Guide

How to Solve Cloudflare Turnstile Errors: Every Code, What It Means, the Fix

Every Cloudflare Turnstile error code explained: what 600010, 300030 and 110200 mean, why a token gets rejected, and the fix for visitors and site owners.

HProxy Team··Updated September 26, 2026·8 min read
HProxy.Guide

Skip the dead lists.

Our free proxy list re-checks every exit every few minutes across 100+ countries, with a live last-checked time, so you copy IPs that worked moments ago, not a stale text dump.

Open the free proxy list→

Cloudflare Turnstile is the small "Verify you are human" box on logins, signups and forms. When the check fails, the widget shows an error code, and the site can still reject the token it produced. The code tells you what went wrong and, more usefully, whether the visitor or the site has to act.

This page goes through every code in the official tables, the fix for each side, and the server errors behind a rejected token. We also read 142 public GitHub issues that quote one of these codes, to show which ones people actually meet. If the box keeps looping instead of showing a code, our guide to the Verify you are human loop covers that case.

Which side the code is on

The first three digits of a code name its family, and the family tells you who acts. Most codes that start with 110, and all that start with 400, come from the setup of the site, such as an unknown hostname or a wrong sitekey, and only the site owner can fix them. Two 110 codes are the exception: 110600 and 110620 are timeouts on the visitor's side, and a retry can help. Codes that start with 200 point to the clock of the visitor, a cache in between, or a frame that could not load. The 300 and 600 families are failed challenges: Cloudflare detected what it reads as bot behavior, and a retry can help.

For codes marked with an asterisk, "the remaining digits can vary and are for internal use". So 600010 and 600020 mean the same thing to you.

The codes, and who has to act

CodeWho actsRetryWhat the official table saysIn our reports
600*Visitor firstYesGeneric challenge failure, bot behavior detected.31, all 600010
300*Visitor firstYesGeneric challenge failure, bot behavior detected.35
110200SiteNoDomain not authorized: the hostname is missing from the widget.20
110100SiteNoInvalid sitekey: verify it in the dashboard.1
400020SiteNoInvalid sitekey: verify it in the dashboard.3
110110SiteNoSitekey not found: check its spelling and the dashboard.0
400021SiteNoSitekey domain mismatch: the region does not match the script tag.0
400070SiteNoSitekey disabled: check the dashboard.1
110600VisitorYesChallenge timed out: the clock may be wrong, or the check took too long.2
110620VisitorYesInteraction timed out: the visitor did not interact in time.1
200100Visitor or networkNoClock or cache problem: a wrong clock, or a cache in between.2
200500Visitor or networkYesIframe load error: something may block challenges.cloudflare.com.1

If you are the visitor

Cloudflare gives visitors one checklist for failed challenges, in this order:

  1. Use a supported, current browser: all major browsers work except Internet Explorer, but not browsers or systems over five years old or without security updates for two years. A compatibility test runs at debug.challenges.cloudflare.com.
  2. Turn extensions off, because ad blockers and similar extensions can block the scripts the widget needs.
  3. Allow JavaScript, because the check does not run without it.
  4. Try a private window, then another browser or device.
  5. Turn off any VPN or proxy: the official checklist says they can interfere, and how websites detect proxies explains why an address can count against you.
  6. Try another network, such as a phone hotspot.

For 110600 and 200100, check the clock of your computer, since a wrong clock is a named cause of both. For 200500, the frame of the widget could not load, so check whether something blocks challenges.cloudflare.com.

Two things in the browser console look alarming and are harmless. A 401 error during the check comes from a request for a Private Access Token that your device or browser cannot issue, and Cloudflare says you can generally ignore it. Failed lookups for subdomains of challenges.cloudflare.com or dnstest.dev are part of the normal check and do not block you either.

If nothing helps, write to the site with the error code and the Ray ID if the page shows one, or use Submit Feedback in the widget. Clicking the logo on the widget four times shows a QR code for that exact check, which the site or the Cloudflare support team can trace. For a problem that stays, they also ask for a HAR file and a console log recorded while it happens.

If you run the site

Most codes on the site side come from the widget configuration:

  • 110200, domain not authorized: add every hostname that serves the page to the widget in Hostname Management. In the reports, it hit sites that had added a new domain, and preview deployments whose hosts were never listed.
  • Sitekey codes: 110100 and 400020 mean an invalid sitekey, 110110 a sitekey that was not found, and 400070 a disabled one. For 400021, the sitekey region does not match the domain in the script tag. Check the key in the dashboard.
  • A widget that never loads: if the site sends a Content Security Policy, it must allow https://challenges.cloudflare.com in script-src and frame-src.
  • Errors that break the page: without an error callback, the widget throws a JavaScript exception when something fails. Add one, and expect it to fire more than once, because the widget retries on its own. After 110620, a timeout without interaction, turnstile.reset() starts the widget again.
  • Failures only inside an app: four causes are usual in a WebView. They are JavaScript turned off, no DOM storage or cookie support, a blocked challenges.cloudflare.com, or a user agent that changes during the session.

For localhost, development and automated tests, use the test keys. They work on any domain, and Cloudflare recommends that production sitekeys do not allow local domains. Pair a test sitekey with a test secret key, because a production secret key rejects the dummy token.

Test sitekeys, for the widget on the page:

  • 1x00000000000000000000AA always passes, with a visible widget.
  • 2x00000000000000000000AB always fails, with a visible widget.
  • 3x00000000000000000000FF forces an interactive challenge.

