Cloudflare WAF and 5-second challenge solver
Solve Cloudflare WAF and 5-second challenge pages to a cf_clearance cookie.
Solve Cloudflare WAF and 5-second challenge pages too: a task returns the cf_clearance cookie with the user agent it was issued for.
Cloudflare WAF, "Just a moment..." and the 5-second challenge
Three names people search for, and one page to solve: the interstitial challenge Cloudflare shows in front of a site. A CloudflareChallengeTask passes it, whatever it is called.
- Cloudflare WAF challenge
- A site's Cloudflare WAF rules (custom rules, rate limiting rules and IP Access rules) can answer a request with a challenge instead of the page, when the rule's action is Managed Challenge, Non-Interactive Challenge or Interactive Challenge. Bot Fight Mode and Under Attack mode show the same page.
- "Just a moment..." and "Checking your browser"
- The interstitial challenge page itself: a full-page screen, sent with HTTP 403 and the header cf-mitigated: challenge, that runs Cloudflare's checks before the visitor reaches the page. "Checking your browser before accessing..." is its older wording, which Cloudflare's reference still uses for Under Attack mode.
- The 5-second challenge
- The old name for Cloudflare's JavaScript challenge, after the few seconds its page took. Today it is a Managed Challenge or a Non-Interactive Challenge (API value js_challenge), which Cloudflare says typically takes less than five seconds.
- cf_clearance
- The cookie a browser earns by passing any of them. It lets that visitor through until the site's Challenge Passage time runs out, and it is what a challenge task returns.
What a challenge task returns
You send the page's URL and your proxy. The result is what your own client needs to be let through: use all three together, or the site challenges you again.
The cf_clearance cookie
The cookie Cloudflare sets once its challenge is passed, which lets later requests to the site through.
The user agent it was issued for
Cloudflare ties the cookie to the browser that earned it, so your requests must send the same User-Agent header.
Your proxy, used for the solve
Send the proxy your later requests will use: the cookie is meant to be replayed from the address that earned it.
One request, one clearance
Create a CloudflareChallengeTask with the page's URL and your proxy, read it until it ends, then send the cf_clearance cookie with its user agent through the same proxy. The sample points at our own test page behind a managed challenge, so it runs as copied.
Challenge page or Cloudflare Turnstile widget?
A challenge page, the "Just a moment…" screen a Cloudflare WAF rule shows, once called the 5-second challenge, stands in front of a whole site. Passing it sets the cf_clearance cookie, and your client then browses the site with that cookie, its user agent and its address.
A Turnstile widget sits inside a page, usually a form. It produces a single-use token that the form sends and the site verifies within 300 seconds. That is what the Cloudflare Turnstile solver returns today.
Both are tasks on the same API, with the same prepaid balance and the same rule: you pay only when a task succeeds.
Cloudflare WAF and 5-second challenge guides
- CloudflareCloudflare Challenge Page vs Cloudflare Turnstile: Which Is It?The "Just a moment..." page and the Cloudflare Turnstile widget are different features. How each works, what it produces, and how to tell which you face.
- CloudflareThe cf_clearance Cookie Explained: User Agent, IP and LifetimeWhat Cloudflare's cf_clearance cookie is, what it is tied to, how long it lasts, and how to reuse it correctly with the same user agent through the same proxy.
Cloudflare challenges, errors and WAF rules
- ExplainerCloudflare WAF Bypass: What Gets an Automated Client ThroughLooking for a Cloudflare WAF bypass? What each WAF action does to a scraper, which ones can be passed, which only the site owner can lift, and the request.
- ExplainerCloudflare 5-Second Challenge: What It Is Now and How to Pass ItThe Cloudflare 5-second challenge is the old name for its JavaScript challenge page. What replaced it, how to recognise it, and how to pass it with an API.
