Skip to content

Cloudflare Turnstile implicit rendering demo

This page renders its Cloudflare Turnstile widget implicitly: the HTML holds a div with the class cf-turnstile and a data-sitekey, and Cloudflare's api.js finds it and fills it in. No script of the page's own is involved. The sitekey is right there in the markup.

The widget

Live

Check a token from a task

A task's solution.token for this page. It passes once, within 300 seconds of the solve.

This widget's settings

Sitekey0x4AAAAAAFMVDQUY9ZAPO0ni
Mode
managed
Appearance
always
Size
normal
Rendering
implicit
Task
TurnstileTaskProxyless

The verdict

The token goes to this site's API, which asks Cloudflare's siteverify with the widget's secret key. The reply is shown as it came.

No token checked yet

Solve the widget and press Verify, or paste a token a task returned for this page.

success
not checked yet
hostname
not checked yet
challenge_ts
not checked yet
action
not checked yet
cdata
not checked yet
error-codes
not checked yet
Widget
not checked yet
Round trip
not checked yet

Solve this page with the API

The complete createTask request for this page, then getTaskResult every 2 seconds until it is ready, then the result used as the page uses it. Set ZEROCAPTCHA_KEY to your API key.

type
TurnstileTaskProxyless, or TurnstileTask with your proxy
websiteURL
https://zerocaptcha.io/captcha-test/cloudflare-turnstile-implicit-rendering
websiteKey
0x4AAAAAAFMVDQUY9ZAPO0ni
metadata.action
This widget sets none
metadata.cdata
This widget sets none
proxy
Only with TurnstileTask: http://user:pass@host:port
callbackUrl
Optional: called with the result when the task ends
Idempotency-Key
A header: sent again within 24 hours, it returns the first task

A task is charged at the listed price when it succeeds; a failed one costs nothing. The same task over REST, POST /v1/tasks, is inSolving Cloudflare Turnstile.

#!/usr/bin/env bash
# Solve this page's Cloudflare Turnstile widget with createTask, then check the token here.
set -euo pipefail
API=${ZEROCAPTCHA_API:-https://api.zerocaptcha.io}
KEY=${ZEROCAPTCHA_KEY:?Set ZEROCAPTCHA_KEY to your API key, zc_live_..., from the dashboard.}

# 1. createTask for this page and its sitekey.
#    This widget sets no data-action or data-cdata. For one that does, send both, or a site
#    that checks them refuses the token: add metadata: {action: "login", cdata: "session-7f3a9c2e"}.
#    To solve through your own proxy, make the type TurnstileTask and add
#    proxy: "http://user:pass@proxy.example.net:8080" to the task.
#    CALLBACK_URL, when set, is called with the result when the task ends.
BODY=$(jq -n --arg key "$KEY" --arg callback "${CALLBACK_URL:-}" '{
  clientKey: $key,
  task: {
    type: "TurnstileTaskProxyless",
    websiteURL: "https://zerocaptcha.io/captcha-test/cloudflare-turnstile-implicit-rendering",
    websiteKey: "0x4AAAAAAFMVDQUY9ZAPO0ni"
  },
  callbackUrl: (if $callback == "" then null else $callback end)
}')
CREATED=$(curl -sS --fail-with-body "$API/createTask" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d "$BODY")
# errorId 1 is a refusal: errorCode and errorDescription say why.
if [ "$(jq -r .errorId <<<"$CREATED")" != 0 ]; then echo "$CREATED" >&2; exit 1; fi
TASK_ID=$(jq -r .taskId <<<"$CREATED")

# 2. getTaskResult every 2 seconds until the task is ready; errorId 1 means it failed, unpaid.
while :; do
  sleep 2
  RESULT=$(curl -sS --fail-with-body "$API/getTaskResult" \
    -H "Content-Type: application/json" \
    -d "$(jq -n --arg key "$KEY" --arg id "$TASK_ID" '{clientKey: $key, taskId: $id}')")
  if [ "$(jq -r .errorId <<<"$RESULT")" != 0 ]; then echo "$RESULT" >&2; exit 1; fi
  if [ "$(jq -r .status <<<"$RESULT")" = ready ]; then break; fi
done
TOKEN=$(jq -r .solution.token <<<"$RESULT")

# 3. Use solution.token once, within 300 seconds: here, this page's check, which asks
#    Cloudflare's siteverify. Or paste it into the token box on the page.
curl -sS --fail-with-body "$API/v1/demo/verify" \
  -H "Content-Type: application/json" \
  -d "$(jq -n --arg token "$TOKEN" '{widget: "managed", token: $token}')"

What this widget is

Implicit rendering is the simplest way to add Turnstile: load api.js, and put an element with the class cf-turnstile where the widget goes. The script scans the page for such elements and renders each one, reading its settings from data- attributes.

It is the easiest kind to automate against, because every value a task needs, the sitekey, the action and the cData, is an attribute in the HTML.

Bring a token from elsewhere: the Cloudflare Turnstile token checker.

How to use the result

The task's result is a token: the same value a browser puts in the form's hidden cf-turnstile-response field. Send it where the page's own form sends it, in the same field. On this page that is the check at the top, beside the widget, which asks Cloudflare's siteverify about it with this widget's secret and shows the verdict; a task's token goes in its token box.

A token passes siteverify once, within 300 seconds of the solve. Use it straight away, and solve again for the next submission rather than reusing one.

How to recognise it on a real site

  • A cf-turnstile element with data-sitekey, and api.js loaded without ?render=explicit.

  • The page loads https://challenges.cloudflare.com/turnstile/v0/api.js, the only script Cloudflare supports: it must not be copied, proxied or cached.

  • The widget itself is an iframe from challenges.cloudflare.com, under /cdn-cgi/challenge-platform/. Its requests go to Cloudflare, never to the site.

  • Inside a form, the widget adds a hidden input named cf-turnstile-response and puts the token there. The site's server checks it with POST https://challenges.cloudflare.com/turnstile/v0/siteverify.

  • No cookie is set on the site's own domain: the widget's state lives in Cloudflare's iframe.

This page's widget markup
<script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async defer></script>
<div class="cf-turnstile" data-sitekey="0x4AAAAAAFMVDQUY9ZAPO0ni"></div>
<!-- once solved: <input type="hidden" name="cf-turnstile-response" value="…"> -->

Implicit rendering questions

Which ZeroCaptcha task solves the implicitly rendered Cloudflare Turnstile widget?

TurnstileTaskProxyless, or TurnstileTask to solve through your own proxy, with the page's URL and its sitekey, plus action and cdata when the widget sets them. The same task solves every Cloudflare Turnstile widget, whatever its mode or appearance.

Where is the sitekey with implicit rendering?

In the data-sitekey attribute of the element with the class cf-turnstile, in the page's HTML.