Cloudflare Turnstile
Cloudflare Turnstile Modes: Managed, Non-Interactive, Invisible
Cloudflare Turnstile's three widget modes compared: what visitors see in each, how to tell which one a page uses, and why a solving task is the same for all.
3 min readPublished Updated
Cloudflare lets a site owner choose how visible a Turnstile widget is. There are three modes, set per widget in the Cloudflare dashboard: managed, non-interactive and invisible. They change what a visitor sees; they do not change what a solving task needs. This guide describes each mode, how to recognize it, and what it means for automation and testing.
Managed
Managed mode is the one Cloudflare recommends. The widget shows a small box. For most visitors it runs its checks and shows a success mark without any interaction. When Cloudflare wants more evidence, the box asks the visitor to tick a checkbox. There are no image grids or puzzles in either case.
How to recognize it: a visible box on the form, sometimes with a checkbox, labeled with Cloudflare’s branding.
Non-interactive
Non-interactive mode also shows the box, with a loading indicator while it runs, but it never asks the visitor to do anything. The checks run in the background, and the widget reports success when they pass.
How to recognize it: a visible box that shows progress and then success, with no checkbox.
Invisible
Invisible mode shows nothing. The widget runs in the background of the page, and the page’s code
receives the token through the widget’s callback or finds it in the hidden
cf-turnstile-response input. Cloudflare requires a site that uses invisible mode to reference its
Turnstile privacy addendum in the site’s own privacy policy.
How to recognize it: no box at all, but the page loads the Turnstile script from
challenges.cloudflare.com and contains a cf-turnstile element or a turnstile.render() call.
Comparing the three
| Mode | Visible box | Visitor may need to click | Token in the page |
|---|---|---|---|
| Managed | Yes | Sometimes, a checkbox | Hidden input or callback |
| Non-interactive | Yes | Never | Hidden input or callback |
| Invisible | No | Never | Hidden input or callback |
In all three, the result is the same kind of token: single-use, valid for 300 seconds, and verified by the site’s server with Cloudflare’s siteverify endpoint.
What changes for a solving task: nothing
A ZeroCaptcha task describes the widget, not how it looks. It needs:
websiteURL: the page with the widget.websiteKey: the widget’s sitekey.actionandcdata: when the widget sets them.
The same task types, TurnstileTaskProxyless and TurnstileTask, work for every mode. You do not
tell the API which mode the widget uses. Find a Cloudflare Turnstile sitekey
shows where the sitekey hides in each case, including invisible widgets rendered from code.
{ "clientKey": "zc_live_…", "task": { "type": "TurnstileTaskProxyless", "websiteURL": "https://shop.example.com/login", "websiteKey": "0x4AAAAAAAB1cD2eF3gH4iJ5", "metadata": { "action": "login", "cdata": "session-7f3a9c2e" } }}metadata carries the widget’s data-action and data-cdata, or the action and cData options
of turnstile.render(), whatever its mode; leave out any the widget does not set.
What changes for your automation
The mode matters for how you hand the token to the page, not for how you get it:
- With a visible widget driven in a real browser, the widget may keep running its own checks while your script works. Set the token in the hidden input, or call the page’s callback, then submit. Submit a Cloudflare Turnstile token shows both.
- With an invisible widget, the page’s code often submits on its own once the callback fires. Find the function the callback calls and call it with your token, or post the request yourself.
Testing your own widgets
If the widget is on your own site, you can test every mode without a solver. Cloudflare publishes testing sitekeys that always pass, always fail or force an interactive challenge, in visible and invisible variants. Test Cloudflare Turnstile in CI lists them and shows how to switch keys per environment.
See each mode live
The managed, non-interactive and invisible Cloudflare Turnstile demos each carry one widget in that mode, with its markup and a check of the token it gives. The Cloudflare Turnstile demo and CAPTCHA test pages have the appearances and sizes too.
Where to go next
The Cloudflare Turnstile solver page walks through the full flow with samples in Python, Node.js, Go, PHP, Java, C# and curl, and in Playwright, Puppeteer and Selenium. For the words used here, such as sitekey and siteverify, see the glossary.