Skip to content

Cloudflare Turnstile token checker

Paste a token from one of this site's Cloudflare Turnstile demo widgets, say which widget gave it, and this page asks Cloudflare's siteverify with that widget's secret. You get the verdict as Cloudflare gave it: whether the token passed, for which hostname, action and cData, and why not if it failed.

Check a token

A token comes from a demo widget solved in your browser, or from a task pointed at a demo page: its solution.token. It passes once, within 300 seconds of the solve. Checks have a budget per address.

The cf-turnstile-response value, or a task's solution.token: up to 2,048 characters.

The verdict

The token goes to this site's API, which asks Cloudflare's siteverify with the widget's secret key. The reply is shown as it came.

No token checked yet

Paste a token and say which widget gave it, then check it with Cloudflare.

success
not checked yet
hostname
not checked yet
challenge_ts
not checked yet
action
not checked yet
cdata
not checked yet
error-codes
not checked yet
Widget
not checked yet
Round trip
not checked yet

What the error codes mean

A refused token comes back with one or more of Cloudflare's siteverify error codes. Most failures of a solved token are timeout-or-duplicate or invalid-input-response.

missing-input-secret
No secret key reached siteverify: a fault in the check, not in your token.
invalid-input-secret
The widget's secret key was refused: a fault in this site's settings, not in your token.
missing-input-response
No token reached siteverify.
invalid-input-response
The token is malformed, expired, or was issued for another widget. Solve this page's widget again.
bad-request
siteverify could not read the request.
timeout-or-duplicate
The token was already checked, or is older than 300 seconds. A token passes once: solve again.
internal-error
Cloudflare had an internal error. Check a new token in a moment.

Check tokens for your own widget

Your server checks your widget's tokens itself, with your widget's secret key: one POST to siteverify. Replace YOUR_SECRET_KEY and TOKEN_FROM_THE_FORM, or run it as it is with Cloudflare's test secret and dummy token.

# Ask Cloudflare about a token, as a site's server does.
curl -s https://challenges.cloudflare.com/turnstile/v0/siteverify \
  --data-urlencode "secret=YOUR_SECRET_KEY" \
  --data-urlencode "response=TOKEN_FROM_THE_FORM"

Token checker questions

Can this checker verify a token from any website?

No. siteverify needs the secret key of the widget that issued the token, so this page checks tokens from this site's demo widgets only. For your own widget, call siteverify from your server with your secret, as the code on this page does.

Why does a token pass once and then fail?

Cloudflare accepts each token once, within 300 seconds of the solve. A second check of the same token answers timeout-or-duplicate.

Is the token I paste stored?

No. It is sent to Cloudflare's siteverify with the widget's secret, and the verdict comes back to you; the token is never logged or kept.