Headed Chrome is a requirement, not a deployment detail
Turnstile Bypass controls a real, visible Chrome window. For a widget embedded on a page, it returns a token as JSON. For a Cloudflare waiting room, it keeps the browser on the destination after obtaining the clearance cookie. The project does not claim to be a general Cloudflare bypass. Its own scope table excludes error 1020, rate-limit error 1015, WAF blocks, hCaptcha, reCAPTCHA, and a browser that Cloudflare has already rejected.
That boundary decides where the tool fits. It is reasonable for an authorized QA job that already uses one browser and can stop when the challenge fails. It is a poor match for a headless worker fleet. The README says the interstitial route needs the tab brought to the front, and Linux machines without a desktop need Xvfb. Tokens are described as short-lived, around 300 seconds, so saving one for later sessions is not a supported workflow.
The default lane patches one Cloudflare iframe behavior
The default route uses DrissionPage plus a packaged Chrome extension. Its Manifest V3 file runs a two-file patch in the main page world and matches the Cloudflare challenge domain. The README says the patch corrects screen coordinates produced by Chrome DevTools Protocol clicks because Turnstile treats the uncorrected pattern as automated input. This is a focused workaround tied to browser and challenge behavior, not a new browser engine.
There are two optional lanes. If Node and agent-browser-cli are already available, the solver can prefer that browser route. A YesCaptcha path exists as a last resort and requires its own client key. More lanes do not erase the main constraint: the result depends on a live site, Chrome behavior, network reputation, and Cloudflare's current checks. The project itself warns that datacenter IPs often fail and suggests stopping after one residential-proxy retry.
What happened when we ran it
Our fresh Debian sandbox installed commit abff97c in 18 seconds. It added 47 Python packages and occupied 54 MB on disk. The container had 3 CPUs, 8 GB of RAM, no secrets, and no elevated privileges. The build check then succeeded in 7 seconds. Pip-audit found 0 known vulnerabilities in the installed environment.
The test step was skipped because the repository exposes no test script or target. Pytest did not run and no pass count exists. Our scan also found no tests directory, CI workflow, or Dockerfile. Those absences matter more than the quick install because the fragile part is not importing Python. It is whether a current browser can clear a current challenge on the specific site you are authorized to test.
The checkout itself is small: 28 files, about 1,903 source lines, and 0.1 MB before dependencies. Its installation script creates a virtual environment, installs DrissionPage, packs the extension, and runs a preflight check. That preflight verifies Chrome, a display, the patch, and available lanes. It does not replace a live regression test against your target, and our lab measurements did not attempt one.
JSON failures are safer than invented tokens
The interface has one good operational choice: standard output is one JSON object, and failure returns ok: false with an error instead of manufacturing a token. That makes a caller easier to contain. A job can reject missing or short output and stop rather than sending an invalid credential into another request. The README also says not to cache tokens across sessions.
Use still requires a rule outside the code: run it only against systems you own or have permission to test. A technical path through a challenge does not confer access rights. Put target allowlists, request budgets, and a hard failure path in the calling job. The repository does not provide those controls for you, and its narrow JSON contract should not be mistaken for a complete scraping policy.
Four open pull requests are the whole activity trail
GitHub showed 483 stars and 4 open issues and pull requests. All four open items were pull requests, not bug reports. They propose an HTTP frontend, broader browser support, compatibility with Node versions below 22, and a different way to find Turnstile buttons. The latest repository push was September 7, 2026, while those pull requests were updated through September 27. That is recent activity, but it is too short a history to establish steady maintenance.
There is no published GitHub release. commit abff97c, the revision we measured, was made on the repository's first day and documents the waiting-room path. With no automated test target, release tag, or CI signal, pin the commit and keep your own authorized fixture. The 18-second install makes experiments cheap. The missing regression layer makes unattended reliance expensive, especially when a browser update or challenge change can invalidate the central technique.

