Skip to content

Cloudflare Turnstile

Cloudflare Turnstile Modes: Managed, Non-Interactive, Invisible

Cloudflare Turnstile's three widget modes compared: what visitors see in each, how to tell which one a page uses, and why a solving task is the same for all.

3 min readPublished Updated

Cloudflare lets a site owner choose how visible a Turnstile widget is. There are three modes, set per widget in the Cloudflare dashboard: managed, non-interactive and invisible. They change what a visitor sees; they do not change what a solving task needs. This guide describes each mode, how to recognize it, and what it means for automation and testing.

Managed

Managed mode is the one Cloudflare recommends. The widget shows a small box. For most visitors it runs its checks and shows a success mark without any interaction. When Cloudflare wants more evidence, the box asks the visitor to tick a checkbox. There are no image grids or puzzles in either case.

How to recognize it: a visible box on the form, sometimes with a checkbox, labeled with Cloudflare’s branding.

Non-interactive

Non-interactive mode also shows the box, with a loading indicator while it runs, but it never asks the visitor to do anything. The checks run in the background, and the widget reports success when they pass.

How to recognize it: a visible box that shows progress and then success, with no checkbox.

Invisible

Invisible mode shows nothing. The widget runs in the background of the page, and the page’s code receives the token through the widget’s callback or finds it in the hidden cf-turnstile-response input. Cloudflare requires a site that uses invisible mode to reference its Turnstile privacy addendum in the site’s own privacy policy.

How to recognize it: no box at all, but the page loads the Turnstile script from challenges.cloudflare.com and contains a cf-turnstile element or a turnstile.render() call.

Comparing the three

Mode Visible box Visitor may need to click Token in the page
Managed Yes Sometimes, a checkbox Hidden input or callback
Non-interactive Yes Never Hidden input or callback
Invisible No Never Hidden input or callback

In all three, the result is the same kind of token: single-use, valid for 300 seconds, and verified by the site’s server with Cloudflare’s siteverify endpoint.

What changes for a solving task: nothing

A ZeroCaptcha task describes the widget, not how it looks. It needs:

  • websiteURL: the page with the widget.
  • websiteKey: the widget’s sitekey.
  • action and cdata: when the widget sets them.

The same task types, TurnstileTaskProxyless and TurnstileTask, work for every mode. You do not tell the API which mode the widget uses. Find a Cloudflare Turnstile sitekey shows where the sitekey hides in each case, including invisible widgets rendered from code.

{
"clientKey": "zc_live_…",
"task": {
"type": "TurnstileTaskProxyless",
"websiteURL": "https://shop.example.com/login",
"websiteKey": "0x4AAAAAAAB1cD2eF3gH4iJ5",
"metadata": { "action": "login", "cdata": "session-7f3a9c2e" }
}
}

metadata carries the widget’s data-action and data-cdata, or the action and cData options of turnstile.render(), whatever its mode; leave out any the widget does not set.

What changes for your automation

The mode matters for how you hand the token to the page, not for how you get it:

  • With a visible widget driven in a real browser, the widget may keep running its own checks while your script works. Set the token in the hidden input, or call the page’s callback, then submit. Submit a Cloudflare Turnstile token shows both.
  • With an invisible widget, the page’s code often submits on its own once the callback fires. Find the function the callback calls and call it with your token, or post the request yourself.

Testing your own widgets

If the widget is on your own site, you can test every mode without a solver. Cloudflare publishes testing sitekeys that always pass, always fail or force an interactive challenge, in visible and invisible variants. Test Cloudflare Turnstile in CI lists them and shows how to switch keys per environment.

See each mode live

The managed, non-interactive and invisible Cloudflare Turnstile demos each carry one widget in that mode, with its markup and a check of the token it gives. The Cloudflare Turnstile demo and CAPTCHA test pages have the appearances and sizes too.

Where to go next

The Cloudflare Turnstile solver page walks through the full flow with samples in Python, Node.js, Go, PHP, Java, C# and curl, and in Playwright, Puppeteer and Selenium. For the words used here, such as sitekey and siteverify, see the glossary.

Questions

Does an invisible Cloudflare Turnstile widget still have a sitekey?

Yes. Every widget has a sitekey, whatever its mode. An invisible widget is still rendered from a div or a turnstile.render() call that names it.

Do I need a different task type for invisible Cloudflare Turnstile?

No. TurnstileTaskProxyless and TurnstileTask cover every mode; the task needs the page URL and sitekey, plus action and cData when the widget sets them.

Where does a site owner choose the mode?

In the Cloudflare dashboard, per widget. The mode is not written in the page, so you usually tell it by what the widget shows.

Read next

This guide is part of the Cloudflare Turnstile solver hub. Every task is charged only when a token is ready.

Get an API key