Cloudflare Turnstile glossary
The Turnstile and Cloudflare-challenge terms that come up when you are integrating or debugging, defined precisely and without hedging.
Cloudflare uses four words for four different things
Most of the confusion in this vocabulary comes from one place: Cloudflare ships several products that all end in a visitor proving they are not a bot, and their names are used interchangeably everywhere except in Cloudflare's own documentation. Getting the wrong one sends you to the wrong dashboard page and the wrong fix.
| Term | What it actually is | Where it is configured |
|---|---|---|
| Turnstile | A widget you embed in your own page, on your own sitekey, that hands you a token to validate | The Turnstile tab — one widget per sitekey |
| Turnstile WAF / challenge page | A full-page interstitial Cloudflare serves before your origin. Provider-specific challenge parameters; clearing it can issue a cookie | WAF rules on the zone |
| Managed Challenge | The *action* a WAF rule takes. What the visitor sees is chosen by Cloudflare per request | The action field on a rule |
| Bot Fight Mode | A zone-wide toggle that challenges traffic Cloudflare scores as automated | Security settings, one switch |
The practical test is whether there is a data-sitekey in the page source. If there is, you are looking at Turnstile and the sitekey is yours to read. If the whole page is Cloudflare's, with a /cdn-cgi/challenge-platform/ script and no widget of your own, check the response for cf-mitigated: challenge. That identifies a challenge page; its integration differs from the site owner's widget — Turnstile vs Cloudflare challenge works through the difference, and our checker will tell you which one a URL serves.
Which term you probably want
Sorted by what people are actually holding when they start searching:
- You have a long opaque string from a form and need to know how long it lasts and how many times you can use it — token lifetime.
- You have a cookie named
cf_clearanceand want to know what sets it and what invalidates it — cf_clearance. - You solved a challenge and want the next request to skip one — pre-clearance.
- You are looking at a widget and want to know which mode it is in — widget modes. The short answer is that the mode is not in the markup.
- You need a key that behaves the same way every run in CI — test keys.
- You are deciding which product a page is using at all — Turnstile vs reCAPTCHA or Turnstile vs Cloudflare challenge.
Where these definitions come from
Every page here cites Cloudflare's own documentation, and each one records the revision it was checked against. That is not ceremony. Cloudflare's error-code table alone gained nine codes and lost twenty between late 2025 and March 2026, which means a large share of the third-party pages on these terms carry definitions that were briefly true and are now wrong — the full account is on the error index.
That history is written up in full on the blog, which is where arguments about a moving target live so the reference pages can stay reference pages.
Where Cloudflare's documentation does not answer something, these pages say so rather than filling the gap. The widget mode is the clearest example: it is stored against the sitekey inside the account that owns it, so no amount of reading a page will reveal it, and a definition claiming otherwise is worth less than an admission.
Common questions
No. Turnstile is a widget you embed on your own site with your own sitekey, and it gives you a token to validate. A challenge page is a full-page interstitial Cloudflare serves in front of your origin, issued by a WAF rule; it may contain challenge parameters of its own and clearing it can issue a clearance cookie. SolveGate handles this with gate=waf and currently requires a non-empty sitekey=waf placeholder. They are configured in different places and need different integration steps.
No. The mode — managed, non-interactive or invisible — is stored on the widget in the Cloudflare account that owns the sitekey. The page carries only the key. You can infer it by observing: a container that renders at zero height and never appears is invisible, and a checkbox appearing at any point means managed.
Because Cloudflare's own documentation has changed materially. Between roughly December 2025 and March 2026 the error-code table shipped codes that did not exist and definitions that contradicted the widget's behaviour, then reverted most of it. A definition without a date cannot be checked against the revision it was taken from.
Related
Sources
Automating a gate you own or are authorised to test?
// SolveGate clears Cloudflare Turnstile and WAF challenges through one REST call · first 1,000 solves free