October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
bot detection

How Cloudflare Detects Bots: TLS, HTTP/2, Canvas, and Turnstile

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare detects bots with layers, not one fingerprint. Its documented system combines known-pattern heuristics, request and session characteristics, browser-side signals, optional JavaScript Detections, and (on eligible Bot Management plans) machine-learning scoring. TLS fingerprints such as JA3 and JA4 are useful signals, while Turnstile is a separate, embedded challenge that asks a browser to prove it behaves like a real client. Canvas and HTTP/2 can be relevant to browser or request analysis, but Cloudflare’s public documentation does not establish either as a universal, standalone bot verdict.

The short answer: Cloudflare combines several independent signals

Cloudflare’s bot defenses operate at different layers. A request may be compared with known automation patterns, evaluated for unusual headers or session behavior, enriched with browser-side JavaScript results, and scored by a machine-learning model. Operators then decide what to do with that signal: allow, rate-limit, present a challenge, or block.

This distinction matters. Detection describes what Cloudflare thinks about traffic; mitigation is the rule or product action applied afterward. A suspicious field is not automatically proof that a visitor is a bot, and a missing signal is not proof that a visitor is legitimate.

Heuristics for recognizable automation

Heuristics match patterns that repeatedly appear in automated traffic. Cloudflare exposes detection IDs so administrators can see which heuristic matched and use those IDs in analytics or rules. A documented example looks at headers arriving in an order that does not fit the browser identified by the request. Several IDs can match the same request.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Malicious Bots
  • Used Book in Good Condition

Request, session and browser features

For Business and Enterprise Bot Management, Cloudflare says its supervised machine-learning engine combines request features, headers, session characteristics and browser signals. The resulting Bot Score ranges from 1 to 99. Cloudflare also describes the __cf_bm cookie as a measure of request patterns that supplies session context and helps reduce false positives for genuine users.

Enterprise documentation separately describes Anomaly Detection, but Cloudflare’s current notice says it is not onboarding new customers to that option. Availability therefore depends on the product and plan attached to your zone.

How TLS fingerprints (JA3 and JA4) fit in

JA3 and JA4 are fingerprints derived from a client’s TLS handshake, especially the way it sends a ClientHello. Cloudflare uses them to group clients that look alike across destination IPs, ports and certificates. JA4 sorts ClientHello extensions; Cloudflare says this reduces the number of unique fingerprints produced by modern browsers and makes grouping more useful.

What administrators can do with them

On Enterprise accounts that have purchased Bot Management, JA3 and JA4 can be used for analytics and referenced in WAF rules, Transform Rules or Workers. That makes them useful for identifying a recurring automated client or separating one class of traffic from another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why a JA3 or JA4 value may be missing

  • Plain HTTP has no TLS handshake, so there is no TLS fingerprint.
  • Cloudflare may skip Bot Management for a request.
  • Some Worker routing and internal-zone cases do not produce the documented value.
  • TLS session resumption can avoid a new handshake, leaving no new fingerprint to calculate.

Do not convert an absent JA3 or JA4 field into a bot decision. Treat it as “signal unavailable” and combine the remaining evidence.

Headers and HTTP/2: useful context, not a published recipe

Cloudflare explicitly documents request features and header behavior as inputs to detection. Header names, values and ordering can reveal that a client claims to be one browser while behaving like another. Session continuity and the timing or consistency of requests add more context.

Cloudflare’s public material reviewed for this explanation does not publish a complete list of HTTP/2 properties, their weights, or a fixed HTTP/2 fingerprint that applies to every plan. It is accurate to say that HTTP-level request characteristics can contribute to detection; it is not accurate to claim that Cloudflare always checks one specific HTTP/2 field or uses a universal fingerprint recipe. Build rules from observed analytics rather than from an assumed list of protocol quirks.

Browser-side JavaScript and Canvas signals

JavaScript Detections

JavaScript Detections inject a lightweight, invisible script into HTML page responses. The result is exposed as a pass/fail field that can later be referenced by rules. Because the script is injected into an HTML response, it is not a general test on a client’s first non-HTML request. API calls and mobile-app traffic are not affected in the same way.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A failed result has benign explanations: a network failure, an ad blocker, disabled JavaScript, or a native application that does not execute page scripts. Cloudflare recommends using the field on browser endpoints and with Managed Challenge rather than unconditionally blocking every failure.

Where Canvas fits

Canvas and WebGL are browser APIs that can expose differences in rendering environments. Cloudflare’s challenge documentation refers to them when explaining a limitation: Turnstile and challenge flows cannot support extensions that modify the User-Agent or browser APIs such as Canvas and WebGL. That establishes that these APIs matter to browser compatibility and client-side checks.

It does not establish that every Bot Management request collects a Canvas image, nor that Canvas output alone decides whether traffic is a bot. Explain Canvas as one possible browser signal in a layered system, not as a universal Cloudflare fingerprint.

