# ZeroCaptcha > ZeroCaptcha is a CAPTCHA-solving API for developers. It solves Cloudflare Turnstile widgets and Cloudflare WAF and 5-second challenge pages (the "Just a moment..." screen): create a task with the page, then poll for the token (or cf_clearance cookie) or receive it by a signed callback. You pay per solved task from a prepaid USD balance; failed tasks cost nothing. - Three API formats on one host: REST v1 with idempotency keys and RFC 9457 errors, the createTask format (createTask, getTaskResult, getBalance), and 2Captcha's in.php and res.php. - Task types TurnstileTaskProxyless and TurnstileTask (through your HTTP or HTTPS proxy), with the aliases AntiTurnstileTaskProxyLess and AntiTurnstileTask; and CloudflareChallengeTask, alias AntiCloudflareTask, for a Cloudflare WAF or 5-second challenge page, always through your proxy. - A task's price is held when it is created and charged only when a token is ready; a failed or expired task costs nothing. Cloudflare Turnstile tokens work once, for 300 seconds. - One kind of API key (zc_live_…), sent as a bearer token, with scopes, IP allowlists, per-key daily spend caps, rotation and revocation. Every task is real and paid: there is no sandbox, test key or free credit. Callbacks are signed with HMAC-SHA256. - Prepaid in US dollars, topped up in crypto through NOWPayments from $10 with no maximum; top-ups are final. - Official clients for JavaScript, Python and Go are coming to their package registries; until then, and in any other language, call the API over plain HTTP. - Solve Cloudflare WAF and 5-second challenge pages too: a task returns the cf_clearance cookie with the user agent it was issued for. - For sites you are allowed to automate only: the Acceptable Use Policy applies, staff block a domain by hand after a report, and any site owner can ask to opt out. - For AI coding assistants: start with the integration brief under "For AI assistants"; it is self-contained. ## Solvers - [Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver): Cloudflare Turnstile tokens through createTask, in.php or REST - [Cloudflare WAF and 5-second challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver): cf_clearance for "Just a moment..." pages ## Languages and tools - [Solve Cloudflare Turnstile in Python](https://zerocaptcha.io/cloudflare-turnstile-solver/python): Solve Cloudflare Turnstile from Python with requests: create a task, poll for the token, pay only for solved tasks. An official Python client is coming. - [Solve Cloudflare Turnstile in Node.js](https://zerocaptcha.io/cloudflare-turnstile-solver/nodejs): Solve Cloudflare Turnstile from Node.js with fetch: create a task, poll for the token, pay only when solved. An official JavaScript client is coming. - [Solve Cloudflare Turnstile in Go](https://zerocaptcha.io/cloudflare-turnstile-solver/go): Solve Cloudflare Turnstile from Go with net/http: create a task, poll for its token within a deadline, pay only for solved tasks. A Go client is coming. - [Solve Cloudflare Turnstile in PHP](https://zerocaptcha.io/cloudflare-turnstile-solver/php): Solve Cloudflare Turnstile from PHP with the curl extension: create a task, poll getTaskResult for the token, and pay only for solved tasks. - [Solve Cloudflare Turnstile in Java](https://zerocaptcha.io/cloudflare-turnstile-solver/java): Solve Cloudflare Turnstile from Java with java.net.http and Jackson: create a task, poll for the token, pay only for solved tasks. - [Solve Cloudflare Turnstile in C#](https://zerocaptcha.io/cloudflare-turnstile-solver/csharp): Solve Cloudflare Turnstile from C# with HttpClient and System.Text.Json: create a task, poll for the token, and pay only for solved tasks. - [Solve Cloudflare Turnstile in Playwright](https://zerocaptcha.io/cloudflare-turnstile-solver/playwright): Fill a Cloudflare Turnstile widget in Playwright: read its site key, action and cData, get a token from ZeroCaptcha, set the form field and submit. - [Solve Cloudflare Turnstile in Puppeteer](https://zerocaptcha.io/cloudflare-turnstile-solver/puppeteer): Fill a Cloudflare Turnstile widget in Puppeteer: read its site key, action and cData, get a token from ZeroCaptcha, set the form field and submit. - [Solve Cloudflare Turnstile in Selenium](https://zerocaptcha.io/cloudflare-turnstile-solver/selenium): Fill a Cloudflare Turnstile widget in Selenium with Python: read its site key, action and cData, get a token from ZeroCaptcha, set the field, submit. - [Solve Cloudflare Turnstile with curl](https://zerocaptcha.io/cloudflare-turnstile-solver/curl): Solve Cloudflare Turnstile from the shell with curl and jq: createTask, poll getTaskResult, print the token. Every failure named, nothing charged. ## Docs - [Introduction](https://zerocaptcha.io/docs.md): What ZeroCaptcha does, how a task goes from createTask to a token, the three API formats, your key and your prepaid balance, and where to go next. - [2Captcha format](https://zerocaptcha.io/docs/2captcha.md): Use a 2Captcha client with ZeroCaptcha for Cloudflare Turnstile. in.php and res.php, their parameters, replies and error codes, and what differs. - [Account security](https://zerocaptcha.io/docs/account-security.md): Protect your ZeroCaptcha sign-in with an authenticator app, recovery codes and passkeys, manage your sessions, and see what needs a recent sign-in. - [Cloudflare Turnstile action and cData](https://zerocaptcha.io/docs/action-and-cdata.md): When a Cloudflare Turnstile task needs the widget's action and cData, where to find them, what happens without them, and how to send them in every format. - [Hand off