Technical
Turnstile
Turnstile is Cloudflare's CAPTCHA alternative: a widget that runs browser checks in the background and issues a token, asking for a click only when it cannot decide. Your server decides what to do with the token.
How it is measured
The page embeds the widget script and a `cf-turnstile` element with a sitekey. On success it adds a `cf-turnstile-response` token to the form. Your server POSTs the token and secret to the `siteverify` endpoint and reads `success`. Tokens are single-use and expire after about five minutes.
Measure the pass rate, the share of visitors shown an interactive challenge, and failures by country and browser in the dashboard.
Worked example
A signup form on an Astro site sees 190 fake registrations a day. After Turnstile goes in with managed mode, fake signups fall to 9, and 97% of real visitors pass without seeing a challenge. The old image CAPTCHA had been costing 22% of mobile completions.
A form that checks the token only in JavaScript still gets hit. A curl script posts 140 times with no token and every request succeeds until the server-side verification is added.
How it differs
Turnstile tries to prove a browser is real without a puzzle in most cases. A CAPTCHA asks for visible work every time. Turnstile offers no guaranteed puzzle, and a classic CAPTCHA offers no silent pass.
Common errors
Skipping `siteverify`. Reusing tokens. Hard-coding the secret in the front end. Not handling token expiry on long forms. Blocking the challenge domain in a CSP. Putting it on every page instead of the abused action.
In practice
Add it to the one form being abused, verify the token on the server, and watch the pass rate. Update your CSP to allow the challenge domain before you ship.