# WAF Challenges Across Vendors: AWS, Akamai, Fastly, SafeLine

> How Cloudflare, AWS WAF, Akamai Bot Manager, Fastly Next-Gen WAF and SafeLine challenge a request: status codes, headers, cookies and lifetimes, side by side.

- Source: https://zerocaptcha.io/blog/waf-challenges-across-vendors
- Published: 2026-10-01
- Author: ZeroCaptcha Engineering

Most web application firewalls can answer a suspicious request with a **challenge** instead of a
block, but each vendor does it differently. **Cloudflare** serves a challenge page (HTTP 403,
header `cf-mitigated: challenge`) and sets `cf_clearance` for the zone's Challenge Passage. **AWS WAF**
answers its Challenge action with HTTP **202** and its CAPTCHA action with HTTP **405**, both marked
by the header `x-amzn-waf-action`, and records a pass in the `aws-waf-token` cookie, 300 seconds by
default. **Akamai Bot Manager** uses a Google reCAPTCHA or its own proof-of-work "crypto" challenge.
**Fastly's Next-Gen WAF** has dynamic, non-interactive and CAPTCHA challenges, remembered for an hour.
**SafeLine**, an open-source WAF, has an anti-bot challenge. ZeroCaptcha solves Cloudflare's
challenges only.

This comparison sets the five side by side from each vendor's own documentation, as checked on
1 October 2026, and shows how to tell them apart in code. Automate only sites you are allowed to:
see [responsible captcha automation](https://zerocaptcha.io/guides/responsible-captcha-automation).

## Side by side

| Vendor | Challenge types | How the response looks | What a pass leaves | How long it lasts |
| --- | --- | --- | --- | --- |
| Cloudflare | Managed, Non-Interactive (API value `js_challenge`) and Interactive challenge pages; Cloudflare Turnstile widgets in forms | HTTP 403, `cf-mitigated: challenge`, HTML | `cf_clearance` cookie | The zone's Challenge Passage |
| AWS WAF | Challenge (silent, in the background) and CAPTCHA (a puzzle) | Challenge: HTTP 202; CAPTCHA: HTTP 405; header `x-amzn-waf-action` | `aws-waf-token` cookie | Immunity time, 300 seconds by default |
| Akamai Bot Manager | `GOOGLE_RECAPTCHA`, `AKAMAI_WEB_CRYPTO`, `AKAMAI_MOBILE_CRYPTO` | Not stated in the reference we could read | Not stated | A challenge interval of 1 to 7,200 seconds |
| Fastly Next-Gen WAF | Dynamic, non-interactive (JavaScript proof-of-work) and interactive (CAPTCHA) | Not stated | `_fs_ch_st_` and `_fs_ch_cp_` cookies | 1 hour by default |
| SafeLine | Anti-bot challenge; also an authentication (password) challenge | Not stated | Not stated | Not stated |

"Not stated" means the vendor's public documentation we read does not say; it does not mean there
is nothing to say.

## Cloudflare

Cloudflare's WAF custom rules, Bot Management and rate limiting rules can issue interstitial
challenge pages: non-interactive, managed or interactive. Cloudflare sets `cf-mitigated: challenge`
on all of them, serves them as `text/html` "even if you requested a different resource type", and
its Error 403 page lists challenge actions among the causes of a 403. A passed challenge sets `cf_clearance`, tied to
the visitor and device that earned it. The details are in
[Cloudflare challenge types](https://zerocaptcha.io/blog/cloudflare-challenge-types) and
[Cloudflare WAF rules explained](https://zerocaptcha.io/blog/cloudflare-waf-rules-explained).

## AWS WAF

AWS WAF has two rule actions of this kind. **CAPTCHA** "Requires the end user to solve a CAPTCHA
puzzle to prove that a human being is sending the request." **Challenge** "Runs a silent challenge
that requires the client session to verify that it's a browser, and not a bot." A request with a
valid token passes on as if counted; one without gets a response:

- **Challenge:** "The header `x-amzn-waf-action` with a value of `challenge`" and "The HTTP status
  code `202 Request Accepted`", with a challenge script only if the request's `Accept` header asks
  for `text/html`.
- **CAPTCHA:** `x-amzn-waf-action: captcha` and "The HTTP status code `405 Method Not Allowed`",
  with the puzzle page for HTML requests.

"The token is stored in a cookie named `aws-waf-token`" and is encrypted. How long a pass lasts is
the immunity time: "The default protection pack (web ACL) setting for both immunity times is 300
seconds", with a minimum of 300 seconds for challenges and 60 for CAPTCHAs, and a maximum of three
days. AWS also notes that both actions cost the site owner extra, and that "CAPTCHA puzzles and
silent challenges can only run when browsers are accessing HTTPS endpoints."

## Akamai Bot Manager

Akamai's application security API defines three challenge types for a challenge action: "Choose
`GOOGLE_RECAPTCHA` to make users solve a CAPTCHA puzzle", and `AKAMAI_WEB_CRYPTO` or
`AKAMAI_MOBILE_CRYPTO` to make web or mobile clients "solve a proof-of-work cryptographic challenge".
The owner sets a challenge interval, "Time between challenges", from 1 to 7,200 seconds, and, for the
crypto types, how many seconds the client should spend on the challenge, up to 120: "The longer the
duration, the more difficult the challenge." Akamai's product documentation is behind a sign-in, so
the response format is not covered here.

