Skip to main content

Cloudflare Turnstile: what this CAPTCHA is and how it works

Cloudflare · 09.10.2026 · 3 min read
Illustration for “Cloudflare Turnstile: what this CAPTCHA is and how it works”

Turnstile is Cloudflare's CAPTCHA replacement: the service checks a visitor without pictures, traffic lights, or picking the right tiles in a photo.

How Turnstile differs from a regular CAPTCHA

The difference is not only the lack of pictures but the whole checking principle: a classic CAPTCHA checks a human through a puzzle, Turnstile checks through browser and device behavior signals.

CriterionRegular CAPTCHATurnstile
What the visitor seespictures, a puzzle, or a checkboxusually just a short check with no tasks
What is checkedthe ability to recognize an object in a picturebrowser and device signals, no puzzle
Is a Cloudflare account neededno, it is a third-party serviceyes, the widget is issued in the Cloudflare dashboard
Does it work outside a Cloudflare proxyyes, it does not depend on a proxyyes, it works even without proxying the site through Cloudflare

How it works in general terms

The widget on the page checks the visitor in the browser and issues a token confirming the result of the check. That token goes into the form along with the other fields, and before processing the form the server sends the token off for verification and gets back whether it was confirmed or not.

Where Turnstile is usually placed

  • A sign-in form for an account.
  • A registration form for a new user.
  • A contact form on a site.
  • A comment form under an article.

How to add the widget and verify the token

Setting it up takes two steps: widget markup on the page and token verification on the server.

<div class="cf-turnstile" data-sitekey="your-site-key"></div>

The second step is server-side verification before processing the form: the token value from the hidden form field is sent along with the secret key for verification, and the form is processed only when the result is confirmed.

# take the token from the submitted form
# send the token together with the secret key for verification
# continue processing the form only if verification is confirmed

Common connection mistakes

ProblemLikely causeWhat to do
The widget does not appear on the pagethe site key is wrong or the widget script is not loadedcheck the key and the widget script connection
The token fails server verificationthe secret key is mixed up with the site keycheck which key is used on the server and which in the markup
The widget breaks on mobilethe parent form block is too narrow or clipped by stylescheck the block width and horizontal overflow
The check triggers on your own visitorsa stale or already used token was submitted againrefresh the token on every form resubmission

What Turnstile does not solve

Turnstile checks the visitor filling out a form, but it does not protect against server overload from a flood of requests and does not limit request frequency. For spam protection in general, see the article on protecting a site from spam, and for limiting request frequency and password guessing, see the article on protection against brute-force attacks.

Short conclusion

Turnstile is worth adding where a form is filled out by a real person and it matters to cut off automated submissions without extra steps for the visitor. Where the problem is request volume rather than its source, the widget alone is not enough, and request-rate limiting is needed.

Was this article helpful?
← Back to Knowledge Base Ask Support