Cloudflare Turnstile solver
A Cloudflare Turnstile solver API that charges only for solved tokens.
Send the page's URL and its Turnstile sitekey; get back the token and the time it expires. ZeroCaptcha speaks the createTask format, 2Captcha's in.php and res.php, and REST, so the client you have usually needs only a new host and key.
How it works
Get an API key
Sign up with an email and a password, create your key in the dashboard, and add funds in crypto from $10.
Find the widget's sitekey
Read data-sitekey from the page's Turnstile element, or the sitekey passed to turnstile.render(), and data-action or cData if the widget sets them.
Create a task
Send createTask with the page's URL and the sitekey. The price is held on your balance and a taskId comes back at once.
Poll for the token
Ask getTaskResult every two seconds until the status is ready, or name a callback URL and we call it when the task ends.
Use the token within 300 seconds
Send the token where the page sends it, usually the cf-turnstile-response field. It works once, and every result says when it expires.
Three formats, one host
A task made in any format is priced, held and charged the same way. Task IDs are text, such as 0192f3a4-7b1c-7d2e-9f10-3c4d5e6f7a8b. See the API reference and the error codes.
Task types it takes
TurnstileTaskProxylessSolved from our networkTurnstileTaskSolved through your HTTP or HTTPS proxyAntiTurnstileTaskProxyLessAccepted as TurnstileTaskProxylessAntiTurnstileTaskAccepted as TurnstileTask
createTask format
POST /createTask, /getTaskResult, /getBalanceThe JSON most solver clients speak, with the key as clientKey.
2Captcha format
in.php and res.php, method=turnstileFor clients written for 2Captcha's original API, in plain text or JSON.
REST
POST /v1/tasks, GET /v1/tasks/{id}Bearer keys, an Idempotency-Key for safe retries, problem details for errors.
What a token costs
- Cloudflare Turnstile, your proxy$0.70per 1,000 solved tasks
- Cloudflare Turnstile, proxyless$0.80per 1,000 solved tasks
Prepaid in US dollars and topped up in crypto from $10, with no subscription. A task that fails, expires or is refused costs nothing. See pricing for every line and an estimator.
By language and tool
- PythonPlain HTTP; Python client coming
- Node.jsPlain HTTP; JavaScript client coming
- Go (Golang)Plain HTTP; Go client coming
- PHPPlain HTTP
- JavaPlain HTTP
- C#Plain HTTP
- PlaywrightPlain HTTP; JavaScript client coming
- PuppeteerPlain HTTP; JavaScript client coming
- SeleniumPlain HTTP; Python client coming
- curlPlain HTTP
Cloudflare Turnstile guides
- APICaptcha API Error Codes: What Each Means and What It CostsERROR_CAPTCHA_UNSOLVABLE, ERROR_ZERO_BALANCE, ERROR_KEY_DOES_NOT_EXIST and the rest: what each captcha API error means, whether to retry, and what it costs.
- APICaptcha Solver Callbacks: pingback and callbackUrl, No PollingGet Cloudflare Turnstile results pushed to your server instead of polling: callbackUrl and pingback, what each call contains, retries, and how to answer.
- APICaptcha Solver Concurrency, 429s and Retry-AfterRun many Cloudflare Turnstile tasks at once: how ZeroCaptcha paces calls, what 429, ERROR_RATE_LIMIT and ERROR_NO_SLOT_AVAILABLE mean, and how to back off.
- BillingCaptcha Solving Cost: Price per 1,000 and What You Really PayHow captcha solving is priced per 1,000, why the real cost differs from the list price, and how to estimate a month of Cloudflare Turnstile tasks.
- Cloudflare TurnstileCloudflare Turnstile action and cData: When a Task Needs ThemWhat Turnstile's action and cData parameters do, where to find them in a page, and how to pass them in createTask, in.php or REST so the token is accepted.
- Cloudflare TurnstileCloudflare Turnstile Modes: Managed, Non-Interactive, InvisibleCloudflare Turnstile's three widget modes compared: what visitors see in each, how to tell which one a page uses, and why a solving task is the same for all.
