Skip to content

Cloudflare

The cf_clearance Cookie Explained: User Agent, IP and Lifetime

What Cloudflare's cf_clearance cookie is, what it is tied to, how long it lasts, and how to reuse it correctly with the same user agent through the same proxy.

4 min readPublished Updated

When a site behind Cloudflare shows a challenge page, the prize for passing it is a cookie named cf_clearance. Every later request that carries it is let through without a new challenge, until it expires. Using it correctly is mostly about sending it the way it was issued: from the same client, with the same user agent, through the same network. This guide explains what the cookie is tied to, how long it lasts, and the mistakes that make it fail.

A challenge page is Cloudflare’s full-screen check, shown in front of the site when a request matches a rule the site owner configured. The browser runs the challenge; if it passes, Cloudflare answers with a Set-Cookie header for cf_clearance on the site’s domain, and the page reloads into the real site. If you are not sure you are facing a challenge page rather than a Turnstile widget, read Cloudflare challenge page vs Cloudflare Turnstile first.

A cf_clearance cookie is not a general pass. Cloudflare describes it as “securely tied to the specific visitor and device it was issued to, preventing reuse across machines”, and checks later requests against that client. In practice that means:

  • The user agent. Treat the cookie as bound to the User-Agent string of the browser that earned it. A request with another user agent is usually challenged again, even with a valid cookie.
  • The network. The cookie is typically tied to the IP address it was issued to. A request from another address, including another exit of a rotating proxy, may be challenged again.
  • The domain. It is set for the site’s domain and works only there.

So the rule for replaying it is simple: send the cookie with the same user agent, through the same proxy, and keep that pairing for as long as you use the cookie.

How long it lasts

The site owner decides. Cloudflare’s Challenge Passage setting sets how long a passed challenge is remembered, with a default of 30 minutes; owners can make it shorter or longer. When it expires, the next request is challenged again. Plan for a new cookie per session and per network, rather than one cookie for a whole day of work.

Replaying it correctly

With Python and requests, a request that reuses a cookie looks like this:

import requests
session = requests.Session()
session.proxies = {"https": "http://user:secret@proxy.example.net:8080"} # the same proxy
session.headers["User-Agent"] = user_agent # the same user agent
session.cookies.set("cf_clearance", clearance, domain="shop.example.com")
response = session.get("https://shop.example.com/catalog", timeout=15)

Three details are worth checking when this fails:

  1. The user agent is byte for byte the one the cookie was issued to, not a similar string.
  2. The proxy’s exit address is the same. A rotating proxy that changes address between requests breaks the pairing; use a sticky session.
  3. The cookie is still valid. Challenge Passage may be short on some sites.

Some sites also look at how the client connects, not only at its headers. A client whose TLS and HTTP/2 behavior differs sharply from the browser named in the user agent can be challenged even with a correct cookie and user agent.

Keep your requests reasonable

A clearance cookie lets you through a site owner’s protection, so the usual courtesy applies with more force: keep request rates low, respect robots.txt and the site’s terms, and automate only sites you are allowed to. Scraping a site with Cloudflare Turnstile covers pacing in a data pipeline.

The Cloudflare WAF managed challenge test page shows whether your browser holds a clearance, and the cf_clearance and Cloudflare Turnstile token inspector reads a cookie’s likely issue time and expiry.

What ZeroCaptcha offers for challenge pages

ZeroCaptcha’s challenge task takes the page URL and your proxy, passes the challenge through that proxy, and returns the cf_clearance cookie together with the user agent it was issued for. Your client then sends both, through the same proxy, exactly as above. The Cloudflare WAF and 5-second challenge solver page has the details, and the pricing page the price.

For pages whose protection is a widget on a form, see the Cloudflare Turnstile solver. Solve Cloudflare Turnstile with a proxy covers keeping a solve and its later requests on one network.

For the terms used here, such as challenge page and cf_clearance, see the glossary.

Questions

Why is my cf_clearance cookie rejected?

The usual causes are a different user agent, a different IP address or proxy, or an expired cookie. Send it with exactly the user agent it was issued to, from the same network.

How long does cf_clearance last?

As long as the site's Challenge Passage setting in Cloudflare allows. The default is 30 minutes, and site owners can set it shorter or longer.

Will ZeroCaptcha return a cf_clearance cookie?

Yes. ZeroCaptcha's challenge task passes the page through your proxy and returns the cf_clearance cookie and the user agent it was issued for.

Read next

This guide is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key