to AI](https://zerocaptcha.io/docs/ai.md): Hand your AI coding assistant one file to integrate ZeroCaptcha: the brief, its JSON, Claude Code, Cursor, AGENTS.md and Copilot files, and an MCP server. - [Authentication](https://zerocaptcha.io/docs/authentication.md): Send your ZeroCaptcha API key in each format, read it from the environment, rotate it without an outage, and keep it out of code, logs and browsers. - [Browser automation](https://zerocaptcha.io/docs/browser-automation.md): Read a page's Cloudflare Turnstile site key in Playwright, Puppeteer, Selenium or chromedp, solve it with ZeroCaptcha, and put the token in the page. - [Polling and callbacks](https://zerocaptcha.io/docs/callbacks.md): Wait for a task by polling every 2 seconds, following live updates, or having ZeroCaptcha call your endpoint, and check each call's HMAC-SHA256 signature. - [Cloudflare WAF and 5-second challenges](https://zerocaptcha.io/docs/challenges.md): Pass a Cloudflare WAF or 5-second challenge page ("Just a moment...") through your proxy, then use its cf_clearance cookie with its user agent. - [Solving Cloudflare Turnstile](https://zerocaptcha.io/docs/cloudflare-turnstile.md): Every field of a Cloudflare Turnstile task, how to find the site key, action and cData on a page, and how to use the token in a form or a callback. - [createTask format](https://zerocaptcha.io/docs/createtask.md): ZeroCaptcha's createTask, getTaskResult and getBalance, the JSON format other CAPTCHA APIs use: every field and spelling, reply, code and sample. - [Errors and retries](https://zerocaptcha.io/docs/errors-and-retries.md): Which ZeroCaptcha errors a retry can fix, how long to wait, how to back off, and how an Idempotency-Key makes retrying a create safe. - [Billing](https://zerocaptcha.io/docs/funds.md): Your prepaid USD balance, top-ups in crypto through NOWPayments from $10, how under- and over-payments are credited, receipts, caps and task costs. - [How a task works](https://zerocaptcha.io/docs/how-tasks-work.md): A task's states from queued to succeeded, failed or expired, how long each step takes, how long a token lasts, and what is charged and when. - [API keys](https://zerocaptcha.io/docs/keys.md): How ZeroCaptcha API keys work, from their scopes to allowlists, rotation with an overlap and revocation. - [Migrate a 2Captcha client](https://zerocaptcha.io/docs/migrate-2captcha.md): Move Cloudflare Turnstile solving from 2Captcha to ZeroCaptcha with in.php and res.php or the createTask format: change the host and key, then check. - [Migrate a createTask client](https://zerocaptcha.io/docs/migrate-createtask.md): Move a CapSolver or Anti-Captcha style createTask client to ZeroCaptcha: change the host and key, then check its field names and replies. - [Quickstart](https://zerocaptcha.io/docs/quickstart.md): Create a Cloudflare Turnstile task, poll for its token with a deadline and handle every failure, in Python, Node, Go or curl. - [Rate limits and concurrency](https://zerocaptcha.io/docs/rate-limits.md): What bounds how many tasks you can run and how often you can read them, the RateLimit headers that say where you stand, and how to run many tasks at once. - [Callback payload](https://zerocaptcha.io/docs/reference/callbacks.md): Exactly what ZeroCaptcha POSTs to your callback URL in each format, its headers, how its signature is computed, and how deliveries are retried. - [Changelog](https://zerocaptcha.io/docs/reference/changelog.md): What changed in the ZeroCaptcha API, its formats, the dashboard and these docs, newest first, and how changes to the API are announced. - [Errors](https://zerocaptcha.io/docs/reference/errors.md): Every error code in both API dialects, with what it means, whether a retry helps, what to do next and what it costs. - [FAQ](https://zerocaptcha.io/docs/reference/faq.md): Answers to the questions buyers ask about ZeroCaptcha: trying it, what is charged, tokens, proxies, errors, keys, payments, limits and support. - [Limits](https://zerocaptcha.io/docs/reference/limits.md): Every ZeroCaptcha limit in one place: request sizes and timeouts, field lengths, task deadlines, token lifetimes, budgets, keys, callbacks and retention. - [SDKs](https://zerocaptcha.io/docs/sdks.md): The official ZeroCaptcha clients for JavaScript, Python and Go. Solve Cloudflare Turnstile and WAF challenge pages, read your balance and check callbacks. - [Go SDK](https://zerocaptcha.io/docs/sdks/go.md): The official ZeroCaptcha client for Go, standard library only: solve Cloudflare Turnstile and WAF challenge pages, handle errors and check callbacks. - [Node.js SDK](https://zerocaptcha.io/docs/sdks/node.md): The official ZeroCaptcha client for JavaScript and TypeScript: solve Cloudflare Turnstile and WAF challenge pages, handle errors and check callbacks. - [Python SDK](https://zerocaptcha.io/docs/sdks/python.md): The official ZeroCaptcha client for Python, standard library only: solve Cloudflare Turnstile and WAF challenge pages, handle errors and check callbacks. - [Teams and roles](https://zerocaptcha.io/docs/teams.md): Invite people to your ZeroCaptcha account as owners or members, what each role can do, and the activity log that records every change. - [API reference](https://zerocaptcha.io/docs/reference/api.md): Every ZeroCaptcha API operation your code can call, generated from the OpenAPI contract. - [Tasks API](https://zerocaptcha.io/docs/reference/api/tasks.md): Create Turnstile tasks, read their results, and follow them live. - [Compatible format API](https://zerocaptcha.io/docs/reference/api/compatible.md): The createTask format other