- TroubleshootingCloudflare "Just a Moment" and "Checking Your Browser" PagesWhat Cloudflare's "Just a moment..." and "Checking your browser" pages are, why they appear, what visitors can do, and how automation passes them.
- TroubleshootingPlease Unblock challenges.cloudflare.com to Proceed: FixesWhy a Cloudflare page says to unblock challenges.cloudflare.com, how to fix it in a browser or network, and what it means for automated clients.
- ExplainerCloudflare Managed vs Non-Interactive vs Interactive ChallengeCloudflare's three challenge types, including the one called JS Challenge: what each does, who issues it, which clearance passes which, and what bots meet.
- TroubleshootingCloudflare Challenge Loop: Why 'Just a moment...' RepeatsWhy a Cloudflare 'Just a moment...' page keeps coming back: the documented causes, IP changes mid-solve, lost cookies, clocks, and fixes for code.
- ComparisonCloudflare Bot Management vs Turnstile vs Challenge PagesWhat an automated client meets on a Cloudflare site: Bot Management scores, Bot Fight Mode, Turnstile widgets and challenge pages, and what each one needs.
- TroubleshootingCloudflare Error 1020 Access Denied: What It Means for AutomationCloudflare error 1020 means a site owner's firewall rule blocked your request: what the page shows, why no token lifts it, and what to do next.
- TroubleshootingCloudflare Error 1015 Rate Limited: Causes and Backoff in CodeCloudflare error 1015 means a site's rate limiting rule blocked you. How the rules count, the 429 status, and Python backoff that stops the retries.
- ExplainerCloudflare WAF Rules Explained: Challenge, Block, Skip, LogCloudflare WAF custom rule actions in Cloudflare's words, terminating vs non-terminating, plan limits, rule order, and what each action means for a bot.
- ExplainerWhat Is a WAF? And What a Cloudflare WAF Challenge MeansA web application firewall filters HTTP traffic by rules. How Cloudflare's WAF is built, and what a scraper sees when one of its rules blocks or challenges it.
- TutorialPlaywright and Cloudflare "Just a Moment": Using cf_clearanceWhy Playwright gets stuck on Cloudflare's "Just a moment..." page, how to detect it, and how to load a cf_clearance cookie with its user agent and proxy.
Test it on a live Cloudflare WAF challenge page
A page behind each kind of Cloudflare challenge, and one with a pre-clearance widget, to point a challenge task at. Each shows whether your browser holds a cf_clearance cookie.
Cloudflare WAF and 5-second challenge questions
Are Cloudflare WAF and 5-second challenge pages supported today?
Yes. A challenge task passes the page a Cloudflare WAF rule shows through your proxy, and returns the cf_clearance cookie with the user agent it was issued for, charged only when it succeeds.
What is the Cloudflare 5-second challenge?
The old name for Cloudflare's JavaScript challenge page, after the few seconds it took. Today a WAF rule shows a Managed or Non-Interactive Challenge in its place, which Cloudflare says typically takes less than five seconds. A challenge task solves either, and returns the cf_clearance cookie.
Is "Just a moment..." a Cloudflare WAF challenge?
Usually. "Just a moment..." is the challenge page Cloudflare shows when a WAF rule, Bot Fight Mode or Under Attack mode challenges a request. It answers with HTTP 403 and the header cf-mitigated: challenge. A block, such as error 1020, is a refusal rather than a challenge, and no task can pass it.
How is a challenge page different from Cloudflare Turnstile?
A challenge page stands in front of a whole site and, once passed, sets the cf_clearance cookie. Turnstile is a widget inside a page that gives its form a single-use token. They need different tasks.
Why must I reuse the user agent and proxy?
Cloudflare ties cf_clearance to the visitor and device it was issued to: in practice, the browser's user agent and usually its address. Requests with another user agent or from another address are challenged again.
Will I pay for challenges that fail?
No. Every ZeroCaptcha task holds its price and charges it only when it succeeds; a failed or expired task costs nothing.