Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A repeating Cloudflare browser check usually means the challenge cannot finish in your current browser, network, or embedded WebView. It does not, by itself, prove that you are a bot or that your device is infected. Cloudflare lists blocked scripts, disabled JavaScript, unsupported browsers, unstable connections, VPN or proxy interference, and detection errors as possible causes.

Work through the checks in order: update the browser, enable JavaScript, temporarily test without extensions, use a private window, compare another browser or device, then compare another network. If the loop continues, capture a HAR and console log while reproducing it and send the error code and Ray ID to the website operator.

What the Cloudflare browser check is doing

A Cloudflare Challenge Page asks the browser to run checks before the requested site is delivered. A challenge loop occurs when the page keeps returning to the check instead of completing it. Cloudflare says most challenges are quick and typically take only a few seconds, but a loop can occur when required scripts cannot run, the browser is unsupported, the connection is unstable, or Cloudflare’s detection encounters an error.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Strong bot signals can be one reason a challenge is presented, but a repeating challenge is not proof that Cloudflare has definitively classified you as automated. Ordinary browser and network conditions can produce the same symptom.

#1 Best Overall

Fix the loop with a controlled sequence

Change one variable at a time where possible. The result of each comparison helps locate the failing layer; no single test proves the exact cause.

1. Update the browser and check compatibility

Install the latest version of your browser and reload the page. Cloudflare says Turnstile supports major browsers except Internet Explorer and recommends an up-to-date browser. If the site works in a current browser but not an old one, keep the supported browser rather than trying to work around the challenge.

2. Confirm JavaScript is enabled

Challenge code depends on JavaScript. Check the browser’s site settings for the affected domain and allow JavaScript, then reload. If your organization manages browser policies, an administrator may have disabled it and will need to change the policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Temporarily disable extensions

Ad blockers, script blockers and privacy extensions can prevent challenge resources from loading. Open the browser’s extensions page, disable them temporarily, and test the site again. Restore your protections afterward. If the page works only with one extension disabled, review that extension’s per-site settings instead of leaving all protections off.

4. Test a private or incognito window

Open a private window and visit the same URL. This commonly starts with extensions disabled and a separate session, so it distinguishes an extension or stored-session problem from a wider browser or network issue. A successful private-window test does not identify whether the extension or existing site data was responsible; it only narrows the scope.

5. Compare another browser or device

Try a different current browser on the same device. If that fails, try another device on the same network. A working alternate browser points toward the original browser environment. A working alternate device suggests a device-specific setting or software conflict. Neither result alone identifies the precise setting.

6. Temporarily test without a VPN or proxy

Cloudflare notes that some VPNs and proxies may interfere with a challenge. Disconnect the VPN or proxy only long enough to test, then reconnect it if you need it. Treat this as a diagnostic comparison, not a recommendation to abandon a privacy service permanently. If the direct connection works, discuss the result with the VPN or proxy provider or try a different exit location according to its support guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

7. Try another network

Use a mobile hotspot or another network and open the same page. If the alternate network succeeds while the original does not, the condition is likely tied to the original network path, though this test cannot tell you whether the cause is the connection itself, a proxy, filtering, or another component. On a managed network, give the administrator the exact domain and time of the failed test.

8. Reload only after each change

After changing one setting, reload the page and wait for the challenge to complete. Repeatedly opening many tabs or rapidly refreshing can make diagnosis harder because each attempt creates a different session. Record which browser, device and network produced each result.

What a Private Access Token 401 means

During a Challenge Page load, a browser may request a Private Access Token from a path containing /cdn-cgi/challenge-platform/. Cloudflare explains that a device, browser or network unable to issue that token can receive HTTP 401, after which Cloudflare falls back to a standard challenge. Therefore, a 401 on that token request alone is not evidence of a block, a misconfigured site, a false positive or a broken widget. Judge the complete page behavior rather than that one request.

If the problem occurs only inside an app

Native apps often display sites in an embedded WebView rather than a full browser. Cloudflare lists several WebView-specific causes:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • JavaScript is disabled.
  • DOM storage or cookies are unavailable.
  • Access to challenges.cloudflare.com is blocked by the app or network.
  • The User-Agent changes during the session.

Test the same URL in the device’s normal browser. If it works there but loops only in the app, the app operator needs to correct its embedded-browser configuration. A visitor generally cannot repair those settings from the challenge page itself.