providers use, so existing clients work unchanged. Its errors come in its errorId shape, with HTTP 200; only a failure outside the endpoint, such as a body over the size limit, is a problem document. - [2Captcha format API](https://zerocaptcha.io/docs/reference/api/2captcha.md): 2Captcha's in.php and res.php for Turnstile, so a 2Captcha client works after changing only its base URL and key. Priced and charged as the other dialects are. Every reply is HTTP 200, as plain text or, with `json=1`, JSON; only a failure outside the endpoint is a problem document. - [Balance API](https://zerocaptcha.io/docs/reference/api/balance.md): The prepaid balance and what is held for tasks in progress. - [Prices API](https://zerocaptcha.io/docs/reference/api/prices.md): What each task type costs now and the next change scheduled: public, with no key or session, and cacheable. - [Status feed API](https://zerocaptcha.io/docs/reference/api/status.md): The platform's last 24 hours: task success rate, median solve time and API availability. Public, with no key or session, and cacheable. - [Site-owner opt-out API](https://zerocaptcha.io/docs/reference/api/opt-out.md): Site owners asking for their domain to be excluded: public, with no key or session. Staff check and decide each request by hand. - [Abuse reports API](https://zerocaptcha.io/docs/reference/api/abuse-reports.md): Reporting a site ZeroCaptcha was used against: public, with no key or session. Staff look into each report and act by hand. - [Support messages API](https://zerocaptcha.io/docs/reference/api/support.md): Messages to support: from the dashboard with a session, or from the public contact form with none. Staff answer by email. - [Demo pages API](https://zerocaptcha.io/docs/reference/api/demo.md): The public demo and CAPTCHA test pages: checking a token from one of their Cloudflare Turnstile widgets with Cloudflare's siteverify, and whether a request carried a Cloudflare clearance. Public, with no key or session; nothing here solves anything. - [Health API](https://zerocaptcha.io/docs/reference/api/health.md): Liveness and readiness probes for load balancers and orchestrators. - [The contract API](https://zerocaptcha.io/docs/reference/api/contract.md): Documents about the API itself, such as this contract. ## For AI assistants - [Integration brief](https://zerocaptcha.io/ai/integration.md): one self-contained file: configuration, every call, polling and callbacks, every error code, retries, reference clients in four languages and a checklist - [The brief as JSON](https://zerocaptcha.io/ai/zerocaptcha.json): endpoints, fields, enums, errors, rules and examples, for tools - [Claude Code skill](https://zerocaptcha.io/ai/claude/SKILL.md): save as .claude/skills/zerocaptcha/SKILL.md in your project - [Cursor rule](https://zerocaptcha.io/ai/cursor/zerocaptcha.mdc): save as .cursor/rules/zerocaptcha.mdc in your project - [AGENTS.md section](https://zerocaptcha.io/ai/AGENTS.md): paste into your project's AGENTS.md, read by Codex, Jules, Gemini CLI and other agents - [GitHub Copilot instructions](https://zerocaptcha.io/ai/copilot-instructions.md): save as .github/copilot-instructions.md in your repository - [Every docs page in one file](https://zerocaptcha.io/llms-full.txt) - [OpenAPI contract](https://zerocaptcha.io/openapi.json): the API's own OpenAPI 3.1 document ## Guides - [Captcha API Error Codes: What Each Means and What It Costs](https://zerocaptcha.io/guides/captcha-api-error-codes.md): ERROR_CAPTCHA_UNSOLVABLE, ERROR_ZERO_BALANCE, ERROR_KEY_DOES_NOT_EXIST and the rest: what each captcha API error means, whether to retry, and what it costs. - [Captcha Solver Callbacks: pingback and callbackUrl, No Polling](https://zerocaptcha.io/guides/captcha-solver-callbacks.md): Get Cloudflare Turnstile results pushed to your server instead of polling: callbackUrl and pingback, what each call contains, retries, and how to answer. - [Captcha Solver Concurrency, 429s and Retry-After](https://zerocaptcha.io/guides/rate-limits-and-concurrency.md): Run many Cloudflare Turnstile tasks at once: how ZeroCaptcha paces calls, what 429, ERROR_RATE_LIMIT and ERROR_NO_SLOT_AVAILABLE mean, and how to back off. - [Captcha Solving Cost: Price per 1,000 and What You Really Pay](https://zerocaptcha.io/guides/captcha-solving-cost.md): How captcha solving is priced per 1,000, why the real cost differs from the list price, and how to estimate a month of Cloudflare Turnstile tasks. - [Cloudflare Challenge Page vs Cloudflare Turnstile: Which Is It?](https://zerocaptcha.io/guides/cloudflare-challenge-vs-turnstile.md): The "Just a moment..." page and the Cloudflare Turnstile widget are different features. How each works, what it produces, and how to tell which you face. - [Cloudflare Turnstile action and cData: When a Task Needs Them](https://zerocaptcha.io/guides/cloudflare-turnstile-action-and-cdata.md): What Turnstile's action and cData parameters do, where to find them in a page, and how to pass them in createTask, in.php or REST so the token is accepted. - [Cloudflare Turnstile Modes: Managed, Non-Interactive, Invisible](https://zerocaptcha.io/guides/cloudflare-turnstile-widget-modes.md): Cloudflare Turnstile's three widget modes compared: what visitors see in each, how to tell which one a page uses, and why a solving task is the same for all. - [Cloudflare Turnstile Token Expired? Lifetime and Reuse Explained](https://zerocaptcha.io/guides/cloudflare-turnstile-token-expiry.md): Cloudflare Turnstile tokens last 300 seconds and work once. Why tokens expire, what timeout-or-duplicate means, and how