Skip to content

Comparison

WAF Challenges Across Vendors: AWS, Akamai, Fastly, SafeLine

How Cloudflare, AWS WAF, Akamai Bot Manager, Fastly Next-Gen WAF and SafeLine challenge a request: status codes, headers, cookies and lifetimes, side by side.

By 6 min readPublished

Most web application firewalls can answer a suspicious request with a challenge instead of a block, but each vendor does it differently. Cloudflare serves a challenge page (HTTP 403, header cf-mitigated: challenge) and sets cf_clearance for the zone’s Challenge Passage. AWS WAF answers its Challenge action with HTTP 202 and its CAPTCHA action with HTTP 405, both marked by the header x-amzn-waf-action, and records a pass in the aws-waf-token cookie, 300 seconds by default. Akamai Bot Manager uses a Google reCAPTCHA or its own proof-of-work “crypto” challenge. Fastly’s Next-Gen WAF has dynamic, non-interactive and CAPTCHA challenges, remembered for an hour. SafeLine, an open-source WAF, has an anti-bot challenge. ZeroCaptcha solves Cloudflare’s challenges only.

This comparison sets the five side by side from each vendor’s own documentation, as checked on 1 October 2026, and shows how to tell them apart in code. Automate only sites you are allowed to: see responsible captcha automation.

Side by side

Vendor Challenge types How the response looks What a pass leaves How long it lasts
Cloudflare Managed, Non-Interactive (API value js_challenge) and Interactive challenge pages; Cloudflare Turnstile widgets in forms HTTP 403, cf-mitigated: challenge, HTML cf_clearance cookie The zone’s Challenge Passage
AWS WAF Challenge (silent, in the background) and CAPTCHA (a puzzle) Challenge: HTTP 202; CAPTCHA: HTTP 405; header x-amzn-waf-action aws-waf-token cookie Immunity time, 300 seconds by default
Akamai Bot Manager GOOGLE_RECAPTCHA, AKAMAI_WEB_CRYPTO, AKAMAI_MOBILE_CRYPTO Not stated in the reference we could read Not stated A challenge interval of 1 to 7,200 seconds
Fastly Next-Gen WAF Dynamic, non-interactive (JavaScript proof-of-work) and interactive (CAPTCHA) Not stated _fs_ch_st_ and _fs_ch_cp_ cookies 1 hour by default
SafeLine Anti-bot challenge; also an authentication (password) challenge Not stated Not stated Not stated

“Not stated” means the vendor’s public documentation we read does not say; it does not mean there is nothing to say.

Cloudflare

Cloudflare’s WAF custom rules, Bot Management and rate limiting rules can issue interstitial challenge pages: non-interactive, managed or interactive. Cloudflare sets cf-mitigated: challenge on all of them, serves them as text/html “even if you requested a different resource type”, and its Error 403 page lists challenge actions among the causes of a 403. A passed challenge sets cf_clearance, tied to the visitor and device that earned it. The details are in Cloudflare challenge types and Cloudflare WAF rules explained.

AWS WAF

AWS WAF has two rule actions of this kind. CAPTCHA “Requires the end user to solve a CAPTCHA puzzle to prove that a human being is sending the request.” Challenge “Runs a silent challenge that requires the client session to verify that it’s a browser, and not a bot.” A request with a valid token passes on as if counted; one without gets a response:

  • Challenge: “The header x-amzn-waf-action with a value of challenge” and “The HTTP status code 202 Request Accepted”, with a challenge script only if the request’s Accept header asks for text/html.
  • CAPTCHA: x-amzn-waf-action: captcha and “The HTTP status code 405 Method Not Allowed”, with the puzzle page for HTML requests.

“The token is stored in a cookie named aws-waf-token” and is encrypted. How long a pass lasts is the immunity time: “The default protection pack (web ACL) setting for both immunity times is 300 seconds”, with a minimum of 300 seconds for challenges and 60 for CAPTCHAs, and a maximum of three days. AWS also notes that both actions cost the site owner extra, and that “CAPTCHA puzzles and silent challenges can only run when browsers are accessing HTTPS endpoints.”

