Skip to content

Cloudflare Turnstile

How to Find a Cloudflare Turnstile Sitekey on Any Page

Find a Cloudflare Turnstile sitekey in data-sitekey, in turnstile.render() or in the network log, and check you have the right one before you send a task.

3 min readPublished Updated

Every Turnstile task needs two details of the page: its full URL and the widget’s sitekey. The sitekey is public, it is in the page, and it usually takes under a minute to find. This guide shows the four places it lives, how to tell it apart from other keys, and how to check it before you spend money on a task.

What a sitekey looks like

A Turnstile sitekey is a short string that most often starts with 0x4AAAAAAA, such as 0x4AAAAAAAB1cD2eF3gH4iJ5. It is not a UUID, not a JWT and not the long token the widget produces. If what you found is hundreds of characters long, you are looking at a token, not a sitekey.

1. In the widget’s HTML: data-sitekey

Most sites use the implicit rendering that Cloudflare documents: a div with the class cf-turnstile and a data-sitekey attribute.

<form action="/login" method="post">
<div class="cf-turnstile" data-sitekey="0x4AAAAAAAB1cD2eF3gH4iJ5" data-action="login"></div>
<button type="submit">Log in</button>
</form>

Open the page, view its source or the inspector, and search for data-sitekey. Note data-action and data-cdata too if they are there: a task should carry the same values. See Cloudflare Turnstile action and cData.

2. In JavaScript: turnstile.render()

Single-page apps often render the widget from code. Search the page’s scripts for turnstile.render:

turnstile.render("#login-captcha", {
sitekey: "0x4AAAAAAAB1cD2eF3gH4iJ5",
action: "login",
callback: (token) => submitLogin(token),
});

The sitekey option is the one you need. In bundled code the call may be minified, but the key itself is a plain string and search finds it.

3. In the network log

If the sitekey is built at runtime, open the browser’s developer tools, go to the Network tab and reload the page. The widget loads from challenges.cloudflare.com, and the requests it makes name the sitekey in their URLs. Filter by challenges.cloudflare.com and look for the 0x4… value.

4. From your automation tool

If you already drive the page with Playwright, Puppeteer or Selenium, read the attribute there instead of copying it by hand:

sitekey = page.locator(".cf-turnstile").get_attribute("data-sitekey")

That keeps your code working when the site owner rotates the key. The Playwright, Puppeteer and Selenium pages show the whole flow from reading the sitekey to submitting the token.

To try both ways on a real widget, compare the implicit rendering demo, where the sitekey is in the HTML, with the explicit rendering demo, where it is in the script. The Cloudflare Turnstile sitekey finder reads both from HTML you paste.

Use the right URL too

websiteURL is the address of the page that shows the widget, such as https://shop.example.com/login, not the address the form posts to and not the Cloudflare script’s URL. Use the full URL with its path. For a widget in an iframe, use the URL of the page the visitor sees.

Send the task

With both values, and the widget’s action and cData when it sets them, a task in the compatible format looks like this:

Terminal window
# metadata holds the widget's data-action and data-cdata, found beside data-sitekey (or the
# action and cData options of turnstile.render()): leave out any the widget does not set. The
# Idempotency-Key makes a retried create return the same task.
curl -s "$ZEROCAPTCHA_API/createTask" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"clientKey": "'"$ZEROCAPTCHA_KEY"'",
"task": {
"type": "TurnstileTaskProxyless",
"websiteURL": "https://shop.example.com/login",
"websiteKey": "0x4AAAAAAAB1cD2eF3gH4iJ5",
"metadata": {"action": "login", "cdata": "session-7f3a9c2e"}
}
}'

The reply carries a taskId; poll getTaskResult with it until the token is ready. The quickstart shows the complete loop, and the Cloudflare Turnstile solver page shows it in every supported language.

When the sitekey is wrong

A wrong sitekey does not fail at createTask: the task is accepted and then cannot be solved. It ends with ERROR_CAPTCHA_UNSOLVABLE, and nothing is charged, because a task is charged only when its token is ready. If several tasks in a row end that way, check the sitekey and URL against the live page before anything else. Captcha API error codes lists the other outcomes and what each costs.

Checklist

  • The sitekey comes from the widget on the form you submit, not from another widget on the page.
  • websiteURL is the full page URL the visitor sees.
  • action and cdata match the widget’s, when it sets them.
  • You read the sitekey from the live page, not from a copy saved weeks ago.

Questions

Is the Cloudflare Turnstile sitekey a secret?

No. The sitekey is public and sits in the page for every visitor. The secret key, which verifies tokens, stays on the site's server and never appears in the page.

Can a page have more than one Cloudflare Turnstile sitekey?

Yes. A page can render several widgets, each with its own sitekey. Use the sitekey of the widget on the form you are submitting.

Does the sitekey change over time?

Site owners can create new widgets or rotate keys in the Cloudflare dashboard, so read the sitekey from the live page again if tasks start to fail.

Read next

This guide is part of the Cloudflare Turnstile solver hub. Every task is charged only when a token is ready.

Get an API key