mrkeyoor.com_
Wed 30 Sept 06:10 UTC
Automationevaluationupdated 30 Sept 2026

cloudflare-turnstile-solver review

Cloudflare Turnstile Solver is a small Python client that finds a Turnstile sitekey in page markup and asks the commercial Peak API to return a response token. It does not solve Turnstile locally; its sensible use is authorized QA on pages you own or have permission to test.

Verdict

Our run needed 36 packages and 85 seconds to install a 288-line project, while the advertised --url command crashed before making a request. Do not put version 1.0.1 into CI unchanged. For authorized testing, Cloudflare's test keys and an end-to-end browser test are easier to audit; consider this wrapper only if Peak is already approved and you are willing to fix and test the client yourself.

We ran it

Lab card: what happened when we ran cloudflare-turnstile-solverScreenshot of cloudflare-turnstile-solver (github.com/biusberline/cloudflare-turnstile-solver)
Install✓ · 85s36 packages · 37 MB
Build✓ · 10s
Testsn/ano test script
Known vulns0(pip-audit)
Repo11 files~288 lines of source · 0.5 MB · 0 CI workflows

Answers from our run

Does cloudflare-turnstile-solver build from source?

Dependencies installed in 85 seconds (36 packages), and the build succeeded in 10 seconds. We cloned commit cd81428 into a clean Debian container with 3 CPUs and no project-specific setup.

Does cloudflare-turnstile-solver have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does cloudflare-turnstile-solver have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use cloudflare-turnstile-solver?

Scraping or form submission on sites you do not own or lack permission to test: this package is presented as a token solver, and authorization remains your responsibility.

What are the alternatives to cloudflare-turnstile-solver?

Cloudflare Turnstile Workers demo, Playwright. Our run needed 36 packages and 85 seconds to install a 288-line project, while the advertised --url command crashed before making a request.

Setup2/5Simple API shape, but 85-second install and broken default CLI
Docs2/5Clear examples advertise a CLI path that crashes at this commit
Community2/5313 stars, no open items, and a September 15 push
Maturity1/5No tests, CI, or release, plus a reproduced CLI failure

Who it’s for

Site owners testing their own Turnstile-protected forms outside production.
QA teams that have approved Peak as an external processor and can keep its API key secret.
Python scripts that need a minimal standard-library wrapper around a remote service.
Developers prepared to patch or avoid the broken default CLI path in version 1.0.1.

Who it’s NOT for

Scraping or form submission on sites you do not own or lack permission to test: this package is presented as a token solver, and authorization remains your responsibility.
Teams requiring a local or self-hosted solution: token creation is delegated to api.peak.fo.
Privacy-sensitive tests that cannot send a target URL, sitekey, action, cdata, or optional proxy to a third party.
CI pipelines that expect the documented --url quick start to work at commit cd81428: we reproduced an immediate Python TypeError.
Release gates requiring project tests or CI: our scan found no test target, tests directory, or workflow.

Setup reality

Our run installed 36 packages in 85 seconds and used 37 MB. The build succeeded in 10 seconds. No test script or target existed, so tests were skipped. Pip-audit reported 0 known vulnerabilities.

The package requires Python 3.8 or newer, internet access, and a PEAK_API_KEY. The project declares no runtime dependencies, but every token request depends on Peak's API. Proxy credentials can also be passed through the client, which makes secret handling and third-party approval part of setup.

The documented --url CLI path is broken in version 1.0.1 at this commit: main() supplies an unsupported api_url keyword to token_for_page(). We reproduced the resulting TypeError locally before any request was sent. There is no Dockerfile or tagged release.

Version 1.0.1 is a Peak API client, not a local solver

Cloudflare Turnstile Solver 1.0.1 is one Python module with two jobs. It scans HTML for a sitekey and optional action, then posts those values and the page URL to api.peak.fo. The service response supplies the token. An optional proxy and cdata value can travel in the same payload. There is no browser engine, challenge model, or local token-generation implementation in the repository.

That boundary should decide adoption. The package is small because Peak performs the difficult part. You need a Peak API key, network access to its endpoint, and an approved reason for sending it details about the protected page. If a proxy contains a username and password, those credentials also enter the third-party request. Review Peak's terms, data handling, retention, and service reliability before placing this wrapper in a company test pipeline.

