Cloudflare detects bots using a combination of request and session characteristics, browser-side signals, known-pattern heuristics, and—on eligible plans—machine-learning scores. TLS fingerprints such as JA3 and JA4 can contribute to bot analysis, but they are only signals, not proof. Cloudflare’s public documentation does not specify a complete HTTP/2 fingerprint recipe or establish Canvas output as a universal, decisive Bot Management signal. Turnstile is a separate, embedded challenge layer that can be used even when a site’s traffic does not pass through Cloudflare.
Cloudflare bot detection is a set of layers, not one fingerprint
Cloudflare documents several detection engines because automated traffic can look different from one request to the next. Some methods match known patterns; others use session context or information collected by a browser. On Business and Enterprise plans with Bot Management, a supervised machine-learning engine combines request features—including headers, session characteristics, and browser signals—and produces a Bot Score from 1 to 99. The public description does not disclose the model’s full feature list or the weight assigned to each feature.
| Layer | What it does | Important qualification |
|---|---|---|
| Heuristics | Match request patterns associated with known automated behavior. | A request may match more than one heuristic; a match is a signal to assess, not necessarily a complete verdict. |
| JavaScript Detections | Run a lightweight script in HTML page responses and expose a pass/fail result for later use in rules. | They require an HTML response where Cloudflare can inject the script; they do not test every first request. |
| Bot Management machine learning | Combines request, session, and browser features to return a Bot Score. | The documented score is available to Business and Enterprise customers with Bot Management. |
| Anomaly Detection | Separately described as an Enterprise option for identifying unusual patterns. | Cloudflare says it is not onboarding new customers to this feature. |
| Turnstile | Adds a client-side challenge that a site embeds and validates. | It is a challenge product, distinct from passive request scoring. |
Cloudflare also describes the __cf_bm cookie as measuring a user’s request pattern and providing context to scoring, with the aim of reducing false positives for genuine sessions. That is one reason a single request field should not be treated as the entire decision: session behavior can add context that an isolated request does not show.
Detection and mitigation are different stages. A score or heuristic identifies a characteristic; a WAF rule, Bot Fight Mode, Super Bot Fight Mode, challenge, or block is an action configured in response. Choose the action for the endpoint and observed traffic pattern, and account for legitimate crawlers and integrations before tightening a rule. Cloudflare’s Bot Management variables documentation, updated September 16, 2026, and its bot detection engines documentation, updated May 5, 2026, describe these distinctions.
#1 Best Overall
What JA3 and JA4 reveal—and what they do not
JA3 and JA4 are fingerprints derived from the client’s TLS connection handshake. Cloudflare describes them as a way to profile similar TLS clients across destination IP addresses, ports, and certificates. JA4 sorts ClientHello extensions; Cloudflare says this reduces the number of unique fingerprints for modern browsers and makes it easier to group similar clients. These values can support analytics and can be used in WAF rules, Transform Rules, or Workers.
Availability is limited: Cloudflare documents these fields for Enterprise customers who have purchased Bot Management. Even for an eligible account, a value may be absent. JA3/JA4 are calculated during a TLS handshake, so ordinary unencrypted HTTP has no such value. Cloudflare also lists skipped Bot Management, some Worker-routing or internal-zone cases, and TLS session resumption as situations where a fingerprint may be missing. With session resumption, a new handshake may not occur.
Therefore, a missing JA3 or JA4 value is not a positive bot verdict. It may simply mean the conditions needed to calculate a fingerprint were not present. A value is also not an identity: it describes a TLS client profile and is best treated alongside other request and session evidence.
Headers, HTTP/2, and heuristic detection
Cloudflare says its machine-learning model uses request features such as headers, session characteristics, and browser signals. Its detection-ID documentation gives an example heuristic that notices headers arriving in an order different from what the claimed browser would normally use. A request can match multiple detection IDs, and operators can inspect those IDs in analytics or logs and use them in rules.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →That example should not be mistaken for a published universal header-order test. More importantly, Cloudflare’s public documentation does not specify exactly which HTTP/2 properties it evaluates, how they are weighted, or whether a particular HTTP/2 fingerprint is used in every product tier. It is reasonable to say request features can inform detection; it is not supported to present a fixed HTTP/2 fingerprint recipe as Cloudflare’s rule.
When investigating a suspected mismatch, look at the full request and the relevant detection signals rather than inferring a verdict from the HTTP version alone. A browser, an integration, and an automated client may differ across headers, session history, and browser behavior; the reviewed public documentation does not provide a universal threshold for any one of those differences.
JavaScript signals and the limits of Canvas claims
JavaScript Detections work by injecting code into HTML page responses. Cloudflare exposes a pass/fail field that site operators can use in rules, but the script must first have an HTML response in which to run. It is not a general test of every request before a visitor has loaded a page.
Cloudflare says API and mobile-app traffic is unaffected by JavaScript Detections. A failure to pass can also result from network failures, ad blockers, disabled JavaScript, or native-app traffic. For that reason, Cloudflare’s guidance is to use this field on browser endpoints and alongside Managed Challenge—not to make a failed result alone an unconditional reason to block. The JavaScript Detections documentation was updated August 26, 2026.
Canvas and WebGL need careful wording. Cloudflare’s Turnstile challenge documentation discusses them in the context of compatibility: challenges cannot support browser extensions that modify the User-Agent or Web APIs such as Canvas and WebGL. This establishes that these APIs can matter to challenge behavior. It does not establish that Cloudflare universally collects Canvas output, uses it as a standalone Bot Management fingerprint, or makes a bot decision from it by itself.
