# The cf_clearance Cookie Explained: User Agent, IP and Lifetime

> What Cloudflare's cf_clearance cookie is, what it is tied to, how long it lasts, and how to reuse it correctly with the same user agent through the same proxy.

- Source: https://zerocaptcha.io/guides/cf-clearance-cookie-explained
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

When a site behind Cloudflare shows a challenge page, the prize for passing it is a cookie named
`cf_clearance`. Every later request that carries it is let through without a new challenge, until
it expires. Using it correctly is mostly about sending it the way it was issued: from the same
client, with the same user agent, through the same network. This guide explains what the cookie is
tied to, how long it lasts, and the mistakes that make it fail.

## Where the cookie comes from

A challenge page is Cloudflare's full-screen check, shown in front of the site when a request
matches a rule the site owner configured. The browser runs the challenge; if it passes, Cloudflare
answers with a `Set-Cookie` header for `cf_clearance` on the site's domain, and the page reloads
into the real site. If you are not sure you are facing a challenge page rather than a Turnstile
widget, read [Cloudflare challenge page vs Cloudflare Turnstile](https://zerocaptcha.io/guides/cloudflare-challenge-vs-turnstile) first.

## What the cookie is tied to

A `cf_clearance` cookie is not a general pass. Cloudflare describes it as "securely tied to the
specific visitor and device it was issued to, preventing reuse across machines", and checks later
requests against that client. In practice that means:

- **The user agent.** Treat the cookie as bound to the `User-Agent` string of the browser that
  earned it. A request with another user agent is usually challenged again, even with a valid
  cookie.
- **The network.** The cookie is typically tied to the IP address it was issued to. A request
  from another address, including another exit of a rotating proxy, may be challenged again.
- **The domain.** It is set for the site's domain and works only there.

So the rule for replaying it is simple: **send the cookie with the same user agent, through the
same proxy**, and keep that pairing for as long as you use the cookie.

## How long it lasts

The site owner decides. Cloudflare's **Challenge Passage** setting sets how long a passed
challenge is remembered, with a default of 30 minutes; owners can make it shorter or longer. When
it expires, the next request is challenged again. Plan for a new cookie per session and per
network, rather than one cookie for a whole day of work.

## Replaying it correctly

With Python and `requests`, a request that reuses a cookie looks like this:

```python
import requests

session = requests.Session()
session.proxies = {"https": "http://user:secret@proxy.example.net:8080"}  # the same proxy
session.headers["User-Agent"] = user_agent                              # the same user agent
session.cookies.set("cf_clearance", clearance, domain="shop.example.com")

response = session.get("https://shop.example.com/catalog", timeout=15)
```

Three details are worth checking when this fails:

1. The user agent is **byte for byte** the one the cookie was issued to, not a similar string.
2. The proxy's **exit address** is the same. A rotating proxy that changes address between
   requests breaks the pairing; use a sticky session.
3. The cookie is **still valid**. Challenge Passage may be short on some sites.

Some sites also look at how the client connects, not only at its headers. A client whose TLS and
HTTP/2 behavior differs sharply from the browser named in the user agent can be challenged even
with a correct cookie and user agent.

## Keep your requests reasonable

A clearance cookie lets you through a site owner's protection, so the usual courtesy applies with
more force: keep request rates low, respect `robots.txt` and the site's terms, and automate only
sites you are allowed to. [Scraping a site with Cloudflare Turnstile](https://zerocaptcha.io/guides/cloudflare-turnstile-web-scraping)
covers pacing in a data pipeline.

The [Cloudflare WAF managed challenge test page](https://zerocaptcha.io/captcha-test/cloudflare-managed-challenge) shows
whether your browser holds a clearance, and the
[cf_clearance and Cloudflare Turnstile token inspector](https://zerocaptcha.io/tools/cf-clearance-token-inspector) reads a
cookie's likely issue time and expiry.

## What ZeroCaptcha offers for challenge pages

ZeroCaptcha's challenge task takes the page URL and your proxy, passes the challenge through that proxy, and returns the cf_clearance cookie together with the user agent it was issued for. Your client then sends both, through the same proxy, exactly as above.
The [Cloudflare WAF and 5-second challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver) page has the details, and the
[pricing page](https://zerocaptcha.io/pricing) the price.

For pages whose protection is a widget on a form, see the
[Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver).
[Solve Cloudflare Turnstile with a proxy](https://zerocaptcha.io/guides/solve-cloudflare-turnstile-with-a-proxy) covers
keeping a solve and its later requests on one network.

For the terms used here, such as challenge page and cf_clearance, see the [glossary](https://zerocaptcha.io/glossary).

## Questions

### Why is my cf_clearance cookie rejected?

The usual causes are a different user agent, a different IP address or proxy, or an expired cookie. Send it with exactly the user agent it was issued to, from the same network.

### How long does cf_clearance last?

As long as the site's Challenge Passage setting in Cloudflare allows. The default is 30 minutes, and site owners can set it shorter or longer.

### Will ZeroCaptcha return a cf_clearance cookie?

Yes. ZeroCaptcha's challenge task passes the page through your proxy and returns the cf_clearance cookie and the user agent it was issued for.
