Cloudflare Turnstile sitekey finder
Paste a page's HTML and the finder lists every Cloudflare Turnstile widget in it: the sitekey, the action and cData, the appearance, size and execution, whether it is rendered from markup or by turnstile.render(), and the ZeroCaptcha task that would solve it. It works on the text you paste, in your browser, and sends nothing.
What the finder found
Paste a page's HTML and press Find the sitekey.
Where a sitekey hides
With implicit rendering, the sitekey is the data-sitekey attribute of an element with the class cf-turnstile, and data-action and data-cdata sit beside it. With explicit rendering, the page's script passes it to turnstile.render() as sitekey, with action and cData. A sitekey starts with 0x4.
The finder reads both. It cannot run the page's scripts, so a sitekey built at run time, or fetched from an API, will not show: watch the network panel for the widget's iframe from challenges.cloudflare.com instead. Every kind of widget, with its markup, is on the Cloudflare Turnstile demo pages.
Sitekey finder questions
Why can't the finder fetch a page by its URL?
It runs only in your browser, which may not read other sites' pages, and many widgets appear only after scripts run. Open the page, copy its HTML from the developer tools' Elements panel, and paste it here.
Can the finder tell the widget's mode?
No. Managed, non-interactive and invisible are settings in Cloudflare's dashboard, not in the HTML. Only Cloudflare's test sitekeys give their behaviour away, and the finder names them.
What if no sitekey is found?
Copy the HTML again after the widget has loaded, from the Elements panel rather than View Source, or search the page's scripts for turnstile.render. A page titled Just a moment... is a challenge page, which has no sitekey.