitors, and can fail.
  • Sticky: the same exit address for a set time, often 1 to 30 minutes, usually chosen by a session ID in the proxy username.

Use a sticky session that outlasts the task, and, for a site that checks the network, reuse the same session to submit the token. For challenge pages, the session must last as long as you use the clearance. Cloudflare says the cookie “is securely tied to the specific visitor and device it was issued to”, and a Managed Challenge solved from a different IP than the one it was issued to is not valid. ZeroCaptcha’s challenge task runs through your proxy for that reason, and returns the cf_clearance cookie with the user agent to send with it. See the cf_clearance cookie explained.

Step 4: choose the region

Pick an exit country the site expects its visitors to come from. A shop that sells only in Germany may challenge, or refuse with error 1009, visitors from elsewhere. When the site serves everyone, choose a region near the site’s audience rather than near you.

What ZeroCaptcha requires of a proxy

  • HTTP or HTTPS. SOCKS4 and SOCKS5 are refused when the task is created, before anything is held.
  • A public address. A proxy on a private or reserved address, such as 10.0.0.0/8 or 127.0.0.1, is refused; so is a host name that resolves to one when the task runs, and that task fails without a charge.
  • Reachable from the internet. The solver connects to it from ZeroCaptcha’s servers, so a proxy that only works inside your office or VPC fails.
  • Credentials made for the job. The proxy’s username and password travel with the task. They are never logged and are deleted when the task ends, but use credentials you can rotate.

A task whose proxy fails ends failed and costs nothing; the hold returns to your balance at once.

Pass the proxy

In the compatible format, add the proxy to a TurnstileTask, as one URL:

{
"clientKey": "zc_live_…",
"task": {
"type": "TurnstileTask",
"websiteURL": "https://shop.example.com/login",
"websiteKey": "0x4AAAAAAAB1cD2eF3gH4iJ5",
"metadata": { "action": "login", "cdata": "session-7f3a9c2e" },
"proxy": "http://user-session-7f3a:secret@proxy.example.net:8080"
}
}

The user-session-7f3a username shows the common way providers pin a sticky session; your provider’s documentation gives its exact format. The proxy changes nothing else: metadata still carries the widget’s data-action and data-cdata (or the action and cData options of turnstile.render()), and any it does not set are left out.

Checklist

  1. Start proxyless; add a proxy only when the site gives you a reason.
  2. Choose the cheapest type the site accepts, measured on your own pages.
  3. Use a sticky session longer than the task, and longer than you will use a clearance.
  4. Choose an exit region the site serves.
  5. Submit the token, or use the clearance, through the same session.
  6. Use HTTP or HTTPS proxies with credentials you can rotate.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

Do I need a proxy to solve Cloudflare Turnstile?

Usually not. A proxyless task is the default and works for most sites. Use a proxy when the site rejects proxyless tokens, or serves the page only to some regions.

Residential or datacenter proxies for Cloudflare?

Datacenter addresses are cheaper and faster but belong to hosting networks, which Cloudflare's security features often treat with more suspicion. Residential and mobile addresses cost more and are challenged less. Start with what the site accepts, not with the most expensive option.

Why does a proxy need a sticky session for solving?

A task runs for several seconds through one connection path. If a rotating proxy changes its exit address mid-task, the solve can fail; for a Cloudflare challenge page, Cloudflare ties the clearance to the visitor and device it was issued to.

Read next

This article is part of the Cloudflare Turnstile solver hub. Every task is charged only when a token is ready.

Get an API key