Cloudflare Turnstile is an embeddable alternative to traditional CAPTCHA. Announced in open beta on September 28, 2022, and generally available since September 29, 2023, it uses adaptive browser checks to decide whether a visitor is likely legitimate, usually without puzzles or image grids. A site can use Turnstile even when its traffic does not run through Cloudflare.
What is Cloudflare Turnstile?
Turnstile is Cloudflare’s hosted bot-detection widget. A website places the widget in its page, Turnstile evaluates signals from the visitor’s browser and session, and the widget returns a short-lived token. The site’s server must then send that token to Cloudflare for verification before accepting a login, signup, comment or other protected action.
Turnstile is therefore not merely a visual replacement for reCAPTCHA. It is a client-and-server integration, and the server-side verification step is what makes the result trustworthy.
Is Turnstile a CAPTCHA?
Cloudflare positions Turnstile as a CAPTCHA alternative rather than a conventional CAPTCHA. It can perform proof-of-work, proof-of-space and browser/API probing in the background. Depending on the risk assessment, visitors may see no interaction, a small checkbox or another adaptive check.
Recommended Free Tools
#1 Best Overall
Cloudflare’s current widget modes are:
| Mode | Visitor experience | When it fits |
|---|---|---|
| Managed | Turnstile chooses whether to show an interaction, such as a checkbox. | Most sites that want adaptive protection with a visible fallback when needed. |
| Non-Interactive | Runs its checks without requiring the visitor to click. | Forms and flows where a visible control is undesirable but a widget can remain on the page. |
| Invisible | Hides the widget from the page and runs in the background. | Highly streamlined interfaces; the site must account for an additional privacy-policy requirement described below. |
How does Cloudflare Turnstile work?
- Render the widget. Add the Turnstile client widget to the protected page and configure it with the site key.
- Receive a token. After the browser checks complete, the widget supplies a response token to the page.
- Send the token to your server. Do not treat a browser callback as proof by itself. Pass the token to your backend over your normal form or API request.
- Call Siteverify. Your backend sends a POST request containing the secret key and response token to
https://challenges.cloudflare.com/turnstile/v0/siteverify. - Accept only a successful response. Check the verification result and, where appropriate, confirm that the hostname and action match what your application expects before completing the operation.
Cloudflare says a token can be up to 2,048 characters, remains valid for 300 seconds (five minutes), and can be redeemed only once. A token that is expired, reused or never checked with Siteverify must be rejected. Keep the secret key exclusively on the server; placing it in client-side JavaScript defeats the security model.
Does Turnstile use cookies?
Cloudflare describes Turnstile as minimizing data collection, but that does not mean it performs no processing. Its September 28, 2022 announcement says: “Turnstile never looks for cookies (like a login cookie), or uses cookies to collect or store information of any kind.” The same announcement says the service examines session data such as request headers, the user agent and browser characteristics to perform its security checks.
Cloudflare’s current overview says Turnstile processes data strictly necessary to provide the security service and does not access, store or transmit communications, form entries or other page inputs. It also describes Private Access Tokens as a way for Apple to validate certain device properties without Cloudflare itself collecting those properties.
Rank #2
- Comes with secure packaging
- It can be a gift item
- Easy to read text
These are Cloudflare’s product statements, not the conclusion of an independent privacy audit. Sites should describe Turnstile accurately in their own privacy documentation and consider their legal obligations in the regions where they operate.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Invisible mode and privacy notices
Cloudflare’s widget documentation says a site that enables Invisible mode must reference the Turnstile Privacy Addendum in its own privacy policy. The documentation does not state that this exact requirement applies identically to every widget mode, so operators should check the terms for the mode they deploy.
Is Cloudflare Turnstile free?
Cloudflare’s plans page, last updated August 14, 2026, lists a Free plan and an Enterprise plan. The free option allows unlimited challenges, but account and configuration limits still apply.
Rank #3
| Plan | Price | Widgets | Hostnames per widget | Analytics lookback | Notable details |
|---|---|---|---|---|---|
| Free | Free | Up to 20 per account | Up to 10 | Up to 7 days | WCAG 2.2 AAA compliance |
| Enterprise | Contact sales | Unlimited | Up to 200 | Up to 30 days | Ephemeral IDs and removal of Cloudflare branding |
Cloudflare announced unlimited free use when Turnstile reached general availability in 2023; the current limits above are the more useful reference for planning an account. Enterprise is intended for organizations needing higher widget or hostname limits, longer analytics history or enterprise-only features.
What Turnstile does—and does not—prove
A successful verification means Cloudflare accepted the submitted token under the conditions checked by Siteverify. It is not a guarantee that a human completed the action, nor is it a substitute for rate limits, account security, abuse monitoring or authorization checks.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Cloudflare reported about three billion Turnstile verifications on a typical weekday in a September 25, 2026 announcement. That is a vendor-reported usage figure, not independent evidence of detection accuracy. Similarly, Cloudflare’s earlier claim of a 91% reduction in the CAPTCHAs it chose to serve described its own challenge system in 2022; it should not be read as Turnstile’s independent success rate.
The available product material does not establish comparative accuracy or privacy superiority over Google reCAPTCHA or other providers. Choosing between services requires your own review of user experience, data practices, regional requirements, integration effort and operational limits.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Deployment checklist for site owners
- Create a Turnstile widget and restrict its allowed hostnames.
- Choose Managed, Non-Interactive or Invisible mode based on the interaction and policy requirements of your flow.
- Put the site key in the page and keep the secret key in server-side configuration.
- Require a fresh Siteverify response before creating an account, changing credentials, posting content or completing another sensitive action.
- Reject missing, invalid, expired, duplicated or hostname-mismatched tokens.
- Log verification failures in a way that supports troubleshooting without storing unnecessary form or session data.
- Review Cloudflare’s terms and privacy addendum, and update your privacy notice when Invisible mode is enabled.
- Combine Turnstile with rate limiting, email verification, authentication controls and application-level abuse detection.
Common implementation failures
Checking only in the browser
An attacker can bypass a client-side widget and submit a forged string. Only a successful server call to Siteverify should authorize the protected operation.
Reusing a token
Because tokens are single-use and expire after five minutes, retries should obtain a new token rather than replaying an old one.
Best Value
Exposing the secret key
The site key belongs in browser code; the secret key belongs in a protected server environment. If the secret leaks, rotate it through Cloudflare and redeploy the backend configuration.
Ignoring hostname or action checks
When your integration supplies expected hostname or action values, validate them in the Siteverify response. This helps prevent a valid token from being accepted in the wrong context.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




