INTEGRITY Documentation

How Challenges work

Challenges can be issued in three primary ways depending on which Cloudflare products or features are in use. Each method is designed to balance security with seamless visitor experience.

Product Challenge type(s)
WAF (custom rules, rate limiting rules, IP access rules) Interstitial Challenge Page
Bot Management JavaScript Detections
Bot Fight Mode, Super Bot Fight Mode Interstitial Challenge Page
Turnstile Embedded widget
HTTP DDoS attack protection Any Challenge
Under Attack Mode Managed Challenge

Challenge Pages and Turnstile rely on the same underlying mechanism to issue challenges to your website or application's visitors.

JavaScript Detections is an optional feature within Bot Management. When enabled, Cloudflare injects a JavaScript snippet into HTML responses to gather client-side signals. Unlike Challenge Pages, JavaScript Detections runs on every HTML request without pausing or interrupting the visitor. It populates a pass/fail result (cf.bot_management.js_detection.passed) that you can then act on using a WAF custom rule.

For session-level detection that informs when challenges should be applied, refer to Precursor.


Available challenges

Refer to the following pages for more information on the different challenge types:


Limitations

Cloudflare Challenges cannot support the following: