mrkeyoor.com_
Thu 01 Oct 08:16 UTC
Automationevaluationupdated 01 Oct 2026

cloudflare-turnstile-bypass review

Cloudflare Turnstile Bypass is a small Python client that finds a Turnstile sitekey and asks the Peak service for a response token. It is useful only for authorized testing or automation where the site owner permits a third-party solver.

Verdict

Our run passed 11 of 11 tests and pip-audit found 0 known vulnerabilities, but it never contacted Peak, so it proves the wrapper rather than the promised solve. Use it only for an authorized target after reviewing what leaves your network and testing the paid service yourself. For your own application, Cloudflare's test keys are simpler, repeatable, and do not turn QA into anti-bot bypassing.

We ran it

Lab card: what happened when we ran cloudflare-turnstile-bypassScreenshot of cloudflare-turnstile-bypass (github.com/henryzawadzki6542/cloudflare-turnstile-bypass)
Install✓ · 19s36 packages · 37 MB
Build✓ · 4s
Tests✓ · 7s11 passed · 0 failed of 11 (pytest)
Known vulns0(pip-audit)
Repo14 files~336 lines of source · 0.5 MB · 0 CI workflows · tests dir

Answers from our run

Does cloudflare-turnstile-bypass build from source?

Dependencies installed in 19 seconds (36 packages), and the build succeeded in 4 seconds. We cloned commit 42adace into a clean Debian container with 3 CPUs and no project-specific setup.

Do cloudflare-turnstile-bypass's tests pass?

Yes: 11 of 11 passed when we ran the project's own test command (pytest). Some failures need services or credentials a bare container does not have.

Does cloudflare-turnstile-bypass have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use cloudflare-turnstile-bypass?

Scraping or account automation against a site you do not control: the package's purpose is to obtain a valid anti-bot token, so authorization and the target's terms are a hard boundary.

What are the alternatives to cloudflare-turnstile-bypass?

Cloudflare Turnstile test keys, 2Captcha Python SDK, FlareSolverr. Our run passed 11 of 11 tests and pip-audit found 0 known vulnerabilities, but it never contacted Peak, so it proves the wrapper rather than the promised solve.

Setup4/519-second install and no runtime deps; a Peak key is still required
Docs3/5API and CLI are clear, but operational and privacy detail is thin
Community2/5624 stars, but no issues, releases, or visible contributor activity
Maturity2/5Young single-file client with no CI and no live-service test in our run

Who it’s for

QA teams testing a site they own when Cloudflare's official test keys cannot reproduce a solver-dependent path.
Integration engineers with written permission to automate a Turnstile-protected workflow.
Python developers who want a standard-library CLI around the Peak API and can review every target.
Small internal tools that can tolerate an external solver dependency and its credential, privacy, and billing terms.

Who it’s NOT for

Scraping or account automation against a site you do not control: the package's purpose is to obtain a valid anti-bot token, so authorization and the target's terms are a hard boundary.
Tests of your own Turnstile integration that only need deterministic pass or fail behavior: Cloudflare publishes test sitekeys and secret keys for that job.
Teams that cannot send the target URL, sitekey, optional action, cdata, and proxy details to Peak: the source puts those fields in the solver request.
Pages that create the widget only after client-side JavaScript runs: read_page uses urllib and does not execute a browser, while discovery is regex-based.
Buyers using GitHub stars as a trust shortcut: the repository was created in September 2026, has no GitHub release or CI workflow, and its README also advertises paid GitHub search ranking.

Setup reality

Our sandbox installed commit 42adace in 19 seconds, pulling 36 packages and using 37 MB. The build passed in 4 seconds. Pytest passed all 11 tests in 7 seconds, and pip-audit reported 0 known vulnerabilities.

A real solve needs a Peak API key and sends a request to api.peak.fo; our no-secrets run did not test that service. The package itself declares no runtime dependencies, but its build and test environment accounts for the 36 packages we measured.

Python 3.8 or newer is required. The repository has a tests directory, but no Dockerfile and no CI workflows. Static HTML discovery is built in; JavaScript execution is not.

This package delegates the challenge to Peak

The name sounds like a local Cloudflare exploit. The code is much simpler: it extracts a public Turnstile sitekey, builds a JSON request, and sends that request to Peak's solver API. A successful response contains a cf-turnstile-response token. The package returns that token through Python or prints it from a command line interface.

That distinction matters for both reliability and permission. Your program does not solve the challenge by itself, and this repository does not contain Peak's solver. A real run depends on the vendor accepting the task, returning a token before it expires, and producing a result that the target accepts. The README describes CI and QA use, but the same mechanism can defeat a site's anti-bot control. Use it only on workflows you own or have permission to test.

