mrkeyoor.com_
Thu 01 Oct 08:16 UTC
Automationevaluationupdated 01 Oct 2026

turnstile-bypass review

Turnstile Bypass is a Python helper that drives a visible Chrome window through a Cloudflare Turnstile widget or interstitial waiting room. It returns a short-lived token or keeps the cleared browser tab open, but it does not handle IP bans, rate limits, WAF blocks, hCaptcha, or reCAPTCHA.

Verdict

Our run installed 47 packages in 18 seconds and passed its 7-second build check, but the repository supplied no test target, so installation success says nothing about whether a live challenge will clear tomorrow. Use it only for authorized, narrow browser automation where headed Chrome is acceptable and a failed solve can stop cleanly. Choose a fuller browser framework or service when you need an API, containers, cross-browser testing, or a maintained regression suite.

We ran it

Lab card: what happened when we ran turnstile-bypassScreenshot of turnstile-bypass (github.com/Sophomoresty/turnstile-bypass)
Install✓ · 18s47 packages · 54 MB
Build✓ · 7s
Testsn/ano test script
Known vulns0(pip-audit)
Repo28 files~1,903 lines of source · 0.1 MB · 0 CI workflows

Answers from our run

Does turnstile-bypass build from source?

Dependencies installed in 18 seconds (47 packages), and the build succeeded in 7 seconds. We cloned commit abff97c into a clean Debian container with 3 CPUs and no project-specific setup.

Does turnstile-bypass have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does turnstile-bypass have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use turnstile-bypass?

Headless-only servers: the README requires headed Chrome and says waiting-room pages need a visible, focused tab, with Xvfb as the Linux workaround.

What are the alternatives to turnstile-bypass?

FlareSolverr, undetected-chromedriver, Playwright. Our run installed 47 packages in 18 seconds and passed its 7-second build check, but the repository supplied no test target, so installation success says nothing about whether a live challenge will clear tomorrow.

Setup4/518-second install, but headed Chrome and a display are required
Docs4/5Commands, scope, outputs, and failure boundaries are explicit
Community2/5483 stars, one maintainer push, and four open pull requests
Maturity1/5No release, CI workflow, Dockerfile, or automated test target

Who it’s for

Developers testing Cloudflare-protected sites they own or are authorized to automate.
Small browser-automation jobs that can keep a headed Chrome session visible.
Python users who want JSON output from a narrow command rather than a full scraping proxy.
Teams willing to rerun checks whenever Cloudflare or Chrome behavior changes.

Who it’s NOT for

Headless-only servers: the README requires headed Chrome and says waiting-room pages need a visible, focused tab, with Xvfb as the Linux workaround.
Jobs blocked by Cloudflare 1020, 1015, WAF rules, or a rejected IP: the project lists every one of those cases as out of scope.
Teams needing a maintained HTTP service or container image: the repository has no Dockerfile, and open pull request 3 is still proposing the HTTP frontend.
Release processes that require an automated test target: our sandbox found none, and the repository has no CI workflow or tests directory.
Automation without the target owner's permission: passing an anti-bot challenge does not grant authorization to access or scrape a site.

Setup reality

Our sandbox installed commit abff97c in 18 seconds, adding 47 packages and 54 MB. The build check passed in 7 seconds. There was no test script or target, so tests were skipped; pip-audit reported 0 known vulnerabilities.

The default path needs Python 3.10 or newer, Chrome or Chromium, a visible display, and the packaged Manifest V3 extension. A Linux server without a desktop needs Xvfb. The optional browser lane also needs Node and agent-browser-cli, while the YesCaptcha fallback needs a service key.

This is a 28-file, roughly 1,903-line repository with no CI workflow, Dockerfile, release, or tests directory. Installation is light. Proving that a target still works is left to the live end-to-end script and your own authorized site checks.

Headed Chrome is a requirement, not a deployment detail

Turnstile Bypass controls a real, visible Chrome window. For a widget embedded on a page, it returns a token as JSON. For a Cloudflare waiting room, it keeps the browser on the destination after obtaining the clearance cookie. The project does not claim to be a general Cloudflare bypass. Its own scope table excludes error 1020, rate-limit error 1015, WAF blocks, hCaptcha, reCAPTCHA, and a browser that Cloudflare has already rejected.

