Cloudflare
The cf_clearance Cookie Explained: User Agent, IP and Lifetime
What Cloudflare's cf_clearance cookie is, what it is tied to, how long it lasts, and how to reuse it correctly with the same user agent through the same proxy.
4 min readPublished Updated
When a site behind Cloudflare shows a challenge page, the prize for passing it is a cookie named
cf_clearance. Every later request that carries it is let through without a new challenge, until
it expires. Using it correctly is mostly about sending it the way it was issued: from the same
client, with the same user agent, through the same network. This guide explains what the cookie is
tied to, how long it lasts, and the mistakes that make it fail.
Where the cookie comes from
A challenge page is Cloudflare’s full-screen check, shown in front of the site when a request
matches a rule the site owner configured. The browser runs the challenge; if it passes, Cloudflare
answers with a Set-Cookie header for cf_clearance on the site’s domain, and the page reloads
into the real site. If you are not sure you are facing a challenge page rather than a Turnstile
widget, read Cloudflare challenge page vs Cloudflare Turnstile first.
What the cookie is tied to
A cf_clearance cookie is not a general pass. Cloudflare describes it as “securely tied to the
specific visitor and device it was issued to, preventing reuse across machines”, and checks later
requests against that client. In practice that means:
- The user agent. Treat the cookie as bound to the
User-Agentstring of the browser that earned it. A request with another user agent is usually challenged again, even with a valid cookie. - The network. The cookie is typically tied to the IP address it was issued to. A request from another address, including another exit of a rotating proxy, may be challenged again.
- The domain. It is set for the site’s domain and works only there.
So the rule for replaying it is simple: send the cookie with the same user agent, through the same proxy, and keep that pairing for as long as you use the cookie.
How long it lasts
The site owner decides. Cloudflare’s Challenge Passage setting sets how long a passed challenge is remembered, with a default of 30 minutes; owners can make it shorter or longer. When it expires, the next request is challenged again. Plan for a new cookie per session and per network, rather than one cookie for a whole day of work.
Replaying it correctly
With Python and requests, a request that reuses a cookie looks like this:
import requests
session = requests.Session()session.proxies = {"https": "http://user:secret@proxy.example.net:8080"} # the same proxysession.headers["User-Agent"] = user_agent # the same user agentsession.cookies.set("cf_clearance", clearance, domain="shop.example.com")
response = session.get("https://shop.example.com/catalog", timeout=15)Three details are worth checking when this fails:
- The user agent is byte for byte the one the cookie was issued to, not a similar string.
- The proxy’s exit address is the same. A rotating proxy that changes address between requests breaks the pairing; use a sticky session.
- The cookie is still valid. Challenge Passage may be short on some sites.
Some sites also look at how the client connects, not only at its headers. A client whose TLS and HTTP/2 behavior differs sharply from the browser named in the user agent can be challenged even with a correct cookie and user agent.
Keep your requests reasonable
A clearance cookie lets you through a site owner’s protection, so the usual courtesy applies with
more force: keep request rates low, respect robots.txt and the site’s terms, and automate only
sites you are allowed to. Scraping a site with Cloudflare Turnstile
covers pacing in a data pipeline.
The Cloudflare WAF managed challenge test page shows whether your browser holds a clearance, and the cf_clearance and Cloudflare Turnstile token inspector reads a cookie’s likely issue time and expiry.
What ZeroCaptcha offers for challenge pages
ZeroCaptcha’s challenge task takes the page URL and your proxy, passes the challenge through that proxy, and returns the cf_clearance cookie together with the user agent it was issued for. Your client then sends both, through the same proxy, exactly as above. The Cloudflare WAF and 5-second challenge solver page has the details, and the pricing page the price.
For pages whose protection is a widget on a form, see the Cloudflare Turnstile solver. Solve Cloudflare Turnstile with a proxy covers keeping a solve and its later requests on one network.
For the terms used here, such as challenge page and cf_clearance, see the glossary.