# Cloudflare Turnstile Modes: Managed, Non-Interactive, Invisible

> Cloudflare Turnstile's three widget modes compared: what visitors see in each, how to tell which one a page uses, and why a solving task is the same for all.

- Source: https://zerocaptcha.io/guides/cloudflare-turnstile-widget-modes
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

Cloudflare lets a site owner choose how visible a Turnstile widget is. There are three modes, set
per widget in the Cloudflare dashboard: **managed**, **non-interactive** and **invisible**. They
change what a visitor sees; they do not change what a solving task needs. This guide describes
each mode, how to recognize it, and what it means for automation and testing.

## Managed

Managed mode is the one Cloudflare recommends. The widget shows a small box. For most visitors it runs its
checks and shows a success mark without any interaction. When Cloudflare wants more evidence, the
box asks the visitor to tick a checkbox. There are no image grids or puzzles in either case.

**How to recognize it:** a visible box on the form, sometimes with a checkbox, labeled with
Cloudflare's branding.

## Non-interactive

Non-interactive mode also shows the box, with a loading indicator while it runs, but it never
asks the visitor to do anything. The checks run in the background, and the widget reports success
when they pass.

**How to recognize it:** a visible box that shows progress and then success, with no checkbox.

## Invisible

Invisible mode shows nothing. The widget runs in the background of the page, and the page's code
receives the token through the widget's callback or finds it in the hidden
`cf-turnstile-response` input. Cloudflare requires a site that uses invisible mode to reference its
Turnstile privacy addendum in the site's own privacy policy.

**How to recognize it:** no box at all, but the page loads the Turnstile script from
`challenges.cloudflare.com` and contains a `cf-turnstile` element or a `turnstile.render()` call.

## Comparing the three

| Mode | Visible box | Visitor may need to click | Token in the page |
| --- | --- | --- | --- |
| Managed | Yes | Sometimes, a checkbox | Hidden input or callback |
| Non-interactive | Yes | Never | Hidden input or callback |
| Invisible | No | Never | Hidden input or callback |

In all three, the result is the same kind of token: single-use, valid for 300 seconds, and
verified by the site's server with Cloudflare's siteverify endpoint.

## What changes for a solving task: nothing

A ZeroCaptcha task describes the widget, not how it looks. It needs:

- `websiteURL`: the page with the widget.
- `websiteKey`: the widget's sitekey.
- `action` and `cdata`: when the widget sets them.

The same task types, `TurnstileTaskProxyless` and `TurnstileTask`, work for every mode. You do not
tell the API which mode the widget uses. [Find a Cloudflare Turnstile sitekey](https://zerocaptcha.io/guides/find-cloudflare-turnstile-sitekey)
shows where the sitekey hides in each case, including invisible widgets rendered from code.

```json
{
  "clientKey": "zc_live_…",
  "task": {
    "type": "TurnstileTaskProxyless",
    "websiteURL": "https://shop.example.com/login",
    "websiteKey": "0x4AAAAAAAB1cD2eF3gH4iJ5",
    "metadata": { "action": "login", "cdata": "session-7f3a9c2e" }
  }
}
```

`metadata` carries the widget's `data-action` and `data-cdata`, or the `action` and `cData` options
of `turnstile.render()`, whatever its mode; leave out any the widget does not set.

## What changes for your automation

The mode matters for how you hand the token to the page, not for how you get it:

- With a **visible** widget driven in a real browser, the widget may keep running its own checks
  while your script works. Set the token in the hidden input, or call the page's callback, then
  submit. [Submit a Cloudflare Turnstile token](https://zerocaptcha.io/guides/submit-cloudflare-turnstile-token) shows both.
- With an **invisible** widget, the page's code often submits on its own once the callback fires.
  Find the function the callback calls and call it with your token, or post the request yourself.

## Testing your own widgets

If the widget is on your own site, you can test every mode without a solver. Cloudflare publishes
testing sitekeys that always pass, always fail or force an interactive challenge, in visible and
invisible variants. [Test Cloudflare Turnstile in CI](https://zerocaptcha.io/guides/test-cloudflare-turnstile-in-ci) lists them and shows how
to switch keys per environment.

## See each mode live

The [managed](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-managed),
[non-interactive](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-non-interactive) and
[invisible](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-invisible) Cloudflare Turnstile demos each carry one
widget in that mode, with its markup and a check of the token it gives. The
[Cloudflare Turnstile demo and CAPTCHA test pages](https://zerocaptcha.io/captcha-test) have the appearances and sizes
too.

## Where to go next

The [Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver) page walks through the full flow with samples in Python,
Node.js, Go, PHP, Java, C# and curl, and in Playwright, Puppeteer and Selenium. For the words used
here, such as sitekey and siteverify, see the [glossary](https://zerocaptcha.io/glossary).

## Questions

### Does an invisible Cloudflare Turnstile widget still have a sitekey?

Yes. Every widget has a sitekey, whatever its mode. An invisible widget is still rendered from a div or a turnstile.render() call that names it.

### Do I need a different task type for invisible Cloudflare Turnstile?

No. TurnstileTaskProxyless and TurnstileTask cover every mode; the task needs the page URL and sitekey, plus action and cData when the widget sets them.

### Where does a site owner choose the mode?

In the Cloudflare dashboard, per widget. The mode is not written in the page, so you usually tell it by what the widget shows.
