# Cloudflare Challenge Page vs Cloudflare Turnstile: Which Is It?

> The "Just a moment..." page and the Cloudflare Turnstile widget are different features. How each works, what it produces, and how to tell which you face.

- Source: https://zerocaptcha.io/guides/cloudflare-challenge-vs-turnstile
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

Cloudflare puts two different things between automation and a website, and they are easy to
confuse. One is **Turnstile**, a widget inside a page's form. The other is a **challenge page**,
the full-screen "Just a moment…" check that appears before the site loads at all. They work
differently, they produce different results, and they need different handling. This guide shows
how to tell them apart and what each one expects from you.

## The Cloudflare Turnstile widget

Turnstile is embedded by the site's own developers, in the page, usually on a form. The site loads
Cloudflare's script, renders a widget with its sitekey, and gets a **token** when the widget's
checks pass. The site's own server then sends that token to Cloudflare's siteverify endpoint.

- Where: inside a normal page, next to a form.
- Who decides: the site's code.
- Result: a single-use token, valid for 300 seconds, submitted with the form.
- Checked by: the site's server.

[What is Cloudflare Turnstile?](https://zerocaptcha.io/guides/what-is-cloudflare-turnstile) covers it in full.

## The challenge page

A challenge page comes from Cloudflare's network, in front of the site. When a request matches a
rule the site owner set in Cloudflare, such as a firewall rule, bot protection or an "under
attack" setting, Cloudflare answers with its own page instead of the site's. The browser runs the
challenge, and on success Cloudflare sets a **cookie** called `cf_clearance` and lets the request
through. Later requests that carry the cookie are not challenged again for a while.

- Where: a full page, before any of the site's content.
- Who decides: the site's Cloudflare configuration, not its code.
- Result: the `cf_clearance` cookie, sent with every later request.
- Checked by: Cloudflare's network, on each request.

[The cf_clearance cookie explained](https://zerocaptcha.io/guides/cf-clearance-cookie-explained) covers what the cookie
is tied to and how long it lasts.

## How to tell which one you face

| Sign | Turnstile widget | Challenge page |
| --- | --- | --- |
| Page title | The site's own | Often "Just a moment…" |
| Site content visible | Yes, around the widget | No |
| Appears on | A form, when you submit | The first request, or any request |
| HTTP status of the page | Usually 200 | 403, with the header `cf-mitigated: challenge` |
| Markup | `cf-turnstile` element, `data-sitekey` | Cloudflare's challenge platform scripts |
| What passing gives you | A token for one form | A `cf_clearance` cookie |

A quick test from code: fetch the page with a plain HTTP client. If you get the site's HTML with
a widget in it, it is Turnstile. If you get a small Cloudflare page with a 403 status, a
`cf-mitigated: challenge` header and none of the site's content, it is a challenge.

## Why the difference matters

- **A token does not open a challenge page**, and a cookie does not complete a Turnstile form.
  Each needs its own kind of solve.
- **A challenge page is per client.** The `cf_clearance` cookie belongs to the browser that earned
  it: the same user agent, and usually the same IP address, must carry it. A Turnstile token has no
  such tie to your later requests; it is spent on one form.
- **A challenge page covers every request.** Once you hold a valid cookie, you can fetch many pages
  until it expires. A Turnstile token covers one submission.

## What ZeroCaptcha does for each

ZeroCaptcha solves Cloudflare Turnstile widgets: a task with the page URL and sitekey returns a token.
The [Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver) page has samples in ten languages and tools.

For challenge pages, a challenge task takes the page URL and your proxy, and returns the cf_clearance cookie together with the user agent it was issued for, so your client can replay both through the same network.
The [Cloudflare WAF and 5-second challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver) page has the details.

## Before you automate either

Both features exist because a site owner decided to slow down automated traffic. Automate only
sites you are allowed to: your own, a client's with permission, or public pages whose terms allow
it. The [Acceptable Use Policy](https://zerocaptcha.io/legal/acceptable-use) applies to every task, and site owners can
ask to [opt out](https://zerocaptcha.io/opt-out).

## Questions

### Is the "Just a moment..." page a Turnstile widget?

No. It is a Cloudflare challenge page that the site's Cloudflare settings show before the site itself. Passing it sets a cf_clearance cookie rather than giving a form token.

### Can a Turnstile token get me past a challenge page?

No. A Turnstile token is verified by the site's own server for one form. A challenge page is checked by Cloudflare's network, which looks for a valid cf_clearance cookie.

### Can ZeroCaptcha handle a Cloudflare challenge page today?

Yes. A challenge task passes the page through your proxy and returns the cf_clearance cookie and the user agent it was issued for. Cloudflare Turnstile widgets have their own task.