to use each token before it runs out. - [createTask and getTaskResult: The Captcha API Format Explained](https://zerocaptcha.io/guides/createtask-gettaskresult-explained.md): How the createTask, getTaskResult and getBalance format works: request bodies, replies, errorId, polling, and ZeroCaptcha's Cloudflare Turnstile tasks. - [How to Find a Cloudflare Turnstile Sitekey on Any Page](https://zerocaptcha.io/guides/find-cloudflare-turnstile-sitekey.md): Find a Cloudflare Turnstile sitekey in data-sitekey, in turnstile.render() or in the network log, and check you have the right one before you send a task. - [Idempotency Keys: Retry Captcha Tasks Without Paying Twice](https://zerocaptcha.io/guides/idempotency-keys-for-captcha-tasks.md): Use an Idempotency-Key header so a retried createTask never makes a second task: how keys work for 24 hours, the two key errors, and finding a lost task. - [Migrate From 2Captcha: Cloudflare Turnstile in.php and createTask](https://zerocaptcha.io/guides/migrate-from-2captcha.md): Move Cloudflare Turnstile solving from 2Captcha to ZeroCaptcha: keep in.php and res.php or createTask, change the host and key, and check what differs. - [Migrate From Anti-Captcha: TurnstileTask on ZeroCaptcha](https://zerocaptcha.io/guides/migrate-from-anti-captcha.md): Move Cloudflare Turnstile tasks from Anti-Captcha to ZeroCaptcha: the same task types, calls and field names, cData included, and what to check first. - [Migrate From CapSolver: AntiTurnstileTaskProxyLess on ZeroCaptcha](https://zerocaptcha.io/guides/migrate-from-capsolver.md): Move Cloudflare Turnstile tasks from CapSolver to ZeroCaptcha: AntiTurnstileTaskProxyLess and its metadata fields work as they are. Change host and key. - [Pay for a Captcha API With Crypto: Top-ups, Receipts, Limits](https://zerocaptcha.io/guides/pay-for-captcha-api-with-crypto.md): How crypto top-ups work on ZeroCaptcha: invoices in US dollars, the hosted checkout, confirmations, under- and overpayments, receipts, and final top-ups. - [Responsible Captcha Automation: Acceptable Use and Opt-outs](https://zerocaptcha.io/guides/responsible-captcha-automation.md): When using a captcha solver is appropriate, what ZeroCaptcha's Acceptable Use Policy allows, and how site owners opt out or report abuse, all handled by people. - [Scraping a Site With Cloudflare Turnstile: An Authorized Pipeline](https://zerocaptcha.io/guides/cloudflare-turnstile-web-scraping.md): Collect data you are allowed to collect from pages behind Cloudflare Turnstile: when a solver fits, how to add it to a pipeline, and when to ask first. - [Secure Captcha API Keys: IP Allowlists, Rotation, Spend Caps](https://zerocaptcha.io/guides/secure-captcha-api-keys.md): Protect a captcha API key and your balance: scopes, IP allowlists, daily spend caps, rotation with an overlap, instant revocation, and spotting a leaked key. - [Solve Cloudflare Turnstile With a Proxy: TurnstileTask Explained](https://zerocaptcha.io/guides/solve-cloudflare-turnstile-with-a-proxy.md): When to solve Turnstile through your own proxy, how to pass it in createTask, in.php or REST, which proxy types work, and what a bad proxy costs you. - [Submit a Cloudflare Turnstile Token: Form Fields and Callbacks](https://zerocaptcha.io/guides/submit-cloudflare-turnstile-token.md): Where a solved Turnstile token goes: the cf-turnstile-response field, the widget's callback, or a JSON body. With examples for forms, fetch and browsers. - [Test Cloudflare Turnstile in CI With Testing Sitekeys](https://zerocaptcha.io/guides/test-cloudflare-turnstile-in-ci.md): Test your own Turnstile forms in CI with Cloudflare's testing sitekeys and secret keys: always pass, always fail, forced challenges, and spent tokens. - [The cf_clearance Cookie Explained: User Agent, IP and Lifetime](https://zerocaptcha.io/guides/cf-clearance-cookie-explained.md): What Cloudflare's cf_clearance cookie is, what it is tied to, how long it lasts, and how to reuse it correctly with the same user agent through the same proxy. - [Verify a Webhook's HMAC-SHA256 Signature, With Replay Protection](https://zerocaptcha.io/guides/verify-webhook-hmac-signature.md): Check a ZeroCaptcha callback's HMAC-SHA256 signature in Node, Python or Go: the raw body, a constant-time compare, the timestamp window and secret rotation. - [What Is Cloudflare Turnstile? The CAPTCHA Widget Explained](https://zerocaptcha.io/guides/what-is-cloudflare-turnstile.md): Cloudflare Turnstile explained: the widget, the token it issues, how a site verifies it, and what that means when you automate a page that shows it. ## Blog - [Cloudflare "Just a Moment" and "Checking Your Browser" Pages](https://zerocaptcha.io/blog/cloudflare-just-a-moment-checking-your-browser.md): What Cloudflare's "Just a moment..." and "Checking your browser" pages are, why they appear, what visitors can do, and how automation passes them. - [Cloudflare 5-Second Challenge: What It Is Now and How to Pass It](https://zerocaptcha.io/blog/cloudflare-5-second-challenge.md): The Cloudflare 5-second challenge is the old name for its JavaScript challenge page. What replaced it, how to recognise it, and how to pass it with an API. - [Cloudflare WAF Bypass: What Gets an Automated Client Through](https://zerocaptcha.io/blog/cloudflare-waf-bypass.md): Looking for a Cloudflare WAF bypass? What each WAF action does to a scraper, which ones can be passed, which only the site owner can lift, and the request. - [AI CAPTCHA Solvers and Cloudflare Turnstile: How Solving Works](https://zerocaptcha.io/blog/ai-captcha-solver.md): What an AI CAPTCHA solver really