Akamai Bot Manager

Akamai’s application security API defines three challenge types for a challenge action: “Choose GOOGLE_RECAPTCHA to make users solve a CAPTCHA puzzle”, and AKAMAI_WEB_CRYPTO or AKAMAI_MOBILE_CRYPTO to make web or mobile clients “solve a proof-of-work cryptographic challenge”. The owner sets a challenge interval, “Time between challenges”, from 1 to 7,200 seconds, and, for the crypto types, how many seconds the client should spend on the challenge, up to 120: “The longer the duration, the more difficult the challenge.” Akamai’s product documentation is behind a sign-in, so the response format is not covered here.

Fastly Next-Gen WAF

Fastly calls them client challenges: “security tasks that verify users are human or accessing your web application through a legitimate browser”. There are three:

  • Dynamic: “Allow Fastly to automatically choose the most appropriate client challenge”;
  • Non-interactive: a “JavaScript proof-of-work”, in which the client proves “that it is running a JavaScript-compatible browser by solving what is essentially a JavaScript math problem”;
  • Interactive (CAPTCHA): the client is shown “a random alphanumeric string” to type in.

A client that passes is issued “a token, which it stores as a browser cookie”, and “The token defaults to a 1 hour expiration.” The documentation’s limitations section names the cookies _fs_ch_st_ and _fs_ch_cp_.

SafeLine

SafeLine describes itself as a self-hosted web application firewall “to protect your web apps from attacks and exploits”. It runs as a reverse proxy and is published under the GPL-3.0 licence. Its README lists “Anti-Bot challenges to protect your website from bot attacks, human users will be allowed, crawlers and bots will be blocked”, an authentication challenge in which “visitors need to enter the password”, rate limiting, and “Dynamic Protection”, which encrypts a site’s HTML and JavaScript on each visit. Because it is self-hosted, each site runs its own version and settings.

Telling them apart in code

Only two vendors document a response header that marks a challenge, so a client can recognise those two for certain:

import requests
def challenge_vendor(response):
if response.headers.get("cf-mitigated") == "challenge":
return "Cloudflare challenge page"
action = response.headers.get("x-amzn-waf-action")
if action in ("challenge", "captcha"):
return f"AWS WAF {action}"
return None
response = requests.get("https://shop.example.com/", timeout=30, headers={"Accept": "text/html"})
print(response.status_code, challenge_vendor(response) or "no documented challenge marker")

For the others, look at the page in a browser: the challenge page usually names its vendor. Don’t treat an unexplained 202 or 405 as success or failure until you know which WAF sent it.

What ZeroCaptcha does, and doesn’t

ZeroCaptcha solves Cloudflare only: Cloudflare Turnstile widgets on the Cloudflare Turnstile solver, and Cloudflare challenge pages, whose cf_clearance cookie a challenge task returns with its user agent, on the Cloudflare WAF and 5-second challenge solver. It does not solve AWS WAF, Akamai, Fastly, SafeLine or Imperva challenges, and not reCAPTCHA or hCaptcha, including Akamai’s reCAPTCHA-based type. If a site behind another vendor’s WAF challenges your client, the honest options are to ask the site owner for access, or to use a real browser that passes it as any visitor would. The basics of what a WAF is are in what is a WAF.

ZeroCaptcha is not affiliated with Amazon Web Services, Akamai, Fastly or Chaitin Tech (SafeLine); their names appear only to describe their products, and the facts about them come from their own documentation, as checked on 1 October 2026.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

How do I recognise an AWS WAF challenge?

AWS WAF answers a Challenge action with HTTP 202 and the header x-amzn-waf-action: challenge, and a CAPTCHA action with HTTP 405 and x-amzn-waf-action: captcha. A client that passes gets an aws-waf-token cookie.

What challenges does Akamai Bot Manager use?

Its challenge actions come in three types: GOOGLE_RECAPTCHA, which asks users to solve a CAPTCHA puzzle, and AKAMAI_WEB_CRYPTO and AKAMAI_MOBILE_CRYPTO, which make web or mobile clients solve a proof-of-work cryptographic challenge.

Does ZeroCaptcha solve AWS WAF, Akamai or Fastly challenges?

No. ZeroCaptcha solves Cloudflare Turnstile widgets and Cloudflare challenge pages only. It does not solve other vendors' challenges, reCAPTCHA or hCaptcha.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key