Cloudflare Turnstile solver · PHP
Solve Cloudflare Turnstile in PHP
There is no PHP package to install: the API is plain JSON over HTTPS, so PHP's curl extension is all you need. The program below creates a task, polls for its token and stops with the API's own error code when something fails.
No SDK needed: plain JSON over HTTPS
The steps in PHP
Get an API key
Sign up with an email and a password, create your key in the dashboard and add funds in crypto, from $10.
Create a task
Send createTask with the page's URL, its Turnstile site key, and the widget's action and cData when it sets them. The price is held on your balance and a taskId comes back at once.
Poll for the token
Ask getTaskResult every two seconds until the status is ready, and stop after a deadline of your own, such as three minutes.
Use the token within 300 seconds
Send the token where the page sends it, usually the cf-turnstile-response form field. It works once, and expires 300 seconds after it was issued.
New to the API? The quickstart walks through sign-up, the key and the first task.
Good to know
Every compatible reply is HTTP 200 with errorId 0 or 1; any other status means the request failed on its way, so try again later.
Keep the taskId as a string: it is an ID such as 0192f3a4-7b1c-7d2e-9f10-3c4d5e6f7a8b, not a number.
Send an Idempotency-Key header with createTask if you retry it, so a lost reply never creates a second task.
Read next
- MigrationMigrate From 2Captcha: Cloudflare Turnstile in.php and createTaskMove Cloudflare Turnstile solving from 2Captcha to ZeroCaptcha: keep in.php and res.php or createTask, change the host and key, and check what differs.
- APIcreateTask and getTaskResult: The Captcha API Format ExplainedHow the createTask, getTaskResult and getBalance format works: request bodies, replies, errorId, polling, and ZeroCaptcha's Cloudflare Turnstile tasks.
- APICaptcha API Error Codes: What Each Means and What It CostsERROR_CAPTCHA_UNSOLVABLE, ERROR_ZERO_BALANCE, ERROR_KEY_DOES_NOT_EXIST and the rest: what each captcha API error means, whether to retry, and what it costs.
PHP questions
Is there a PHP SDK?
No. The API is plain JSON over HTTPS, so the curl extension is enough, and a client written for createTask or 2Captcha's in.php can point at our host.
How long does a Cloudflare Turnstile token last?
A Cloudflare Turnstile token works once and expires 300 seconds after it is issued, so solve right before you submit. Every result tells you when its token expires.
What does a failed task cost?
Nothing. The price is held when you create a task and released at once if it fails or expires, and a refused task holds nothing; you pay only when a token is ready.