does, why image recognition does not apply to Cloudflare Turnstile, and how automated Turnstile solving works, without hype. - [Captcha Solver Extensions vs a Solving API: When Each Works](https://zerocaptcha.io/blog/captcha-solver-extension-vs-api.md): Browser extensions like Buster and NopeCHA vs a CAPTCHA-solving API: what each solves, why extensions struggle with Cloudflare Turnstile at scale, and costs. - [CAPTCHA Solver MCP Server: ZeroCaptcha in Claude Code and Cursor](https://zerocaptcha.io/blog/captcha-solver-mcp-server.md): Set up the ZeroCaptcha MCP server in Claude Code and Cursor: its four tools, the settings, keeping the key out of your repository, and when to use it. - [Choosing Proxies for Cloudflare Turnstile and Challenge Solving](https://zerocaptcha.io/blog/proxies-for-cloudflare-turnstile.md): When a Cloudflare Turnstile task needs a proxy at all, residential vs datacenter vs mobile, sticky sessions, regions, and the rules a proxy must meet. - [Cloudflare 403 Forbidden When Scraping: Which Cause Is It?](https://zerocaptcha.io/blog/cloudflare-403-forbidden.md): A Cloudflare 403 has five usual causes: a challenge page, a WAF block, a browser-signature ban, an IP or country ban, or the origin. How to tell them apart. - [Cloudflare Bot Management vs Turnstile vs Challenge Pages](https://zerocaptcha.io/blog/cloudflare-bot-management-vs-turnstile.md): What an automated client meets on a Cloudflare site: Bot Management scores, Bot Fight Mode, Turnstile widgets and challenge pages, and what each one needs. - [Cloudflare Challenge Loop: Why 'Just a moment...' Repeats](https://zerocaptcha.io/blog/cloudflare-challenge-loop.md): Why a Cloudflare 'Just a moment...' page keeps coming back: the documented causes, IP changes mid-solve, lost cookies, clocks, and fixes for code. - [Cloudflare Challenges in Electron and Desktop Apps: Fixes](https://zerocaptcha.io/blog/electron-cloudflare-challenge.md): Why an Electron app's requests hit Cloudflare challenge pages, and the fixes: Chromium's network stack, one session, a steady user agent, and cf_clearance. - [Cloudflare Error 1006/1007/1008: Your IP Address Has Been Banned](https://zerocaptcha.io/blog/cloudflare-error-1006-1007-1008.md): Cloudflare errors 1006, 1007, 1008 and 1106 mean the site owner banned your IP address. What the docs say, who can lift it, and why not to rotate IPs. - [Cloudflare Error 1009: Country or Region Banned, Explained](https://zerocaptcha.io/blog/cloudflare-error-1009.md): Cloudflare error 1009 means the site owner banned the country or region of your IP address. Why it happens, who can lift it, and when a proxy region is fine. - [Cloudflare Error 1010: Banned Based on Your Browser's Signature](https://zerocaptcha.io/blog/cloudflare-error-1010.md): Cloudflare error 1010 comes from Browser Integrity Check. What it looks for, what an HTTP client should send, and what only the site owner can change. - [Cloudflare Error 1015 Rate Limited: Causes and Backoff in Code](https://zerocaptcha.io/blog/cloudflare-error-1015.md): Cloudflare error 1015 means a site's rate limiting rule blocked you. How the rules count, the 429 status, and Python backoff that stops the retries. - [Cloudflare Error 1020 Access Denied: What It Means for Automation](https://zerocaptcha.io/blog/cloudflare-error-1020.md): Cloudflare error 1020 means a site owner's firewall rule blocked your request: what the page shows, why no token lifts it, and what to do next. - [Cloudflare Managed vs Non-Interactive vs Interactive Challenge](https://zerocaptcha.io/blog/cloudflare-challenge-types.md): Cloudflare's three challenge types, including the one called JS Challenge: what each does, who issues it, which clearance passes which, and what bots meet. - [Cloudflare Turnstile Ephemeral IDs: What Site Owners See](https://zerocaptcha.io/blog/cloudflare-turnstile-ephemeral-id.md): What a Cloudflare Turnstile ephemeral ID is, who gets it, how it shows in siteverify, how sites use it against fake sign-ups, and what it means for automation. - [Cloudflare Turnstile Error Codes: 110200, 300xxx, 600xxx](https://zerocaptcha.io/blog/cloudflare-turnstile-error-codes.md): What each Cloudflare Turnstile widget error code means, from 110100 to 600xxx: Cloudflare's current table, which errors to retry, and how to fix each one. - [Cloudflare Turnstile in Chrome Extensions and Content Scripts](https://zerocaptcha.io/blog/cloudflare-turnstile-chrome-extension.md): Why a Cloudflare Turnstile widget can't live in a Manifest V3 extension page, what to do instead, and how a content script fills a Turnstile form on a page. - [Cloudflare Turnstile in Headless Browsers: Why It Fails and Fixes](https://zerocaptcha.io/blog/cloudflare-turnstile-headless-browser.md): Why Cloudflare Turnstile fails in headless Chrome, Playwright and Puppeteer, what Cloudflare says about automated browsers, and a fix that uses an API token. - [Cloudflare Turnstile in React, Vue and Next.js Forms](https://zerocaptcha.io/blog/cloudflare-turnstile-react-vue-nextjs.md): How React, Vue, Nuxt and Next.js apps render Cloudflare Turnstile and send its token, how to verify it on the server, and how automation submits these forms. - [Cloudflare Turnstile Pre-Clearance: How It Issues cf_clearance](https://zerocaptcha.io/blog/cloudflare-turnstile-pre-clearance.md): Cloudflare Turnstile pre-clearance issues a cf_clearance cookie with the token, so later requests skip WAF challenge rules up to the level a site sets. - [Cloudflare Turnstile Retry and Refresh-Expired Settings Explained](https://zerocaptcha.io/blog/cloudflare-turnstile-retry-and-refresh.md): What