Turnstile is a challenge layer, not passive Bot Scoring

Turnstile is an embeddable Cloudflare challenge that can run even when a site’s traffic is not proxied through Cloudflare. Its widget modes are Managed, Non-interactive and Invisible. Managed mode can show a checkbox when visitor risk warrants it; the other modes reduce or remove visible interaction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Cybersecurity Word Cloud Hacker Computer Coders Programmer Hardcover Journal, Black
  • Cybersecurity.
  • This merchandise, which shows a computer cybersecurity word cloud design, is ideal for computer programmers, coders, and hackers. It is also for software engineer or software developers, as well as information technology or computer science majors.
  • Hardcover journal with 240 line-ruled pages (120 sheets)
  • Built-in elastic closure and ribbon bookmark
  • Includes an expandable inner storage pocket and a pen holder

Turnstile can examine proof-of-work, proof-of-space, Web APIs, browser quirks and human behavior. The application must validate the token on its server before allowing an action such as login, signup or form submission. Never treat a token that has only been rendered in the browser as sufficient authorization.

Turnstile compared with other Cloudflare layers

Layer Primary job Typical interaction Proxying required?
WAF Filter network and application requests with rules Usually none; a rule may block or challenge For Cloudflare’s edge WAF, traffic normally passes through the zone
Bot Fight Mode / Super Bot Fight Mode Baseline mitigation for known or suspicious automation Block, rate-limit or challenge according to configuration Cloudflare zone protection
Bot Management Granular signals and a 1–99 machine-learning Bot Score Usually invisible scoring followed by your rule Cloudflare zone protection and eligible plan
Turnstile Client-side proof that a browser can complete a challenge Managed checkbox, invisible or non-interactive challenge No; it can be embedded on a site outside Cloudflare’s network
JavaScript Detections Background browser signal on HTML responses Invisible script; no pause for the visitor Implemented through Cloudflare’s page-response path

How to investigate a bot decision without over-blocking

  1. Identify the endpoint. Separate browser pages, APIs, mobile clients and webhooks. JavaScript-based evidence is appropriate for an HTML page but may be irrelevant to an API.
  2. Review analytics and logs. Look for Bot Scores (where licensed), detection IDs, request headers, session behavior and whether JA3/JA4 were actually present.
  3. Check the response path. Confirm whether the request reached an HTML response capable of receiving JavaScript Detections, and whether an intermediary or Worker skipped Bot Management.
  4. Preserve expected automation. Verify legitimate crawlers, payment callbacks, monitoring agents and partner integrations before tightening a rule.
  5. Choose the least disruptive action. Start with logging or rate limits, use Managed Challenge where an interactive proof is appropriate, and reserve unconditional blocking for a pattern you can explain.
  6. Validate Turnstile server-side. If a widget protects an action, send its token to your server and perform the documented validation before changing account or transaction state.

Common investigation mistakes and fixes

  • “No JA4 means bot.” Fix: check for HTTP, session resumption, skipped Bot Management or Worker routing before interpreting the absence.
  • “A JavaScript failure proves automation.” Fix: account for disabled scripts, ad blockers, network errors and native clients; combine the result with endpoint and session evidence.
  • “Cloudflare has one HTTP/2 fingerprint.” Fix: use only the request characteristics and detection IDs exposed for your product; Cloudflare does not publish a universal weighting recipe.
  • “Canvas is the decision.” Fix: describe Canvas/WebGL as browser compatibility or client-side signals, not a guaranteed standalone Bot Management feature.
  • “Turnstile replaces server controls.” Fix: validate tokens on the server and keep WAF, rate limits and application authorization in place.
  • “Every challenge failure is malicious.” Fix: provide a recovery path for legitimate users and inspect whether browser extensions or privacy tools altered User-Agent, Canvas, WebGL or other Web APIs.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If you need to inspect how a page appears to a real browser before tuning bot rules, ScreenshotNeo can capture a clean page without maintaining your own headless-browser stack. Before capture it accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server provides take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.

One GET request is enough (see the ScreenshotNeo API documentation):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo also supports full-page and selector captures, dark mode, device presets, custom viewport and retina scale, PDF output, custom CSS and JavaScript, click and wait conditions, blocked resources, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, configurable cache TTLs, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, usage reporting and an OpenAPI specification. Its parameter names are compatible with those used by other screenshot APIs, which simplifies switching.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is available on every plan, and annual billing provides two months free. Create a free ScreenshotNeo account.

Frequently Asked Questions

Can Cloudflare’s Bot Score be treated as a probability percentage?

No. It is a 1–99 product score used as a signal for rules, not a published probability or outcome statistic.

Does Turnstile require a site to move all traffic behind Cloudflare?

No. Turnstile can be embedded and validated on a site that does not proxy its traffic through Cloudflare.

Why might a legitimate user receive a challenge?

Browser extensions, privacy tools, disabled JavaScript, network failures and unusual session behavior can produce signals that require an additional check; review the endpoint and provide a recovery path rather than assuming malicious intent.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
Malicious Bots
Malicious Bots
Used Book in Good Condition
$77.60
Bestseller No. 4
Cybersecurity Word Cloud Hacker Computer Coders Programmer Hardcover Journal, Black
Cybersecurity Word Cloud Hacker Computer Coders Programmer Hardcover Journal, Black
Cybersecurity.; Hardcover journal with 240 line-ruled pages (120 sheets); Built-in elastic closure and ribbon bookmark
$16.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.