What happened when we ran it

Our sandbox installed commit cd81428 in 85 seconds, pulling 36 packages and using 37 MB on disk. The build passed in 10 seconds. Pip-audit reported 0 known vulnerabilities. The container had 3 CPUs, 8 GB of RAM, Python 3.12, no secrets, and no elevated privileges.

No test script or target existed, so the test step was skipped. The checkout contained 11 files, about 288 lines of source, and occupied 0.5 MB. Our scan found no CI workflow, Dockerfile, or tests directory. Those results prove that the package can be installed and built in the lab image. They do not establish that the Peak service returns a token, that a site accepts it, or that retries behave correctly.

The 36 installed packages also need context. pyproject.toml declares zero runtime dependencies, while the lab environment still installed 36 packages during its full setup. The supplied measurement does not divide those into build, packaging, and audit tools. A deployed wheel may be lighter than the measured environment, but the 37 MB figure is the reproducible number from our run.

The documented --url command crashes before any request

The README's first example calls the module with --url. At commit cd81428, main() sends api_url=None into token_for_page(), whose signature does not accept an api_url keyword. We ran that path with a placeholder key and an invalid example domain. Python stopped immediately with TypeError: token_for_page() got an unexpected keyword argument 'api_url', before page fetching or API contact.

Supplying --sitekey selects a different branch that calls create_token() directly, so the signature mismatch is confined to automatic page discovery through the CLI. The Python API does not pass that extra argument when users call token_for_page() themselves. Even so, the broken path is the one featured in the quick start and the default route for anyone following the documentation. A project with no test suite missed its most visible command.

Sitekey discovery is regex-based and intentionally narrow

The module uses 2 regular expressions to find data-sitekey, a sitekey or render assignment, and an optional data-action. That can work for server-rendered markup with recognizable strings. It does not run JavaScript, wait for a widget, or inspect a browser DOM after client-side rendering. Passing HTML directly can avoid a fetch, but the discovery rules remain the same.

The page reader uses Python's standard URL opener with a fixed package user agent and a 30-second timeout. It does not expose request headers, cookies, authentication, or browser state. Teams testing a private staging page will probably supply HTML themselves or use another tool for page access. The project description's phrase “any page” is wider than the implementation supports.

Retry logic covers transport failures, not every bad result

create_token() defaults to 3 attempts and waits longer after each transport exception. A successful HTTP response whose JSON says success is false raises immediately, as does a response missing data.token. The result object retains the raw service response alongside the token and sitekey. That is enough for a thin wrapper, but there are no tests showing malformed JSON, HTTP error bodies, timeouts, or retry limits.

Tokens are short-lived and tied to page context, according to the README. The package does not verify a token with your site's server secret; it only returns what Peak supplies. For a site you control, the meaningful end-to-end test still includes your backend's Turnstile verification, expected action and hostname checks, and the business operation protected by the form.

Zero open items do not replace a release or tests

GitHub showed 313 stars, 0 open issues and pull requests, and a last push on September 15, 2026. The repository has no tagged release even though pyproject.toml declares version 1.0.1. With no issue history in the API response, there is little public evidence of how failures are reported, triaged, or fixed.

The MIT license covers the wrapper, while the operational dependency remains a commercial API advertised throughout the README. That makes this project closer to a vendor client than an independent Turnstile tool. For authorized QA on your own application, begin with Cloudflare's documented test keys and server-side verification. Adopt this package only after fixing the CLI, adding tests around every public function, and deciding that sending page and proxy data to Peak fits your security policy.

Alternatives

ProjectWhat it isPick it when
Cloudflare Turnstile Workers demoCloudflare's own example of a Turnstile-protected form and server-side verification on Workers.pick this instead when you own the application and want to test the intended verification flow with Cloudflare's test setup.
Playwright gh↗A browser-testing framework for end-to-end tests across Chromium, Firefox, and WebKit.pick this instead when you can use Turnstile test keys in your own staging environment and want to exercise the complete user flow.

What people are saying

  1. [velocity-scout] biusberline/cloudflare-turnstile-solver

Sources

  1. Cloudflare Turnstile Solver README
  2. Cloudflare Turnstile Solver source at commit cd81428
  3. Cloudflare Turnstile Solver package metadata
  4. Cloudflare Turnstile Solver repository
  5. Cloudflare Turnstile Workers demo

More automation reviews

huashu-mac-use · stop-stutter · warp-masque-actions · ansible · ffmpeg-skill · fable-orchestrator · the whole board →