Comparison
WAF Challenges Across Vendors: AWS, Akamai, Fastly, SafeLine
How Cloudflare, AWS WAF, Akamai Bot Manager, Fastly Next-Gen WAF and SafeLine challenge a request: status codes, headers, cookies and lifetimes, side by side.
By ZeroCaptcha Engineering6 min readPublished
Most web application firewalls can answer a suspicious request with a challenge instead of a
block, but each vendor does it differently. Cloudflare serves a challenge page (HTTP 403,
header cf-mitigated: challenge) and sets cf_clearance for the zone’s Challenge Passage. AWS WAF
answers its Challenge action with HTTP 202 and its CAPTCHA action with HTTP 405, both marked
by the header x-amzn-waf-action, and records a pass in the aws-waf-token cookie, 300 seconds by
default. Akamai Bot Manager uses a Google reCAPTCHA or its own proof-of-work “crypto” challenge.
Fastly’s Next-Gen WAF has dynamic, non-interactive and CAPTCHA challenges, remembered for an hour.
SafeLine, an open-source WAF, has an anti-bot challenge. ZeroCaptcha solves Cloudflare’s
challenges only.
This comparison sets the five side by side from each vendor’s own documentation, as checked on 1 October 2026, and shows how to tell them apart in code. Automate only sites you are allowed to: see responsible captcha automation.
Side by side
| Vendor | Challenge types | How the response looks | What a pass leaves | How long it lasts |
|---|---|---|---|---|
| Cloudflare | Managed, Non-Interactive (API value js_challenge) and Interactive challenge pages; Cloudflare Turnstile widgets in forms |
HTTP 403, cf-mitigated: challenge, HTML |
cf_clearance cookie |
The zone’s Challenge Passage |
| AWS WAF | Challenge (silent, in the background) and CAPTCHA (a puzzle) | Challenge: HTTP 202; CAPTCHA: HTTP 405; header x-amzn-waf-action |
aws-waf-token cookie |
Immunity time, 300 seconds by default |
| Akamai Bot Manager | GOOGLE_RECAPTCHA, AKAMAI_WEB_CRYPTO, AKAMAI_MOBILE_CRYPTO |
Not stated in the reference we could read | Not stated | A challenge interval of 1 to 7,200 seconds |
| Fastly Next-Gen WAF | Dynamic, non-interactive (JavaScript proof-of-work) and interactive (CAPTCHA) | Not stated | _fs_ch_st_ and _fs_ch_cp_ cookies |
1 hour by default |
| SafeLine | Anti-bot challenge; also an authentication (password) challenge | Not stated | Not stated | Not stated |
“Not stated” means the vendor’s public documentation we read does not say; it does not mean there is nothing to say.
Cloudflare
Cloudflare’s WAF custom rules, Bot Management and rate limiting rules can issue interstitial
challenge pages: non-interactive, managed or interactive. Cloudflare sets cf-mitigated: challenge
on all of them, serves them as text/html “even if you requested a different resource type”, and
its Error 403 page lists challenge actions among the causes of a 403. A passed challenge sets cf_clearance, tied to
the visitor and device that earned it. The details are in
Cloudflare challenge types and
Cloudflare WAF rules explained.
AWS WAF
AWS WAF has two rule actions of this kind. CAPTCHA “Requires the end user to solve a CAPTCHA puzzle to prove that a human being is sending the request.” Challenge “Runs a silent challenge that requires the client session to verify that it’s a browser, and not a bot.” A request with a valid token passes on as if counted; one without gets a response:
- Challenge: “The header
x-amzn-waf-actionwith a value ofchallenge” and “The HTTP status code202 Request Accepted”, with a challenge script only if the request’sAcceptheader asks fortext/html. - CAPTCHA:
x-amzn-waf-action: captchaand “The HTTP status code405 Method Not Allowed”, with the puzzle page for HTML requests.
“The token is stored in a cookie named aws-waf-token” and is encrypted. How long a pass lasts is
the immunity time: “The default protection pack (web ACL) setting for both immunity times is 300
seconds”, with a minimum of 300 seconds for challenges and 60 for CAPTCHAs, and a maximum of three
days. AWS also notes that both actions cost the site owner extra, and that “CAPTCHA puzzles and
silent challenges can only run when browsers are accessing HTTPS endpoints.”