That boundary decides where the tool fits. It is reasonable for an authorized QA job that already uses one browser and can stop when the challenge fails. It is a poor match for a headless worker fleet. The README says the interstitial route needs the tab brought to the front, and Linux machines without a desktop need Xvfb. Tokens are described as short-lived, around 300 seconds, so saving one for later sessions is not a supported workflow.

The default lane patches one Cloudflare iframe behavior

The default route uses DrissionPage plus a packaged Chrome extension. Its Manifest V3 file runs a two-file patch in the main page world and matches the Cloudflare challenge domain. The README says the patch corrects screen coordinates produced by Chrome DevTools Protocol clicks because Turnstile treats the uncorrected pattern as automated input. This is a focused workaround tied to browser and challenge behavior, not a new browser engine.

There are two optional lanes. If Node and agent-browser-cli are already available, the solver can prefer that browser route. A YesCaptcha path exists as a last resort and requires its own client key. More lanes do not erase the main constraint: the result depends on a live site, Chrome behavior, network reputation, and Cloudflare's current checks. The project itself warns that datacenter IPs often fail and suggests stopping after one residential-proxy retry.

What happened when we ran it

Our fresh Debian sandbox installed commit abff97c in 18 seconds. It added 47 Python packages and occupied 54 MB on disk. The container had 3 CPUs, 8 GB of RAM, no secrets, and no elevated privileges. The build check then succeeded in 7 seconds. Pip-audit found 0 known vulnerabilities in the installed environment.

The test step was skipped because the repository exposes no test script or target. Pytest did not run and no pass count exists. Our scan also found no tests directory, CI workflow, or Dockerfile. Those absences matter more than the quick install because the fragile part is not importing Python. It is whether a current browser can clear a current challenge on the specific site you are authorized to test.

The checkout itself is small: 28 files, about 1,903 source lines, and 0.1 MB before dependencies. Its installation script creates a virtual environment, installs DrissionPage, packs the extension, and runs a preflight check. That preflight verifies Chrome, a display, the patch, and available lanes. It does not replace a live regression test against your target, and our lab measurements did not attempt one.

JSON failures are safer than invented tokens

The interface has one good operational choice: standard output is one JSON object, and failure returns ok: false with an error instead of manufacturing a token. That makes a caller easier to contain. A job can reject missing or short output and stop rather than sending an invalid credential into another request. The README also says not to cache tokens across sessions.

Use still requires a rule outside the code: run it only against systems you own or have permission to test. A technical path through a challenge does not confer access rights. Put target allowlists, request budgets, and a hard failure path in the calling job. The repository does not provide those controls for you, and its narrow JSON contract should not be mistaken for a complete scraping policy.

Four open pull requests are the whole activity trail

GitHub showed 483 stars and 4 open issues and pull requests. All four open items were pull requests, not bug reports. They propose an HTTP frontend, broader browser support, compatibility with Node versions below 22, and a different way to find Turnstile buttons. The latest repository push was September 7, 2026, while those pull requests were updated through September 27. That is recent activity, but it is too short a history to establish steady maintenance.

There is no published GitHub release. commit abff97c, the revision we measured, was made on the repository's first day and documents the waiting-room path. With no automated test target, release tag, or CI signal, pin the commit and keep your own authorized fixture. The 18-second install makes experiments cheap. The missing regression layer makes unattended reliance expensive, especially when a browser update or challenge change can invalidate the central technique.

Alternatives

ProjectWhat it isPick it when
FlareSolverrA proxy service that exposes browser-based Cloudflare handling over HTTP.pick this instead when an HTTP service fits your existing scraper better than a local JSON command.
undetected-chromedriverA modified Selenium Chrome driver aimed at bot-detection compatibility.pick this instead when you need a general Selenium browser session rather than one Turnstile-focused helper.
Playwright gh↗A browser testing framework for Chromium, Firefox, and WebKit.pick this instead when you control the target and need normal end-to-end testing across browsers.

What people are saying

  1. [velocity-scout] henryzawadzki6542/cloudflare-turnstile-bypass
  2. [velocity-scout] Sophomoresty/turnstile-bypass

Sources

  1. Turnstile Bypass repository and README
  2. Measured commit abff97c
  3. HTTP frontend pull request 3
  4. Node compatibility pull request 4
  5. Chromium issue 40280325

More automation reviews

mactap-app · cloudflare-turnstile-bypass · autoshorts · ARES · appium · huashu-mac-use · the whole board →