Skip to content

cf_clearance and Cloudflare Turnstile token inspector

Paste a cf_clearance cookie, a whole Set-Cookie line, or a Cloudflare Turnstile token, and the inspector says which it is, checks its format, and shows its age and expiry where they can be read. It runs in your browser and sends nothing. To know whether Cloudflare would still accept a token, use the Cloudflare Turnstile token checker.

Inspect a value

Cloudflare's default is 30; only the site's owner knows its own.

What it is

Paste a value and press Inspect.

    What can be read, and how sure it is

    A Set-Cookie line's Expires or Max-Age is exact: it is when the browser drops the cookie. Cloudflare checks its own limit too, the zone's Challenge Passage, so a clearance can end before its cookie does.

    cf_clearance values commonly carry a 10-digit Unix time between hyphens. The inspector reads it as the likely issue time, and adds the Challenge Passage to estimate the expiry. That format is an observation, not something Cloudflare documents, so the result says likely.

    A Cloudflare Turnstile token is opaque: it carries no time anyone but Cloudflare can read. It is accepted once, within 300 seconds of the solve, and is at most 2,048 characters. Cloudflare's test sitekeys all give the dummy token XXXX.DUMMY.TOKEN.XXXX.

    Token inspector questions

    How long does a cf_clearance cookie last?

    As long as the site's Challenge Passage setting, 30 minutes by default; Cloudflare recommends 15 to 45 minutes. A Set-Cookie line's Expires or Max-Age says when the browser drops it.

    Can a Cloudflare Turnstile token's age be read?

    No. A token is opaque. Cloudflare accepts it once, within 300 seconds of the solve, and only siteverify can say whether it still would.

    Is it safe to paste a cookie here?

    The inspector runs in your browser and sends nothing anywhere. Still, a cf_clearance cookie lets its holder past the site's challenges for a while, so treat it as you would a session.