Supported gates
// choose the gate and apply its result
Pass one of these as the gate parameter. Both return the same solve object; only the token shape differs (the WAF token carries the clearance payload).
| gate | Modes | Notes |
|---|---|---|
| turnstile | managed · non-interactive · invisible | Cloudflare Turnstile in all three render modes. Provider avg —, — success. |
| waf | Cloudflare challenge pages | Cloudflare interstitial challenge pages. Provider avg —, bounded retries for transient failures. |
Turnstile tokens and WAF clearance differ. Turnstile tokens are single-use and expire 300 seconds after generation. A WAF result carries cookies and headers; clearance can be reused only while valid for the same visitor and session.
Identify the response first. A response carrying cf-mitigated: challenge is a Cloudflare challenge page: use waf. A Turnstile widget embedded in the target's own page normally exposes a data-sitekey or a turnstile.render() configuration: use turnstile. A challenge page can also contain Turnstile scripts, so script presence alone does not select the gate. The checker can inspect a URL, and Turnstile vs Cloudflare challenge explains the distinction.
Both gates require gate, sitekey and url. For turnstile, supply the actual widget sitekey and page URL, plus the matching action and cdata when set by the widget. Use the lowercase field name cdata; chlPageData is not supported. For waf, send sitekey: "waf" as a placeholder; the provider uses url and proxy.
Decode a live WAF result. After checking status === "solved" and meter !== "sandbox", parse the token string with JSON.parse(solve.token) in Node or json.loads(solve.token) in Python. The object contains cookies, set_cookies, headers, attributes and cf_rt; a provider may also return profileId and emulation metadata. Apply the returned cookies and headers to the target session; do not put the JSON string into cf-turnstile-response or use it as the cookie value. The current SDKs leave this decoding to your application.
Clearance is tied to the visitor and device that earned it. Reuse the same proxy session and exit IP with the returned clearance cookie and user agent, using a browser-compatible TLS client appropriate to the selected profile. Matching headers alone does not reproduce a browser's TLS fingerprint. Verify that the replay reaches the intended page: issuance does not guarantee target acceptance. See Cloudflare's clearance documentation and Turnstile validation rules.
// reported averages cover successful retained solve records, including sandbox responses, and measure the final provider attempt. Success rates use solved and failed records. Cached snapshots refresh periodically; queue time, retries and network time can make your request take longer.
What we do not solve. reCAPTCHA, hCaptcha and Arkose FunCAPTCHA are different products from different vendors, and this API clears neither them nor anything else outside the two gates above. A page can carry Turnstile alongside one of them; only the Turnstile half is in scope. We would rather say so here than have you discover it from a 422.
Ready to pour through the gate?
// free sandbox keys · no card required to start