## Fastly Next-Gen WAF

Fastly calls them client challenges: "security tasks that verify users are human or accessing your web
application through a legitimate browser". There are three:

- **Dynamic:** "Allow Fastly to automatically choose the most appropriate client challenge";
- **Non-interactive:** a "JavaScript proof-of-work", in which the client proves "that it is running
  a JavaScript-compatible browser by solving what is essentially a JavaScript math problem";
- **Interactive (CAPTCHA):** the client is shown "a random alphanumeric string" to type in.

A client that passes is issued "a token, which it stores as a browser cookie", and "The token
defaults to a 1 hour expiration." The documentation's limitations section names the cookies
`_fs_ch_st_` and `_fs_ch_cp_`.

## SafeLine

SafeLine describes itself as a self-hosted web application firewall "to protect your web apps from
attacks and exploits". It runs as a reverse proxy and is published under the GPL-3.0 licence. Its README lists "Anti-Bot challenges
to protect your website from bot attacks, human users will be allowed, crawlers and bots will be
blocked", an authentication challenge in which "visitors need to enter the password", rate limiting,
and "Dynamic Protection", which encrypts a site's HTML and JavaScript on each visit. Because it is
self-hosted, each site runs its own version and settings.

## Telling them apart in code

Only two vendors document a response header that marks a challenge, so a client can recognise those
two for certain:

```python
import requests


def challenge_vendor(response):
    if response.headers.get("cf-mitigated") == "challenge":
        return "Cloudflare challenge page"
    action = response.headers.get("x-amzn-waf-action")
    if action in ("challenge", "captcha"):
        return f"AWS WAF {action}"
    return None


response = requests.get("https://shop.example.com/", timeout=30, headers={"Accept": "text/html"})
print(response.status_code, challenge_vendor(response) or "no documented challenge marker")
```

For the others, look at the page in a browser: the challenge page usually names its vendor. Don't
treat an unexplained 202 or 405 as success or failure until you know which WAF sent it.

## What ZeroCaptcha does, and doesn't

ZeroCaptcha solves **Cloudflare** only: Cloudflare Turnstile widgets on the
[Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver),
and Cloudflare challenge pages, whose cf_clearance cookie a challenge task returns with its user agent, on the [Cloudflare WAF and 5-second challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver).
It does not solve AWS WAF, Akamai, Fastly, SafeLine or Imperva challenges, and not reCAPTCHA or
hCaptcha, including Akamai's reCAPTCHA-based type. If a site behind another vendor's WAF challenges
your client, the honest options are to ask the site owner for access, or to use a real browser that
passes it as any visitor would. The basics of what a WAF is are in
[what is a WAF](https://zerocaptcha.io/blog/what-is-a-waf).

ZeroCaptcha is not affiliated with Amazon Web Services, Akamai, Fastly or Chaitin Tech (SafeLine);
their names appear only to describe their products, and the facts about them come from their own
documentation, as checked on 1 October 2026.

## Sources

- [AWS WAF: CAPTCHA and Challenge](https://docs.aws.amazon.com/waf/latest/developerguide/waf-captcha-and-challenge.html),
  [action behavior](https://docs.aws.amazon.com/waf/latest/developerguide/waf-captcha-and-challenge-actions.html),
  [token characteristics](https://docs.aws.amazon.com/waf/latest/developerguide/waf-tokens-details.html)
  and [immunity times](https://docs.aws.amazon.com/waf/latest/developerguide/waf-tokens-immunity-times.html)
  (checked 1 October 2026).
- [Akamai: create a challenge action](https://techdocs.akamai.com/application-security/reference/post-challenge-action)
  (checked 1 October 2026).
- [Fastly: about client challenges](https://www.fastly.com/documentation/guides/next-gen-waf/using-ngwaf/client-challenges/about-client-challenges/)
  (checked 1 October 2026).
- [SafeLine](https://github.com/chaitin/SafeLine), README (checked 1 October 2026).
- [Cloudflare challenges: challenge pages](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/)
  and [detect a challenge response](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/detect-response/)
  (checked 1 October 2026).
- [Cloudflare: Error 403](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/4xx-client-error/error-403/)
  (checked 1 October 2026).

## Questions

### How do I recognise an AWS WAF challenge?

AWS WAF answers a Challenge action with HTTP 202 and the header x-amzn-waf-action: challenge, and a CAPTCHA action with HTTP 405 and x-amzn-waf-action: captcha. A client that passes gets an aws-waf-token cookie.

### What challenges does Akamai Bot Manager use?

Its challenge actions come in three types: GOOGLE_RECAPTCHA, which asks users to solve a CAPTCHA puzzle, and AKAMAI_WEB_CRYPTO and AKAMAI_MOBILE_CRYPTO, which make web or mobile clients solve a proof-of-work cryptographic challenge.

### Does ZeroCaptcha solve AWS WAF, Akamai or Fastly challenges?

No. ZeroCaptcha solves Cloudflare Turnstile widgets and Cloudflare challenge pages only. It does not solve other vendors' challenges, reCAPTCHA or hCaptcha.
