Cloudflare Turnstile action and cData demo
This page's Cloudflare Turnstile widget sets an action, demo_login, and a cData value, demo-session-42. Cloudflare returns both when the token is checked, so the verdict below shows them. A task for this page must send the same two values.
The widget
LiveThis widget's settings
0x4AAAAAAFMVDQUY9ZAPO0ni- Mode
- managed
- Appearance
- always
- Size
- normal
- Rendering
- implicit
- Action
- demo_login
- cData
- demo-session-42
- Task
- TurnstileTaskProxyless
The verdict
The token goes to this site's API, which asks Cloudflare's siteverify with the widget's secret key. The reply is shown as it came.
No token checked yet
Solve the widget and press Verify, or paste a token a task returned for this page.
- success
- not checked yet
- hostname
- not checked yet
- challenge_ts
- not checked yet
- action
- not checked yet
- cdata
- not checked yet
- error-codes
- not checked yet
- Widget
- not checked yet
- Round trip
- not checked yet
What the error codes mean
The token you checked
Solve this page with the API
The complete createTask request for this page, then getTaskResult every 2 seconds until it is ready, then the result used as the page uses it. Set ZEROCAPTCHA_KEY to your API key.
- type
- TurnstileTaskProxyless, or TurnstileTask with your proxy
- websiteURL
- https://zerocaptcha.io/captcha-test/cloudflare-turnstile-action-cdata
- websiteKey
- 0x4AAAAAAFMVDQUY9ZAPO0ni
- metadata.action
- demo_login
- metadata.cdata
- demo-session-42
- proxy
- Only with TurnstileTask: http://user:pass@host:port
- callbackUrl
- Optional: called with the result when the task ends
- Idempotency-Key
- A header: sent again within 24 hours, it returns the first task
A task is charged at the listed price when it succeeds; a failed one costs nothing. The same task over REST, POST /v1/tasks, is inSolving Cloudflare Turnstile.
What this widget is
action is a short label for what the visitor is doing, up to 32 letters, digits, underscores or dashes. cData is customer data, up to 255 of the same characters, such as a session ID. Both are sent with the widget and come back from siteverify, so the site can refuse a token earned for another form or another session.
A token solved without them is still a token, but a site that compares the action or the cData on its server will refuse it.
Bring a token from elsewhere: the Cloudflare Turnstile token checker.
How to use the result
The task's result is a token: the same value a browser puts in the form's hidden cf-turnstile-response field. Send it where the page's own form sends it, in the same field. On this page that is the check at the top, beside the widget, which asks Cloudflare's siteverify about it with this widget's secret and shows the verdict; a task's token goes in its token box.
A token passes siteverify once, within 300 seconds of the solve. Use it straight away, and solve again for the next submission rather than reusing one.
Check the verdict's action and cdata: they are the values the widget was solved with. A site's server should compare them with what it expects.
How to recognise it on a real site
data-action and data-cdata beside data-sitekey, or action and cData in the turnstile.render() options.
The page loads https://challenges.cloudflare.com/turnstile/v0/api.js, the only script Cloudflare supports: it must not be copied, proxied or cached.
The widget itself is an iframe from challenges.cloudflare.com, under /cdn-cgi/challenge-platform/. Its requests go to Cloudflare, never to the site.
Inside a form, the widget adds a hidden input named cf-turnstile-response and puts the token there. The site's server checks it with POST https://challenges.cloudflare.com/turnstile/v0/siteverify.
No cookie is set on the site's own domain: the widget's state lives in Cloudflare's iframe.
<script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async defer></script>
<div class="cf-turnstile" data-sitekey="0x4AAAAAAFMVDQUY9ZAPO0ni" data-action="demo_login" data-cdata="demo-session-42"></div>
<!-- once solved: <input type="hidden" name="cf-turnstile-response" value="…"> -->Action and cData questions
Which ZeroCaptcha task solves the Cloudflare Turnstile widget with action and cData?
TurnstileTaskProxyless, or TurnstileTask to solve through your own proxy, with the page's URL and its sitekey, plus action and cdata when the widget sets them. The same task solves every Cloudflare Turnstile widget, whatever its mode or appearance.
What if a task leaves out the action?
The token can still be issued, but siteverify then reports another action, or none, and a site that checks it refuses the token. Send the widget's action and cdata exactly as the page sets them.