TechnicalCollectible prompt
Cloudflare Turnstile CAPTCHA verified on the server
Act as a senior web security engineer. Add Cloudflare Turnstile to {{page_or_feature}} in my {{tech_stack}} project. Before changing anything, read the existing forms and server handlers and tell me what you found.
Client:
- Load the Turnstile script only on pages with a protected form, and reserve the widget's space so nothing shifts
- Managed mode by default: most people never see a challenge. Use invisible mode only where a visible widget would hurt a key flow
- Send the token with the form. Keep submit disabled until a token exists, refresh the widget when the token expires, and show a plain retry message on errors
- Match the widget's theme and language to the page
Server, the part AI builders skip:
- Verify every token with Cloudflare's siteverify endpoint before doing any work. The widget alone stops nothing; a bot can post straight to the API
- Check success, the expected hostname and the action name. Tokens last 5 minutes and work once, so reject reused ones
- The secret key stays in a server environment variable; only the site key reaches the browser
- If Cloudflare can't be reached: fail closed for sign-up, fail open with stricter rate limits for contact forms, and log it
- Return one generic error, never the reason a check failed
Also:
- Allow challenges.cloudflare.com for scripts and frames in the Content Security Policy
- Use Cloudflare's published test keys in development and tests
- Accessibility: the widget works by keyboard and screen reader, and the page offers another way to reach us if it fails
- Keep the honeypot and rate limits. Turnstile is one layer, not the only one
- Alternatives: hCaptcha works the same way; reCAPTCHA v3 returns a score you must threshold on the server. Tell me if either fits better
Finish with the files changed, how to test a passing, failing and expired token, and anything you assumed.
0 saves · 1 viewnvoka.com/library/nvoka-cloudflare-turnstile-captcha-with-server-verificationScan to open
Technical
Cloudflare Turnstile CAPTCHA verified on the server
Stop bots on forms without puzzles, and check every token on the server so nobody can skip the widget.
Curated by Nvoka
1 viewCursorClaude CodeLovableCodex
Make it yours
Fill in the blanks and change any word. Only your copy changes, never the card.
Fill in the blanks
0 of 2 filledYour prompt
Act as a senior web security engineer. Add Cloudflare Turnstile to {{page_or_feature}} in my {{tech_stack}} project. Before changing anything, read the existing forms and server handlers and tell me what you found.
Client:
- Load the Turnstile script only on pages with a protected form, and reserve the widget's space so nothing shifts
- Managed mode by default: most people never see a challenge. Use invisible mode only where a visible widget would hurt a key flow
- Send the token with the form. Keep submit disabled until a token exists, refresh the widget when the token expires, and show a plain retry message on errors
- Match the widget's theme and language to the page
Server, the part AI builders skip:
- Verify every token with Cloudflare's siteverify endpoint before doing any work. The widget alone stops nothing; a bot can post straight to the API
- Check success, the expected hostname and the action name. Tokens last 5 minutes and work once, so reject reused ones
- The secret key stays in a server environment variable; only the site key reaches the browser
- If Cloudflare can't be reached: fail closed for sign-up, fail open with stricter rate limits for contact forms, and log it
- Return one generic error, never the reason a check failed
Also:
- Allow challenges.cloudflare.com for scripts and frames in the Content Security Policy
- Use Cloudflare's published test keys in development and tests
- Accessibility: the widget works by keyboard and screen reader, and the page offers another way to reach us if it fails
- Keep the honeypot and rate limits. Turnstile is one layer, not the only one
- Alternatives: hCaptcha works the same way; reCAPTCHA v3 returns a score you must threshold on the server. Tell me if either fits better
Finish with the files changed, how to test a passing, failing and expired token, and anything you assumed.