# How to Find a Cloudflare Turnstile Sitekey on Any Page

> Find a Cloudflare Turnstile sitekey in data-sitekey, in turnstile.render() or in the network log, and check you have the right one before you send a task.

- Source: https://zerocaptcha.io/guides/find-cloudflare-turnstile-sitekey
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

Every Turnstile task needs two details of the page: its full URL and the widget's **sitekey**.
The sitekey is public, it is in the page, and it usually takes under a minute to find. This guide
shows the four places it lives, how to tell it apart from other keys, and how to check it before
you spend money on a task.

## What a sitekey looks like

A Turnstile sitekey is a short string that most often starts with `0x4AAAAAAA`, such as
`0x4AAAAAAAB1cD2eF3gH4iJ5`. It is not a UUID, not a JWT and not the long token the widget
produces. If what you found is hundreds of characters long, you are looking at a token, not a
sitekey.

## 1. In the widget's HTML: data-sitekey

Most sites use the implicit rendering that Cloudflare documents: a `div` with the class
`cf-turnstile` and a `data-sitekey` attribute.

```html
<form action="/login" method="post">
  <div class="cf-turnstile" data-sitekey="0x4AAAAAAAB1cD2eF3gH4iJ5" data-action="login"></div>
  <button type="submit">Log in</button>
</form>
```

Open the page, view its source or the inspector, and search for `data-sitekey`. Note
`data-action` and `data-cdata` too if they are there: a task should carry the same values. See
[Cloudflare Turnstile action and cData](https://zerocaptcha.io/guides/cloudflare-turnstile-action-and-cdata).

## 2. In JavaScript: turnstile.render()

Single-page apps often render the widget from code. Search the page's scripts for
`turnstile.render`:

```js
turnstile.render("#login-captcha", {
  sitekey: "0x4AAAAAAAB1cD2eF3gH4iJ5",
  action: "login",
  callback: (token) => submitLogin(token),
});
```

The `sitekey` option is the one you need. In bundled code the call may be minified, but the key
itself is a plain string and search finds it.

## 3. In the network log

If the sitekey is built at runtime, open the browser's developer tools, go to the Network tab and
reload the page. The widget loads from `challenges.cloudflare.com`, and the requests it makes name
the sitekey in their URLs. Filter by `challenges.cloudflare.com` and look for the `0x4…` value.

## 4. From your automation tool

If you already drive the page with Playwright, Puppeteer or Selenium, read the attribute there
instead of copying it by hand:

```python
sitekey = page.locator(".cf-turnstile").get_attribute("data-sitekey")
```

That keeps your code working when the site owner rotates the key. The
[Playwright](https://zerocaptcha.io/cloudflare-turnstile-solver/playwright), [Puppeteer](https://zerocaptcha.io/cloudflare-turnstile-solver/puppeteer) and
[Selenium](https://zerocaptcha.io/cloudflare-turnstile-solver/selenium) pages show the whole flow from reading the sitekey to
submitting the token.

To try both ways on a real widget, compare the
[implicit rendering demo](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-implicit-rendering), where the sitekey
is in the HTML, with the [explicit rendering demo](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-explicit-rendering),
where it is in the script. The [Cloudflare Turnstile sitekey finder](https://zerocaptcha.io/tools/cloudflare-turnstile-sitekey-finder)
reads both from HTML you paste.

## Use the right URL too

`websiteURL` is the address of the page that shows the widget, such as
`https://shop.example.com/login`, not the address the form posts to and not the Cloudflare
script's URL. Use the full URL with its path. For a widget in an iframe, use the URL of the page
the visitor sees.

## Send the task

With both values, and the widget's action and cData when it sets them, a task in the compatible
format looks like this:

```sh
# metadata holds the widget's data-action and data-cdata, found beside data-sitekey (or the
# action and cData options of turnstile.render()): leave out any the widget does not set. The
# Idempotency-Key makes a retried create return the same task.
curl -s "$ZEROCAPTCHA_API/createTask" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
    "clientKey": "'"$ZEROCAPTCHA_KEY"'",
    "task": {
      "type": "TurnstileTaskProxyless",
      "websiteURL": "https://shop.example.com/login",
      "websiteKey": "0x4AAAAAAAB1cD2eF3gH4iJ5",
      "metadata": {"action": "login", "cdata": "session-7f3a9c2e"}
    }
  }'
```

The reply carries a `taskId`; poll `getTaskResult` with it until the token is ready. The
[quickstart](https://zerocaptcha.io/docs/quickstart) shows the complete loop, and the [Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver)
page shows it in every supported language.

## When the sitekey is wrong

A wrong sitekey does not fail at `createTask`: the task is accepted and then cannot be solved. It
ends with `ERROR_CAPTCHA_UNSOLVABLE`, and nothing is charged, because a task is charged only when
its token is ready. If several tasks in a row end that way, check the sitekey and URL against the
live page before anything else. [Captcha API error codes](https://zerocaptcha.io/guides/captcha-api-error-codes)
lists the other outcomes and what each costs.

## Checklist

- The sitekey comes from the widget on the form you submit, not from another widget on the page.
- `websiteURL` is the full page URL the visitor sees.
- `action` and `cdata` match the widget's, when it sets them.
- You read the sitekey from the live page, not from a copy saved weeks ago.

## Questions

### Is the Cloudflare Turnstile sitekey a secret?

No. The sitekey is public and sits in the page for every visitor. The secret key, which verifies tokens, stays on the site's server and never appears in the page.

### Can a page have more than one Cloudflare Turnstile sitekey?

Yes. A page can render several widgets, each with its own sitekey. Use the sitekey of the widget on the form you are submitting.

### Does the sitekey change over time?

Site owners can create new widgets or rotate keys in the Cloudflare dashboard, so read the sitekey from the live page again if tasks start to fail.