Turnstile is an embedded challenge, not a Bot Score
Turnstile is a widget that a site embeds in a page and validates on its server. Cloudflare says it can be used without routing the site’s traffic through Cloudflare. The widget offers three documented modes: Managed, which may show a checkbox depending on visitor risk; Non-interactive; and Invisible.
| Mechanism | Where it acts | What the visitor experiences |
|---|---|---|
| Bot Management | Analyzes requests and can expose scores and signals for rules. | May inform mitigation; the score itself is not an embedded challenge. |
| JavaScript Detections | Runs in the background on eligible HTML responses. | Does not pause the visitor for an interaction. |
| Turnstile | Runs as a site-embedded client-side challenge, with server-side token validation. | Depending on widget mode and visitor risk, it may be invisible, non-interactive, or show a checkbox. |
Turnstile’s token must be validated server-side before the application proceeds with a sensitive action such as login. A browser-side widget alone is not a substitute for that application-side validation. Cloudflare describes Turnstile alongside WAF and Bot Management: WAF filters network and application traffic, Bot Management analyzes requests, and Turnstile adds a client-side challenge layer.
Cloudflare says Turnstile and Challenge Pages use the same underlying challenge mechanism, while JavaScript Detections run in the background on HTML responses. Its integration guide frames server-side controls and a client-side challenge as complementary layers, not interchangeable products. That distinction helps with deployment decisions: use passive signals to observe or target traffic, and use an embedded challenge when the application needs a visitor-side check.
Recommended Free Tools
Rank #4
- Cybersecurity.
- This merchandise, which shows a computer cybersecurity word cloud design, is ideal for computer programmers, coders, and hackers. It is also for software engineer or software developers, as well as information technology or computer science majors.
- Hardcover journal with 240 line-ruled pages (120 sheets)
- Built-in elastic closure and ribbon bookmark
- Includes an expandable inner storage pocket and a pen holder
How to respond to a bot signal without blocking legitimate traffic
- Identify the signal and its scope. Establish whether the evidence is a heuristic detection ID, a JavaScript Detection result, a Bot Score, a TLS fingerprint, or a Turnstile outcome. Do not treat missing data as a failed check.
- Check the endpoint and request context. A browser-page signal may not be appropriate for an API, mobile app, or integration. Confirm whether the request had a chance to run a browser script or establish a new TLS handshake.
- Review patterns before acting. Use analytics or logs to inspect the relevant detections and the requests they match. Consider expected crawlers, application integrations, and normal session behavior.
- Choose a proportionate mitigation. Use a challenge where additional visitor verification is suitable; reserve blocking for traffic whose behavior and impact justify it. Apply rules to the relevant endpoint or category instead of assuming one suspicious-looking field proves abuse.
- Validate the application path. If using Turnstile, verify the token server-side before allowing the protected action. Test the expected browser and API flows so challenge handling does not unintentionally interrupt legitimate use.
Limits of what Cloudflare publicly documents
- The reviewed documentation does not publish Bot Management’s complete machine-learning feature list or model weights.
- It does not establish a fixed HTTP/2 fingerprint recipe, its weighting, or universal use across Cloudflare products and plans.
- It does not establish Canvas output as a universal, independently decisive Bot Management fingerprint.
- JA3/JA4 availability depends on plan and Bot Management eligibility, and the values can be absent for documented connection and routing reasons.
- Detection signals should not be confused with enforcement: the operator’s configured rules and mitigation determine what happens to a request.
These limits matter because descriptions of bot detection can overstate what a named fingerprint proves. Cloudflare’s own public descriptions support a layered model and several concrete signals, but not a complete reverse-engineered account of every feature or decision boundary.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Using ScreenshotNeo to capture a page during investigation
ScreenshotNeo is a website screenshot API and MCP server for developers, not a Cloudflare bot-detection or mitigation product. If you need a rendered visual record of a page as part of an investigation, it is a separate capture tool to try first; it does not replace Cloudflare analytics, logs, WAF rules, or Turnstile validation. The API accepts a URL and returns a screenshot or PDF. Its options include full-page and selector captures, wait conditions, custom headers and cookies, and device or viewport settings.
For a basic capture, use the cURL request below. See the ScreenshotNeo API documentation for request options and response details.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo accepts and removes cookie or consent banners, newsletter popups, and chat widgets before capture; each of those steps can be turned off. Its response identifies page verdict and billing status: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed. It also offers an MCP server with take_screenshot, get_page_info, and capture_pdf tools for AI agents and MCP clients.
Free tools Windows power users keep installed
One-click scans. No signup required.
The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots. Every feature is available on every plan. Sign up for ScreenshotNeo’s free plan to try 1,000 screenshots a month without a card.
Best Value
Frequently Asked Questions
Can Turnstile be used on a site that is not proxied by Cloudflare?
Yes. Cloudflare documents Turnstile as usable without routing a site’s traffic through its network.
Does a Bot Score tell an application what action to take?
No. It is a signal; enforcement depends on the rules and mitigation the site operator configures.
Does missing JA3 or JA4 mean a request is automated?
No. Cloudflare documents several reasons the fingerprint may be unavailable, including cases where no new TLS handshake occurs.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