Cloudflare Turnstile's retry, retry-interval, refresh-expired and refresh-timeout settings do, their defaults, and when to change them. - [Cloudflare Turnstile Siteverify Errors: Why a Token Is Rejected](https://zerocaptcha.io/blog/cloudflare-turnstile-siteverify-errors.md): Every Cloudflare Turnstile siteverify error code with Cloudflare's meaning and fix, and why a site rejects a token when you automate a form. - [Cloudflare Turnstile Solve Time Benchmark: How We Measure](https://zerocaptcha.io/blog/cloudflare-turnstile-solve-time-benchmark.md): How we measure Cloudflare Turnstile solve time, success rate and availability from the public status feed, with no invented numbers, and how to benchmark yours. - [Cloudflare Turnstile Token: What It Is and What It Proves](https://zerocaptcha.io/blog/cloudflare-turnstile-token.md): What a Cloudflare Turnstile token is, where the widget puts it, how siteverify checks it, what it proves, and how a solving API produces one. - [Cloudflare Turnstile vs reCAPTCHA vs hCaptcha: Full Comparison](https://zerocaptcha.io/blog/cloudflare-turnstile-vs-recaptcha-vs-hcaptcha.md): Cloudflare Turnstile, Google reCAPTCHA and hCaptcha side by side: how each checks visitors, tokens, siteverify, prices and limits, and what automation meets. - [Cloudflare Under Attack Mode: What It Means for Automated Clients](https://zerocaptcha.io/blog/cloudflare-under-attack-mode.md): Cloudflare's I'm Under Attack mode puts a Managed Challenge in front of every visitor. What it does, how to spot it, and what scrapers and API clients can do. - [Cloudflare Verified Bots: How a Crawler Gets Recognized](https://zerocaptcha.io/blog/cloudflare-verified-bots.md): What Cloudflare's verified bots are, the rules a crawler must meet, the three ways to prove who it is (Web Bot Auth, IP lists, reverse DNS) and how to apply. - [Cloudflare WAF Rules Explained: Challenge, Block, Skip, Log](https://zerocaptcha.io/blog/cloudflare-waf-rules-explained.md): Cloudflare WAF custom rule actions in Cloudflare's words, terminating vs non-terminating, plan limits, rule order, and what each action means for a bot. - [Cloudflare Waiting Room vs a Challenge Page: What Crawlers See](https://zerocaptcha.io/blog/cloudflare-waiting-room.md): A Cloudflare Waiting Room is a queue, not a bot check. How to tell it from a challenge page, how its cookie and JSON mode work, and how to wait your turn. - [Cloudflare's Challenge Platform and cf_chl Parameters Explained](https://zerocaptcha.io/blog/cloudflare-challenge-platform-explained.md): What /cdn-cgi/challenge-platform, window._cf_chl_opt, the cf_chl cookies and the __cf_chl_ URL parameters are, and what an automated client should do. - [Crawlee and Cloudflare Turnstile: A PlaywrightCrawler Tutorial](https://zerocaptcha.io/blog/crawlee-cloudflare-turnstile.md): Handle Cloudflare Turnstile forms in a Crawlee PlaywrightCrawler: read the sitekey, get a token from an API, fill the form, and set timeouts that fit. - [Crawlee for Python and Cloudflare Turnstile: A Crawler Tutorial](https://zerocaptcha.io/blog/crawlee-python-cloudflare-turnstile.md): Handle Cloudflare Turnstile forms in Crawlee for Python's PlaywrightCrawler: read the widget, solve the token, fill and submit, with timeouts that fit. - [Cypress and Cloudflare Turnstile: Test Your Own Forms End to End](https://zerocaptcha.io/blog/cypress-cloudflare-turnstile.md): Why Cypress can't pass a live Cloudflare Turnstile widget, and how to test your forms with Cloudflare's testing sitekeys and secrets, per environment, in CI. - [Go Colly and Cloudflare Turnstile: A Scraper Tutorial](https://zerocaptcha.io/blog/go-colly-cloudflare-turnstile.md): A Go Colly collector that finds a Cloudflare Turnstile sitekey with OnHTML, gets a token from a solving API over net/http, and posts the form. - [got-scraping and Cloudflare Turnstile: A Node.js Form Tutorial](https://zerocaptcha.io/blog/got-scraping-cloudflare-turnstile.md): Post a Cloudflare Turnstile form from Node.js with got-scraping: consistent browser headers, a cookie jar, a token from an API, and what replaces it now. - [Hand Off a CAPTCHA API Integration to an AI Coding Assistant](https://zerocaptcha.io/blog/ai-coding-assistant-captcha-integration.md): A walkthrough: give Claude Code, Cursor, Copilot or Codex ZeroCaptcha's integration brief and rule files, then check its work against the brief's checklist. - [n8n and Cloudflare Turnstile: Solve a Form in a Workflow](https://zerocaptcha.io/blog/n8n-cloudflare-turnstile.md): Build an n8n workflow that reads a Cloudflare Turnstile sitekey, gets a token from a solving API with HTTP Request nodes, waits in a loop, and submits the form. - [nodriver and zendriver With Cloudflare Turnstile: A Tutorial](https://zerocaptcha.io/blog/nodriver-cloudflare-turnstile.md): Handle a Cloudflare Turnstile form in nodriver or zendriver: read the widget, get a token from an API, fill the field, call the callback and submit, all async. - [Playwright and Cloudflare "Just a Moment": Using cf_clearance](https://zerocaptcha.io/blog/playwright-cloudflare-challenge.md): Why Playwright gets stuck on Cloudflare's "Just a moment..." page, how to detect it, and how to load a cf_clearance cookie with its user agent and proxy. - [Please Unblock challenges.cloudflare.com to Proceed: Fixes](https://zerocaptcha.io/blog/please-unblock-challenges-cloudflare-com.md): Why a Cloudflare page says to unblock challenges.cloudflare.com, how to fix it in a browser or network, and what it means for automated clients. - [Puppeteer Stealth and Cloudflare Turnstile: What