Test secret keys, for the check on your server:

  • 1x0000000000000000000000000000000AA always passes validation.
  • 2x0000000000000000000000000000000AA always fails validation.
  • 3x0000000000000000000000000000000AA answers that the token was already spent.

When the server rejects the token

The widget alone does not protect a form. The server must send each token to the Siteverify API, and the reason is short: tokens can be forged. A token is valid for 300 seconds and can be checked only once. When the check fails, the answer carries one of these codes:

Siteverify codeMeaningFixIn our reports
timeout-or-duplicateThe token was already validated or is too oldCheck each token once, within 300 seconds.25
invalid-input-responseThe token is invalid, malformed or expiredLet the visitor solve the check again.11
invalid-input-secretThe secret key is invalid or expiredCheck the secret key in the dashboard.9
missing-input-responseNo token was sentSend the form field with the token.9
internal-errorAn internal errorRetry the request.5
bad-requestThe request is malformedCheck the request format.4
missing-input-secretNo secret key was sentSend the secret key.3

The most common one in the reports, timeout-or-duplicate, means the token was checked before or is older than 300 seconds. Typical causes are a form sent twice, a token checked in two places, or a visitor who waited too long. Cloudflare also advises checking the action and hostname in the answer when you set them.

What the reports show

Our searches found 142 public GitHub issues in 96 projects that quote a widget code or a Siteverify code, and 102 of them date from 2026. The failed-challenge families lead, with the 300 family in 35 reports and 600010 alone in 31. The configuration code 110200 follows with 20, and 3 of those mention localhost or a dev server.

Our own console window: 142 GitHub issues in 96 projects quoting a Turnstile code. The 300 family in 35, the 600 family in 31, domain not authorized (110200) in 20. On the server side, timeout-or-duplicate in 25, invalid-input-response in 11, invalid-input-secret and missing-input-response in 9 each.
Captured on our own machine on 26 September 2026: Node 22 printing the summary of our saved census of public GitHub issues. One issue can quote several codes.

Of the 64 reports of a failed challenge, 14 mention a privacy setting, an extension or a privacy browser. Only 7 name an automation tool, and 5 mention a VPN or proxy.

About automated traffic

Turnstile exists to tell people from automation, and its makers say test suites such as Selenium, Cypress and Playwright are detected as bots. For your own site, the test keys above are the answer. This page does not cover getting automation past the widget on sites you do not run.

For tests on your own site, proxies with Playwright covers the browser side. If you use a proxy for other work, our proxy checker shows whether it works at all.

How we counted

We ran 24 GitHub issue searches on 26 September 2026, "turnstile" plus one code each. They cover the ten fixed codes in the official table, seven common members of the 300 and 600 families, and the seven Siteverify codes. That gave 646 hits. We kept the 142 issues whose text quotes a widget code, or a Siteverify code next to the word Turnstile, because generic words such as bad-request also match unrelated issues. Our tool then looks in each issue for named tools and settings. These are mentions, not diagnoses, and GitHub reports lean toward developers.

Sources

All from the Cloudflare developer documentation, read on 26 September 2026:

Frequently asked questions

What does Cloudflare Turnstile error 600010 mean?
It is a generic challenge failure in the 600 family: Cloudflare detected what it reads as bot behavior, and the last digits are for its internal use. A retry can help. Use a supported, current browser, turn extensions off, allow JavaScript, try a private window, another browser or device, and turn off any VPN or proxy. If it persists, send the site the error code and the Ray ID if the page shows one.
What does Turnstile error 300030 mean?
It belongs to the 300 family, which Cloudflare also lists as a generic challenge failure where bot behavior was detected, with a retry allowed. Cloudflare does not publish a finer meaning for the last digits, so the visitor checks are the same as for 600010. If it persists, clicking the widget logo four times shows a QR code that the site or Cloudflare support can trace.
What does Turnstile error 110200 mean?
Domain not authorized. The page that shows the widget runs on a hostname that is not in the Hostname Management list of the widget. Only the site owner can fix it, by adding the hostname. For localhost, the test sitekeys from Cloudflare work on any domain, and Cloudflare recommends that production sitekeys do not allow local domains.
Why was my Turnstile token rejected?
The server of the site checks every token with the Siteverify API. A token is valid for 300 seconds and can be checked only once, so a late or repeated check returns timeout-or-duplicate. Other answers are invalid-input-response for a bad or expired token, invalid-input-secret for a wrong secret key, and missing-input-response when no token was sent.
Is a 401 error in the browser console a problem?
Usually not. Cloudflare says you can generally ignore a 401 during the check. It comes from a request for a Private Access Token that your device or browser cannot issue, and the check falls back to a standard challenge.
How do I test a form with Turnstile in Selenium, Cypress or Playwright?
Use the test keys. Cloudflare says automated test suites are detected as bots, so a real sitekey gives failed or unpredictable tests. The test sitekey 1x00000000000000000000AA always passes and 2x00000000000000000000AB always fails. Pair it with a test secret key, because a production secret key rejects the dummy token.
Can a proxy get me past Cloudflare Turnstile?
No. Turnstile runs small JavaScript challenges in your browser and reads signals from the browser environment, not only your address. Cloudflare lists VPNs and proxies among the things that can interfere with it, so as a visitor, turn them off. If you test your own site, use the test keys.

Get proxies that are alive right now

Our free proxy list re-checks every exit every few minutes across 100+ countries, with a live last-checked time, so you copy IPs that worked moments ago, not a stale text dump. When the location has to survive a real check, the paid network holds up.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed