CAPTCHA test pages
Cloudflare Turnstile test sitekeys and secret keys
Cloudflare publishes test keys for Cloudflare Turnstile so a site can test its own forms without a real challenge: the sitekey 1x00000000000000000000AA always passes, 2x00000000000000000000AB always fails and 3x00000000000000000000FF forces an interactive challenge, and the secret key 1x0000000000000000000000000000000AA passes every token at siteverify. Each is below, with an example you can run.
The test sitekeys, live
Put a test sitekey in data-sitekey, or in the sitekey option of turnstile.render(). Render each one here to see what it does: the page renders it explicitly and shows the token, or the error, its callbacks report.
| Sitekey | Behaviour | Widget | Try it |
|---|---|---|---|
| 1x00000000000000000000AA | Always passes | Visible | |
| 2x00000000000000000000AB | Always fails | Visible | |
| 1x00000000000000000000BB | Always passes | Invisible | |
| 2x00000000000000000000BB | Always fails | Invisible | |
| 3x00000000000000000000FF | Forces an interactive challenge | Visible |
The test secret keys
Configure a test secret key as your server's Turnstile secret, the value it sends to siteverify. The code beside this runs as it is: it asks Cloudflare about the dummy token XXXX.DUMMY.TOKEN.XXXX with the secret that always passes. Swap in another secret to see it fail.
| Secret key | siteverify answers |
|---|---|
| 1x0000000000000000000000000000000AA | Always passes validation |
| 2x0000000000000000000000000000000AA | Always fails validation, with invalid-input-response |
| 3x0000000000000000000000000000000AA | Fails as a token already spent, with timeout-or-duplicate |
Which pair tests what
Pair a sitekey in the page with a secret on the server. The page on the right is a whole form with the sitekey that always passes; keep the real keys out of test environments, and the test keys out of production.
- Your form accepts a good tokensitekey 1x00000000000000000000AA, secret 1x0000000000000000000000000000000AA
- Your server refuses a bad token, whatever the browser sayssitekey 1x00000000000000000000AA, secret 2x0000000000000000000000000000000AA
- Your server handles a replayed tokensitekey 1x00000000000000000000AA, secret 3x0000000000000000000000000000000AA
- Your page handles a widget that failssitekey 2x00000000000000000000AB, secret 2x0000000000000000000000000000000AA
- Your page works while a visitor must clicksitekey 3x00000000000000000000FF, secret 1x0000000000000000000000000000000AA
<script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async defer></script>
<form method="post" action="/login">
<div class="cf-turnstile" data-sitekey="1x00000000000000000000AA"></div>
<button type="submit">Sign in</button>
</form>
<!-- The widget passes at once and puts XXXX.DUMMY.TOKEN.XXXX in cf-turnstile-response. -->Testing a solver rather than your own site? Test sitekeys prove nothing about one: use the live demo pages and the Cloudflare Turnstile token checker.
Test sitekey questions
What are Cloudflare Turnstile's test sitekeys?
1x00000000000000000000AA always passes and 2x00000000000000000000AB always fails, both visible; 1x00000000000000000000BB and 2x00000000000000000000BB do the same invisibly; 3x00000000000000000000FF forces an interactive challenge.
What token does a test sitekey give?
The dummy token XXXX.DUMMY.TOKEN.XXXX. Production secret keys reject it, so pair a test sitekey with a test secret key.
Can a solver be tested with the test sitekeys?
No. A test sitekey passes or fails without any real challenge, so it proves nothing about a solver. Test a solver against a real widget, such as the demo pages here.