Cloudflare 5-second JS challenge test page
This page sits behind a Cloudflare WAF custom rule whose action is the Non-Interactive Challenge, often still called the JS Challenge after its API value, js_challenge: the browser must run Cloudflare's JavaScript, which usually takes a few seconds, and never has to click. Reaching this text means you passed.
Your pass
LiveChecking your clearance…
Asking whether your browser sent cf_clearance with this page.
- WAF rule action
js_challenge(Non-Interactive Challenge (JS Challenge))- Rule
- Live on this site
- Clearance level
- Non-interactive: passes JS challenges only
- cf_clearance sent
- checking…
- Through Cloudflare
- checking…
- Clearance lasts
- The site's Challenge Passage, 30 minutes by default
Checking whether your browser holds a cf_clearance cookie for this site…
Test it again
A private window holds no clearance, so Cloudflare challenges it again: copy this page's link and open it there. Or point a task at the page, below.
What a task returns
A CloudflareChallengeTask opens this page through your proxy in a real browser and passes the challenge. Once it is ready, getTaskResult holds what that browser earned.
- solution.cookies.cf_clearance
- The clearance. Send it as the cf_clearance cookie with every request to the site.
- solution.userAgent
- The browser it was issued to. Send it as the User-Agent header, unchanged.
- expiresAt
- When the API stops serving it: 30 minutes after the solve. The site's Challenge Passage decides how long Cloudflare accepts it.
getTaskResult, once it is ready
{
"errorId": 0,
"taskId": "0192f3a4-7b1c-7d2e-9f10-3c4d5e6f7a8b",
"status": "ready",
"solution": {
"type": "cloudflare",
"token": "Dyw1BhDnEAGRy5fh…",
"userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36",
"cookies": { "cf_clearance": "Dyw1BhDnEAGRy5fh…" }
},
"expiresAt": "2026-09-30T14:32:14Z"
}Send the cookie and the user agent with every request, through the same proxy: Cloudflare ties the clearance to the visitor and device it was issued to. When the site challenges you again, create a new task.
Solve this page with the API
The complete createTask request for this page, then getTaskResult every 2 seconds until it is ready, then the result used as the page uses it. Set ZEROCAPTCHA_KEY to your API key, and PROXY_URL to your proxy.
- type
- CloudflareChallengeTask
- websiteURL
- https://zerocaptcha.io/captcha-test/cloudflare-js-challenge
- proxy
- Required: the clearance works only from its address
- callbackUrl
- Optional: called with the result when the task ends
- Idempotency-Key
- A header: sent again within 24 hours, it returns the first task
A task is charged at the listed price when it succeeds; a failed one costs nothing. The same task over REST, POST /v1/tasks, is inCloudflare WAF and 5-second challenges.
What this challenge is
The Non-Interactive Challenge, API value js_challenge, asks nothing of the visitor but a browser that runs its JavaScript to the end. Cloudflare says it typically takes less than five seconds. Its clearance is the lowest level and covers only Non-Interactive challenges.
Tools without a JavaScript engine, such as curl or wget, cannot pass it; a browser, or a task that runs one, can.
How to use the result
The task's result is the cf_clearance cookie and the user agent it was issued to. Send both with every request to the site, through the same proxy the task used: Cloudflare ties the cookie to "the specific visitor and device it was issued to", which in practice means that address and that user agent.
The clearance lasts for the zone's Challenge Passage time, 30 minutes by default, and covers challenge rules at its level or below. A client whose TLS handshake does not look like the browser its user agent names may be challenged again, so use a browser or a client that impersonates one.
How to recognise it on a real site
The first response has the header cf-mitigated: challenge and the content type text/html, whatever was asked for; in our checks the status was 403 and the page title "Just a moment...".
The challenge page loads its scripts from the site's own /cdn-cgi/challenge-platform/ path, then posts its result there and reloads the page.
Passing sets the cf_clearance cookie on the site, with SameSite=None, Secure and Partitioned.
<!-- The first response: HTTP 403, cf-mitigated: challenge, text/html -->
<title>Just a moment...</title>
<script>window._cf_chl_opt = { /* the challenge's settings */ };</script>
<script src="/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=…"></script>
<!-- Passing sets: cf_clearance=…; SameSite=None; Secure; Partitioned -->JS challenge questions
Which ZeroCaptcha task passes the Cloudflare 5-second JS challenge?
CloudflareChallengeTask, with the page's URL and your proxy. It returns the cf_clearance cookie and the user agent it was issued to; there is no proxyless challenge task, because the cookie only works from the address that earned it.
Is the JS challenge the same as the Non-Interactive Challenge?
Yes. Cloudflare's documentation names it the Non-Interactive Challenge, and its API value is js_challenge, which is why it is often still called the JS Challenge.
Is this the Cloudflare 5-second challenge?
It is what that name means today. The 5-second challenge was the old name for Cloudflare's JavaScript challenge page, after the few seconds it took; a WAF rule's Non-Interactive Challenge is its current form, and Cloudflare says it typically takes less than five seconds.
Does solving a demo page cost anything?
A task pointed at a demo page is an ordinary task: it is charged at the price list's rate when it succeeds, and a failed or expired task costs nothing. Opening the page and checking its token are not charged.