Akamai Bot Manager
Akamai’s application security API defines three challenge types for a challenge action: “Choose
GOOGLE_RECAPTCHA to make users solve a CAPTCHA puzzle”, and AKAMAI_WEB_CRYPTO or
AKAMAI_MOBILE_CRYPTO to make web or mobile clients “solve a proof-of-work cryptographic challenge”.
The owner sets a challenge interval, “Time between challenges”, from 1 to 7,200 seconds, and, for the
crypto types, how many seconds the client should spend on the challenge, up to 120: “The longer the
duration, the more difficult the challenge.” Akamai’s product documentation is behind a sign-in, so
the response format is not covered here.
Fastly Next-Gen WAF
Fastly calls them client challenges: “security tasks that verify users are human or accessing your web application through a legitimate browser”. There are three:
- Dynamic: “Allow Fastly to automatically choose the most appropriate client challenge”;
- Non-interactive: a “JavaScript proof-of-work”, in which the client proves “that it is running a JavaScript-compatible browser by solving what is essentially a JavaScript math problem”;
- Interactive (CAPTCHA): the client is shown “a random alphanumeric string” to type in.
A client that passes is issued “a token, which it stores as a browser cookie”, and “The token
defaults to a 1 hour expiration.” The documentation’s limitations section names the cookies
_fs_ch_st_ and _fs_ch_cp_.
SafeLine
SafeLine describes itself as a self-hosted web application firewall “to protect your web apps from attacks and exploits”. It runs as a reverse proxy and is published under the GPL-3.0 licence. Its README lists “Anti-Bot challenges to protect your website from bot attacks, human users will be allowed, crawlers and bots will be blocked”, an authentication challenge in which “visitors need to enter the password”, rate limiting, and “Dynamic Protection”, which encrypts a site’s HTML and JavaScript on each visit. Because it is self-hosted, each site runs its own version and settings.
Telling them apart in code
Only two vendors document a response header that marks a challenge, so a client can recognise those two for certain:
import requests
def challenge_vendor(response): if response.headers.get("cf-mitigated") == "challenge": return "Cloudflare challenge page" action = response.headers.get("x-amzn-waf-action") if action in ("challenge", "captcha"): return f"AWS WAF {action}" return None
response = requests.get("https://shop.example.com/", timeout=30, headers={"Accept": "text/html"})print(response.status_code, challenge_vendor(response) or "no documented challenge marker")For the others, look at the page in a browser: the challenge page usually names its vendor. Don’t treat an unexplained 202 or 405 as success or failure until you know which WAF sent it.
What ZeroCaptcha does, and doesn’t
ZeroCaptcha solves Cloudflare only: Cloudflare Turnstile widgets on the Cloudflare Turnstile solver, and Cloudflare challenge pages, whose cf_clearance cookie a challenge task returns with its user agent, on the Cloudflare WAF and 5-second challenge solver. It does not solve AWS WAF, Akamai, Fastly, SafeLine or Imperva challenges, and not reCAPTCHA or hCaptcha, including Akamai’s reCAPTCHA-based type. If a site behind another vendor’s WAF challenges your client, the honest options are to ask the site owner for access, or to use a real browser that passes it as any visitor would. The basics of what a WAF is are in what is a WAF.
ZeroCaptcha is not affiliated with Amazon Web Services, Akamai, Fastly or Chaitin Tech (SafeLine); their names appear only to describe their products, and the facts about them come from their own documentation, as checked on 1 October 2026.
Sources
- AWS WAF: CAPTCHA and Challenge, action behavior, token characteristics and immunity times (checked 1 October 2026).
- Akamai: create a challenge action (checked 1 October 2026).
- Fastly: about client challenges (checked 1 October 2026).
- SafeLine, README (checked 1 October 2026).
- Cloudflare challenges: challenge pages and detect a challenge response (checked 1 October 2026).
- Cloudflare: Error 403 (checked 1 October 2026).
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.