Cloudflare Turnstile solver · Puppeteer
Solve Cloudflare Turnstile in Puppeteer
A Puppeteer script on a site you may automate can finish a Turnstile widget in four steps: read the site key, action and cData, ask ZeroCaptcha for a token, set the form field, submit. The sample uses the JavaScript client, which is coming to npm; until then, the Node.js page makes the same calls with fetch.
Plain HTTP today; the official JavaScript client is coming
The steps in Puppeteer
Get an API key
Sign up with an email and a password, create your key in the dashboard and add funds in crypto, from $10.
Read the widget's site key, action and cData
Open the page in Puppeteer and read data-sitekey, data-action and data-cdata from the Turnstile element, or the sitekey, action and cData options of its turnstile.render() call.
Solve it with ZeroCaptcha
Send the page's URL, the site key, and the action and cData when the widget sets them, to ZeroCaptcha and wait for the token. Many sites check both when they verify it.
Put the token in the form
Set the cf-turnstile-response field to the token, then submit the form as a person would, within 300 seconds.
New to the API? The quickstart walks through sign-up, the key and the first task.
Good to know
Send the widget's action and cData with the task whenever it sets them: many sites refuse a token whose action or cData does not match.
Solve right before you submit: the token works once, within 300 seconds.
Some pages read the token from the widget's callback rather than the form field. On those, call the page's own callback with the token.
Read next
- Cloudflare TurnstileSubmit a Cloudflare Turnstile Token: Form Fields and CallbacksWhere a solved Turnstile token goes: the cf-turnstile-response field, the widget's callback, or a JSON body. With examples for forms, fetch and browsers.
- Cloudflare TurnstileCloudflare Turnstile action and cData: When a Task Needs ThemWhat Turnstile's action and cData parameters do, where to find them in a page, and how to pass them in createTask, in.php or REST so the token is accepted.
- Cloudflare TurnstileCloudflare Turnstile Modes: Managed, Non-Interactive, InvisibleCloudflare Turnstile's three widget modes compared: what visitors see in each, how to tell which one a page uses, and why a solving task is the same for all.
Puppeteer questions
Where does the token go?
Where the widget puts it: the hidden cf-turnstile-response field of the form, or the callback the page registered. Then submit as a person would.
How long does a Cloudflare Turnstile token last?
A Cloudflare Turnstile token works once and expires 300 seconds after it is issued, so solve right before you submit. Every result tells you when its token expires.
What does a failed task cost?
Nothing. The price is held when you create a task and released at once if it fails or expires, and a refused task holds nothing; you pay only when a token is ready.