More guides
- Cloudflare Turnstile Token Expired? Lifetime and Reuse Explained
- createTask and getTaskResult: The Captcha API Format Explained
- How to Find a Cloudflare Turnstile Sitekey on Any Page
- Idempotency Keys: Retry Captcha Tasks Without Paying Twice
- Migrate From 2Captcha: Cloudflare Turnstile in.php and createTask
- Migrate From Anti-Captcha: TurnstileTask on ZeroCaptcha
- Migrate From CapSolver: AntiTurnstileTaskProxyLess on ZeroCaptcha
- Pay for a Captcha API With Crypto: Top-ups, Receipts, Limits
- Responsible Captcha Automation: Acceptable Use and Opt-outs
- Scraping a Site With Cloudflare Turnstile: An Authorized Pipeline
- Secure Captcha API Keys: IP Allowlists, Rotation, Spend Caps
- Solve Cloudflare Turnstile With a Proxy: TurnstileTask Explained
- Submit a Cloudflare Turnstile Token: Form Fields and Callbacks
- Test Cloudflare Turnstile in CI With Testing Sitekeys
- Verify a Webhook's HMAC-SHA256 Signature, With Replay Protection
- What Is Cloudflare Turnstile? The CAPTCHA Widget Explained
Cloudflare Turnstile articles
- ExplainerCloudflare Turnstile Token: What It Is and What It ProvesWhat a Cloudflare Turnstile token is, where the widget puts it, how siteverify checks it, what it proves, and how a solving API produces one.
- ComparisonCloudflare Turnstile vs reCAPTCHA vs hCaptcha: Full ComparisonCloudflare Turnstile, Google reCAPTCHA and hCaptcha side by side: how each checks visitors, tokens, siteverify, prices and limits, and what automation meets.
- TroubleshootingCloudflare Turnstile Siteverify Errors: Why a Token Is RejectedEvery Cloudflare Turnstile siteverify error code with Cloudflare's meaning and fix, and why a site rejects a token when you automate a form.
- TroubleshootingCloudflare Turnstile in Headless Browsers: Why It Fails and FixesWhy Cloudflare Turnstile fails in headless Chrome, Playwright and Puppeteer, what Cloudflare says about automated browsers, and a fix that uses an API token.
- ExplainerAI CAPTCHA Solvers and Cloudflare Turnstile: How Solving WorksWhat an AI CAPTCHA solver really does, why image recognition does not apply to Cloudflare Turnstile, and how automated Turnstile solving works, without hype.
- TutorialSimple Cloudflare Turnstile on WordPress: Solving and TestingHow WordPress sites add Cloudflare Turnstile with the Simple Cloudflare Turnstile plugin, Contact Form 7, WPForms or Gravity Forms, and how to automate them.
Test it on a live Cloudflare Turnstile widget
Every kind of Cloudflare Turnstile widget has a live demo page to point a task at: each shows its sitekey and the exact request, and checks the token you bring with Cloudflare's siteverify.
- Cloudflare Turnstile managed widget demo
- Cloudflare Turnstile invisible widget demo
- Cloudflare Turnstile explicit rendering demo
- Cloudflare Turnstile action and cData demo
- Cloudflare Turnstile login form demo
- Cloudflare Turnstile token checker
- Cloudflare Turnstile sitekey finder
- All Cloudflare Turnstile demo and CAPTCHA test pages
Cloudflare Turnstile solver questions
What is a Cloudflare Turnstile solver?
An API that completes a Turnstile widget for your program and returns the token the page's form sends. ZeroCaptcha takes the page's URL and sitekey and returns the token, with the time it expires.
Do I pay for tasks that fail?
No. The price is held when you create a task and released at once if it fails or times out; a refused task holds nothing. You pay only when a token is ready.
Will my current client work?
Usually, after changing its host and key: ZeroCaptcha takes the createTask format with the task names above, and 2Captcha's in.php and res.php. Task IDs are text, so a client that parses them as numbers needs that changed, and proxies must be HTTP or HTTPS.
How long does a Cloudflare Turnstile token last?
Turnstile tokens are single-use and expire 300 seconds after they are issued, so solve right before you submit. Every result says when its token expires.
Which sites may I use it on?
Sites you are allowed to automate: your own, or one whose owner lets you. The Acceptable Use Policy says what that covers, and any site owner can ask to opt their domain out.