Skip to content

CAPTCHA test pages

Cloudflare Turnstile test sitekeys and secret keys

Cloudflare publishes test keys for Cloudflare Turnstile so a site can test its own forms without a real challenge: the sitekey 1x00000000000000000000AA always passes, 2x00000000000000000000AB always fails and 3x00000000000000000000FF forces an interactive challenge, and the secret key 1x0000000000000000000000000000000AA passes every token at siteverify. Each is below, with an example you can run.

The test sitekeys, live

Put a test sitekey in data-sitekey, or in the sitekey option of turnstile.render(). Render each one here to see what it does: the page renders it explicitly and shows the token, or the error, its callbacks report.

Cloudflare Turnstile test sitekeys
SitekeyBehaviourWidgetTry it
1x00000000000000000000AAAlways passesVisible

2x00000000000000000000ABAlways failsVisible

1x00000000000000000000BBAlways passesInvisible

2x00000000000000000000BBAlways failsInvisible

3x00000000000000000000FFForces an interactive challengeVisible

The test secret keys

Configure a test secret key as your server's Turnstile secret, the value it sends to siteverify. The code beside this runs as it is: it asks Cloudflare about the dummy token XXXX.DUMMY.TOKEN.XXXX with the secret that always passes. Swap in another secret to see it fail.

Cloudflare Turnstile test secret keys
Secret keysiteverify answers
1x0000000000000000000000000000000AAAlways passes validation
2x0000000000000000000000000000000AAAlways fails validation, with invalid-input-response
3x0000000000000000000000000000000AAFails as a token already spent, with timeout-or-duplicate
# Ask Cloudflare about a token, as a site's server does.
curl -s https://challenges.cloudflare.com/turnstile/v0/siteverify \
  --data-urlencode "secret=1x0000000000000000000000000000000AA" \
  --data-urlencode "response=XXXX.DUMMY.TOKEN.XXXX"

Which pair tests what

Pair a sitekey in the page with a secret on the server. The page on the right is a whole form with the sitekey that always passes; keep the real keys out of test environments, and the test keys out of production.

  • Your form accepts a good tokensitekey 1x00000000000000000000AA, secret 1x0000000000000000000000000000000AA
  • Your server refuses a bad token, whatever the browser sayssitekey 1x00000000000000000000AA, secret 2x0000000000000000000000000000000AA
  • Your server handles a replayed tokensitekey 1x00000000000000000000AA, secret 3x0000000000000000000000000000000AA
  • Your page handles a widget that failssitekey 2x00000000000000000000AB, secret 2x0000000000000000000000000000000AA
  • Your page works while a visitor must clicksitekey 3x00000000000000000000FF, secret 1x0000000000000000000000000000000AA
A form with the sitekey that always passes
<script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async defer></script>
<form method="post" action="/login">
  <div class="cf-turnstile" data-sitekey="1x00000000000000000000AA"></div>
  <button type="submit">Sign in</button>
</form>
<!-- The widget passes at once and puts XXXX.DUMMY.TOKEN.XXXX in cf-turnstile-response. -->

Testing a solver rather than your own site? Test sitekeys prove nothing about one: use the live demo pages and the Cloudflare Turnstile token checker.

Test sitekey questions

What are Cloudflare Turnstile's test sitekeys?

1x00000000000000000000AA always passes and 2x00000000000000000000AB always fails, both visible; 1x00000000000000000000BB and 2x00000000000000000000BB do the same invisibly; 3x00000000000000000000FF forces an interactive challenge.

What token does a test sitekey give?

The dummy token XXXX.DUMMY.TOKEN.XXXX. Production secret keys reject it, so pair a test sitekey with a test secret key.

Can a solver be tested with the test sitekeys?

No. A test sitekey passes or fails without any real challenge, so it proves nothing about a solver. Test a solver against a real widget, such as the demo pages here.