It Can't Fix](https://zerocaptcha.io/blog/puppeteer-stealth-cloudflare-turnstile.md): What puppeteer-extra-plugin-stealth changes, why Cloudflare Turnstile can still refuse a stealthy browser, and a Puppeteer fallback that gets the token. - [Python httpx and requests: Solve Cloudflare Turnstile at Scale](https://zerocaptcha.io/blog/python-httpx-cloudflare-turnstile.md): Get Cloudflare Turnstile tokens from Python with requests for one form, or httpx and asyncio for hundreds at once, with retries that never pay twice. - [Scrapy and Cloudflare Turnstile: Submit Forms Without a Browser](https://zerocaptcha.io/blog/scrapy-cloudflare-turnstile.md): A Scrapy spider that reads a Cloudflare Turnstile sitekey from the HTML, gets a token from an API without blocking the crawl, and posts the form. - [scrapy-playwright and Cloudflare Turnstile: JS-Rendered Forms](https://zerocaptcha.io/blog/scrapy-playwright-cloudflare-turnstile.md): When the Cloudflare Turnstile widget only exists after JavaScript runs, let scrapy-playwright render the page, then solve the token, fill the form and parse. - [Selenium and Cloudflare Turnstile: undetected-chromedriver vs API](https://zerocaptcha.io/blog/selenium-undetected-chromedriver-cloudflare.md): What undetected-chromedriver and SeleniumBase UC Mode do about Cloudflare Turnstile, where they stop, and a Selenium fallback that gets a token from an API. - [Simple Cloudflare Turnstile on WordPress: Solving and Testing](https://zerocaptcha.io/blog/cloudflare-turnstile-wordpress.md): How WordPress sites add Cloudflare Turnstile with the Simple Cloudflare Turnstile plugin, Contact Form 7, WPForms or Gravity Forms, and how to automate them. - [Switch Captcha Provider in 10 Minutes: 2Captcha and createTask](https://zerocaptcha.io/blog/switch-captcha-provider.md): Move Cloudflare Turnstile solving from 2Captcha or a createTask-style service by changing two settings, then check six details before full traffic. - [The __cf_bm Cookie vs cf_clearance: Cloudflare's Bot Cookies](https://zerocaptcha.io/blog/cf-bm-cookie-explained.md): What Cloudflare's __cf_bm cookie holds, when it is set and when it expires, how it differs from cf_clearance, and how an automated client should handle both. - [TLS Fingerprints, JA3 and JA4: Why Cloudflare Challenges curl](https://zerocaptcha.io/blog/tls-fingerprint-ja4-cloudflare.md): How JA3 and JA4 fingerprint a TLS handshake, what Cloudflare shows Bot Management customers, and why Python with Chrome's user agent still stands out. - [WAF Challenges Across Vendors: AWS, Akamai, Fastly, SafeLine](https://zerocaptcha.io/blog/waf-challenges-across-vendors.md): How Cloudflare, AWS WAF, Akamai Bot Manager, Fastly Next-Gen WAF and SafeLine challenge a request: status codes, headers, cookies and lifetimes, side by side. - [What Is a WAF? And What a Cloudflare WAF Challenge Means](https://zerocaptcha.io/blog/what-is-a-waf.md): A web application firewall filters HTTP traffic by rules. How Cloudflare's WAF is built, and what a scraper sees when one of its rules blocks or challenges it. ## Comparisons - [A 2Captcha alternative for Cloudflare Turnstile](https://zerocaptcha.io/compare/2captcha-alternative): ZeroCaptcha beside 2Captcha for Cloudflare Turnstile: sourced prices, the API formats both take, and what changes when a 2Captcha client moves over. - [A CapSolver alternative for Cloudflare Turnstile](https://zerocaptcha.io/compare/capsolver-alternative): ZeroCaptcha beside CapSolver for Cloudflare Turnstile: sourced prices, AntiTurnstileTaskProxyLess support, and what changes when you switch. - [An Anti-Captcha alternative for Cloudflare Turnstile](https://zerocaptcha.io/compare/anti-captcha-alternative): ZeroCaptcha beside Anti-Captcha for Cloudflare Turnstile: sourced prices, and the same task names and fields, cData included. - [A NopeCHA alternative for Cloudflare Turnstile](https://zerocaptcha.io/compare/nopecha-alternative): ZeroCaptcha beside NopeCHA for Cloudflare Turnstile: its own API vs createTask, proxy rules, credits vs pay per token, with every NopeCHA fact sourced. - [A CapMonster alternative for Cloudflare Turnstile](https://zerocaptcha.io/compare/capmonster-alternative): ZeroCaptcha beside CapMonster Cloud for Cloudflare Turnstile: sourced prices, TurnstileTask on both, challenge pages, and what changes when you switch. - [The best CAPTCHA solver for Cloudflare Turnstile, compared](https://zerocaptcha.io/compare/best-cloudflare-turnstile-solvers): The best CAPTCHA solver for Cloudflare Turnstile? ZeroCaptcha, 2Captcha, CapSolver, Anti-Captcha, NopeCHA and CapMonster Cloud, with sourced prices. ## Demo and CAPTCHA test pages - [Cloudflare Turnstile demo and CAPTCHA test pages](https://zerocaptcha.io/captcha-test): live widgets and challenge pages to test a solver or an integration against - [Cloudflare Turnstile managed widget demo](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-managed): A live Cloudflare Turnstile widget in managed mode: see the checkbox it may show, point a task at it, and check the token with Cloudflare's siteverify. - [Cloudflare Turnstile non-interactive widget demo](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-non-interactive): A live non-interactive Cloudflare Turnstile widget: it shows progress, never asks for a click, and hands its form a token you can check with siteverify. - [Cloudflare Turnstile invisible widget demo](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-invisible): A live invisible Cloudflare Turnstile widget: nothing shows, yet the form gets a token. See how to find it in the page and solve it