Collect evidence before contacting the website

Cloudflare’s troubleshooting guidance recommends preserving browser diagnostics while reproducing the loop. Send the evidence to the website administrator, not to an unknown third party.

Capture a HAR file

  1. Open developer tools in the browser and select the Network panel.
  2. Enable Preserve log before loading the affected URL.
  3. If available, enable Disable cache while developer tools are open.
  4. Clear the panel, reproduce the challenge loop once, and stop recording.
  5. Export the network log as a HAR file.

A HAR records browser requests, response headers and bodies, and page-load timing. Cloudflare warns that it can also contain sensitive information such as passwords and payment details. Open the file as text, remove credentials, tokens, session cookies, personal form data and unrelated URLs, then verify that the redacted file still shows the failing requests.

Save a console log

  1. Keep developer tools open and select Console.
  2. Clear existing messages, reproduce the loop, and copy the resulting errors and warnings.
  3. Include the browser name and version, operating system, affected URL, time of the attempt and whether JavaScript and extensions were enabled.

Include the error code and Ray ID

If the challenge page displays an error code or Ray ID, copy it exactly. Tell the site administrator which comparisons succeeded: private versus normal window, alternate browser or device, and alternate network. This lets the operator investigate the request in context. The site owner controls Cloudflare’s challenge policy; a visitor cannot change that policy from the page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common symptoms and the most useful next test

Symptom Next comparison What the result suggests
Loop in one browser only Private window, then another current browser Browser settings, extensions or stored session data are more likely than a site-wide outage.
Loop on every browser on one device Another device on the same network A device policy, security program or local configuration may be involved if the other device works.
Loop on several devices on one network Mobile hotspot or another network The original network path, filtering or proxy may be involved if the alternate network works.
Works in the normal browser but not an app Ask the app operator to inspect WebView settings JavaScript, cookies, DOM storage, challenge-domain access or User-Agent handling may be wrong.
Only a Private Access Token request shows 401 Inspect whether the standard challenge completes The 401 can be an expected fallback and is not, by itself, a block.

Things not established as fixes

Do not assume that clearing every cookie, changing DNS, restarting a router or buying new hardware will solve the loop. Those actions are not established by Cloudflare’s challenge-loop guidance. They may change your test conditions, but they do not explain why the challenge failed and can erase useful diagnostic state.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is to capture a page for documentation, monitoring or an authorized workflow rather than interact with it manually, ScreenshotNeo provides a single-call screenshot API and an MCP server for AI agents. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing status in headers. It does not turn a protected site into an authorized one, so use it only for pages you are allowed to capture.

Use the parameter names and options documented at ScreenshotNeo’s API documentation. A basic request is:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

The same request in Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

And in Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo also supports full-page captures with lazy images loaded, CSS-selector element capture, custom CSS and JavaScript, click-before-capture actions, waits, resource blocking, headers and cookies, device presets, retina scale, PDF output, signed links, asynchronous jobs and bulk capture. Its MCP tools—take_screenshot, get_page_info and capture_pdf—let Claude, Cursor or another MCP client request captures without your own browser automation. The free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When to stop troubleshooting yourself

Escalate when the loop persists after current-browser, private-window, extension, alternate-device and alternate-network tests, or whenever it affects an embedded app that you do not control. Provide a sanitized HAR, console log, exact error code, Ray ID, browser and operating-system versions, and the successful and unsuccessful comparison results. That is the information the website operator can use to inspect its Cloudflare configuration and request logs.

Frequently Asked Questions

How long should a normal Cloudflare challenge take?

Cloudflare says most challenges typically take only a few seconds. That is a qualitative expectation, not a guaranteed maximum or a published average.

Does a challenge loop mean my computer has malware?

No. Cloudflare lists browser settings, blocked scripts, unstable connections, unsupported browsers and detection errors among possible causes. The loop alone cannot diagnose malware.

Should I permanently turn off my ad blocker or VPN?

No. Disable an extension or VPN only as a temporary comparison. Restore it afterward and investigate a per-site exception or provider setting if that test identifies the component involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I fix a loop on a website I do not own?

You can test your browser, device and network and provide diagnostics, but only the website operator can change the site’s Cloudflare challenge configuration.

What should I remove from a HAR before sharing it?

Remove passwords, payment details, authorization headers, session cookies, access tokens, personal form data and unrelated browsing history. HAR files can contain request and response bodies as well as headers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.