Cloudflare
Cloudflare Challenge Page vs Cloudflare Turnstile: Which Is It?
The "Just a moment..." page and the Cloudflare Turnstile widget are different features. How each works, what it produces, and how to tell which you face.
3 min readPublished Updated
Cloudflare puts two different things between automation and a website, and they are easy to confuse. One is Turnstile, a widget inside a page’s form. The other is a challenge page, the full-screen “Just a moment…” check that appears before the site loads at all. They work differently, they produce different results, and they need different handling. This guide shows how to tell them apart and what each one expects from you.
The Cloudflare Turnstile widget
Turnstile is embedded by the site’s own developers, in the page, usually on a form. The site loads Cloudflare’s script, renders a widget with its sitekey, and gets a token when the widget’s checks pass. The site’s own server then sends that token to Cloudflare’s siteverify endpoint.
- Where: inside a normal page, next to a form.
- Who decides: the site’s code.
- Result: a single-use token, valid for 300 seconds, submitted with the form.
- Checked by: the site’s server.
What is Cloudflare Turnstile? covers it in full.
The challenge page
A challenge page comes from Cloudflare’s network, in front of the site. When a request matches a
rule the site owner set in Cloudflare, such as a firewall rule, bot protection or an “under
attack” setting, Cloudflare answers with its own page instead of the site’s. The browser runs the
challenge, and on success Cloudflare sets a cookie called cf_clearance and lets the request
through. Later requests that carry the cookie are not challenged again for a while.
- Where: a full page, before any of the site’s content.
- Who decides: the site’s Cloudflare configuration, not its code.
- Result: the
cf_clearancecookie, sent with every later request. - Checked by: Cloudflare’s network, on each request.
The cf_clearance cookie explained covers what the cookie is tied to and how long it lasts.
How to tell which one you face
| Sign | Turnstile widget | Challenge page |
|---|---|---|
| Page title | The site’s own | Often “Just a moment…” |
| Site content visible | Yes, around the widget | No |
| Appears on | A form, when you submit | The first request, or any request |
| HTTP status of the page | Usually 200 | 403, with the header cf-mitigated: challenge |
| Markup | cf-turnstile element, data-sitekey |
Cloudflare’s challenge platform scripts |
| What passing gives you | A token for one form | A cf_clearance cookie |
A quick test from code: fetch the page with a plain HTTP client. If you get the site’s HTML with
a widget in it, it is Turnstile. If you get a small Cloudflare page with a 403 status, a
cf-mitigated: challenge header and none of the site’s content, it is a challenge.
Why the difference matters
- A token does not open a challenge page, and a cookie does not complete a Turnstile form. Each needs its own kind of solve.
- A challenge page is per client. The
cf_clearancecookie belongs to the browser that earned it: the same user agent, and usually the same IP address, must carry it. A Turnstile token has no such tie to your later requests; it is spent on one form. - A challenge page covers every request. Once you hold a valid cookie, you can fetch many pages until it expires. A Turnstile token covers one submission.
What ZeroCaptcha does for each
ZeroCaptcha solves Cloudflare Turnstile widgets: a task with the page URL and sitekey returns a token. The Cloudflare Turnstile solver page has samples in ten languages and tools.
For challenge pages, a challenge task takes the page URL and your proxy, and returns the cf_clearance cookie together with the user agent it was issued for, so your client can replay both through the same network. The Cloudflare WAF and 5-second challenge solver page has the details.
Before you automate either
Both features exist because a site owner decided to slow down automated traffic. Automate only sites you are allowed to: your own, a client’s with permission, or public pages whose terms allow it. The Acceptable Use Policy applies to every task, and site owners can ask to opt out.