with a task. - [Cloudflare Turnstile widget with appearance always](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-appearance-always): A Cloudflare Turnstile widget with appearance set to always, the default: visible from page load. Solve it with a task and check the token live. - [Cloudflare Turnstile widget with appearance execute](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-appearance-execute): A Cloudflare Turnstile widget that stays hidden until the form calls turnstile.execute(). See how deferred execution looks, and solve it with a task. - [Cloudflare Turnstile widget with appearance interaction-only](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-interaction-only): A Cloudflare Turnstile widget with appearance interaction-only: hidden unless a visitor must click. See how it looks and solve it with a task. - [Cloudflare Turnstile widget at normal size](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-size-normal): A Cloudflare Turnstile widget at its normal size, 300 by 65 pixels, the default. Point a task at it and check the token with Cloudflare's siteverify. - [Cloudflare Turnstile widget at flexible size](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-size-flexible): A Cloudflare Turnstile widget with size flexible, filling its container from 300 pixels wide. Solve it with a task and check the token with Cloudflare. - [Cloudflare Turnstile widget at compact size](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-size-compact): A compact Cloudflare Turnstile widget, 150 by 140 pixels, for narrow layouts. Point a task at it and check its token with Cloudflare's siteverify. - [Cloudflare Turnstile implicit rendering demo](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-implicit-rendering): Cloudflare Turnstile rendered implicitly: a cf-turnstile div with data-sitekey that api.js finds on its own. See the markup and solve it with a task. - [Cloudflare Turnstile explicit rendering demo](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-explicit-rendering): Cloudflare Turnstile rendered explicitly with turnstile.render(): the sitekey is in the page's script, not its HTML. See where to find it and solve it. - [Cloudflare Turnstile action and cData demo](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-action-cdata): A Cloudflare Turnstile widget that sets an action and cData, and a siteverify check that shows them back. See why a task must send both. - [Several Cloudflare Turnstile widgets on one page](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-multiple-widgets): Two Cloudflare Turnstile widgets on one page, each in its own form with its own action. See how to tell them apart and solve the one you need. - [Cloudflare Turnstile login form demo](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-login-form): A sign-in form protected by Cloudflare Turnstile, as real sites build it. Solve its widget with a task and see the token pass Cloudflare's siteverify. - [Cloudflare Turnstile pre-clearance demo](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-pre-clearance): A Cloudflare Turnstile widget with pre-clearance on: passing it also sets cf_clearance for the zone. Solve it, check the token and see the cookie arrive. - [Cloudflare WAF managed challenge test page](https://zerocaptcha.io/captcha-test/cloudflare-managed-challenge): A page behind a Cloudflare WAF rule with the Managed Challenge action, the "Just a moment..." page. Pass it with a challenge task and see your clearance. - [Cloudflare 5-second JS challenge test page](https://zerocaptcha.io/captcha-test/cloudflare-js-challenge): A page behind a Cloudflare WAF Non-Interactive Challenge (js_challenge), once called the 5-second challenge. Pass it with a challenge task, see your clearance. - [Cloudflare WAF interactive challenge test page](https://zerocaptcha.io/captcha-test/cloudflare-interactive-challenge): A page behind a Cloudflare Interactive Challenge, which always needs an interaction. Pass it with a challenge task and see your clearance checked. - [Cloudflare Turnstile token checker](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-token-checker): a demo widget's token, checked with Cloudflare's siteverify - [Cloudflare Turnstile test sitekeys and secret keys](https://zerocaptcha.io/captcha-test/cloudflare-turnstile-test-sitekeys): Cloudflare's keys that always pass, always fail or force a challenge ## Tools - [Cloudflare Turnstile and CAPTCHA tools](https://zerocaptcha.io/tools): run in the browser only - [Cloudflare Turnstile sitekey finder](https://zerocaptcha.io/tools/cloudflare-turnstile-sitekey-finder): Paste a page's HTML to get its sitekey, action, cData, appearance and rendering. - [cf_clearance and Cloudflare Turnstile token inspector](https://zerocaptcha.io/tools/cf-clearance-token-inspector): Paste a cookie or a token to see its format, its age and its expiry where readable. - [CAPTCHA solving cost calculator](https://zerocaptcha.io/tools/captcha-cost-calculator): Work out a day's and a month's cost at the API's prices, and the top-up it needs. ## Optional - [Pricing](https://zerocaptcha.io/pricing): prices per 1,000 solved tasks, as the API publishes them - [Status](https://zerocaptcha.io/status): the last 24 hours, read live from the API - [Glossary](https://zerocaptcha.io/glossary) - [About](https://zerocaptcha.io/about) - [Acceptable Use Policy](https://zerocaptcha.io/legal/acceptable-use) - [Terms of Service](https://zerocaptcha.io/legal/terms) - [Privacy Policy](https://zerocaptcha.io/legal/privacy) - [Refund Policy](https://zerocaptcha.io/legal/refunds)