A 336-line client keeps the local side small

The repository is 14 files, roughly 336 lines of source, and 0.5 MB checked out. Its main module uses Python's standard library for HTTP, JSON, argument parsing, retries, and regular expressions. The package metadata declares no runtime dependencies and supports Python 3.8 through 3.13. That is attractive compared with carrying a browser and matching driver into a CI image.

Small does not mean self-contained. bypass_turnstile posts the sitekey and target URL to https://api.peak.fo/solve; optional proxy, action, and cdata values go into the same payload. The API key is sent in an X-API-Key header. Teams should treat those fields as third-party disclosures, read Peak's current terms, and avoid placing unrelated secrets in target URLs or proxy strings.

What happened when we ran it

Our unprivileged Python 3.12 sandbox installed commit 42adace in 19 seconds. The environment pulled 36 packages and occupied 37 MB, then the package built successfully in 4 seconds. Pytest finished in 7 seconds with 11 passed and 0 failed. Pip-audit reported 0 known vulnerabilities.

Those 11 tests cover sitekey extraction, action extraction, payload construction, missing credentials, successful and failed API responses, one-call token creation, version output, and the default CLI discovery path. The remote calls are mocked in the test file. Since our sandbox had no secrets, it did not ask Peak for a token or submit one to Cloudflare. No conclusion about solve rate, latency, token acceptance, or billing follows from this run.

The distinction is easy to miss because every measured step is green. We verified that the local wrapper installs, builds, and behaves as its unit tests expect. The service behind the wrapper remains an external dependency. Before relying on it, run an authorized staging case, record error behavior, set a spending limit, and decide what your test should do when the solver is unavailable.

Static HTML discovery misses browser-only widgets

find_sitekey looks for data-sitekey, sitekey=, or render= patterns in supplied HTML. If no HTML is supplied, read_page fetches the URL with urllib and decodes the response. There is no JavaScript runtime. A site that constructs its widget only after scripts execute may therefore leave nothing for this client to match, despite the README saying bundle-source patterns are supported.

The regex also returns the first matching candidate. That is adequate for a simple page with one widget. A page with several keys, conditional scripts, or unrelated text containing the same pattern needs extra selection logic. The library exposes find_action, but its one-call path only forwards the first discovered action and does not verify that the sitekey and action came from the same widget.

One code path deserves another test. When the file runs through python -m with --sitekey, main calls the create_token alias before the file assigns that alias below its if __name__ == "__main__" block. The installed console entry point imports the module first and avoids that ordering problem, but direct module execution can hit it. The 11-test suite covers the discovery CLI path, not this branch.

Cloudflare test keys are better for first-party QA

Cloudflare publishes test sitekeys and secret keys that return defined outcomes on any domain. Its visible widget key ending in AA always passes, while the key ending in BB always blocks. Dummy tokens also let server-side Siteverify tests cover success and failure without a solver account. For most teams testing their own form, those fixtures are the clean answer.

A solver becomes relevant only when an authorized test must exercise behavior closer to a production challenge. Even then, keep it in a separate staging job, never a general crawler. Store the Peak key in a secret manager, restrict target hosts in your wrapper, and log task IDs rather than response tokens. This package has no built-in allowlist or spend control, so those guardrails belong to the caller.

The repository is active but too young for star-based trust

The project was created on September 8, 2026 and pushed on September 30. GitHub showed 624 stars, 41 forks, and 0 open issues or pull requests on October 1. There was no GitHub release, Dockerfile, or CI workflow. The pyproject and changelog identify version 1.0.1, which fixes argument forwarding in the default CLI discovery path.

A clean issue queue in a three-week-old project says little about field use. The README's advertisement offering paid placement in GitHub's top search results also weakens stars as a buying signal, though it does not prove how this repository gained them. Judge the 336 lines yourself, test the Peak dependency on an authorized staging target, and prefer Cloudflare's own fixtures whenever they cover the case.

Alternatives

ProjectWhat it isPick it when
Cloudflare Turnstile test keysOfficial dummy keys produce defined pass and fail outcomes without calling a solver.pick this instead when you own the integration and need repeatable automated tests.
2Captcha Python SDKA Python client for several challenge types, including Cloudflare Turnstile.pick this instead when you already use 2Captcha or need one SDK for several challenge providers.
FlareSolverrA browser-backed proxy that returns Cloudflare session data and cookies.pick this instead when the authorized workflow needs a real browser session rather than one Turnstile token.

What people are saying

  1. [velocity-scout] henryzawadzki6542/cloudflare-turnstile-bypass

Sources

  1. Cloudflare Turnstile Bypass README
  2. Cloudflare Turnstile Bypass source
  3. Cloudflare Turnstile Bypass tests
  4. Cloudflare Turnstile test keys

More automation reviews

mactap-app · turnstile-bypass · autoshorts · ARES · appium · huashu-mac-use · the whole board →