Was this helpful?
How to Bypass Cloudflare Turnstile Standalone on Chess.com
Technical engineer
Introduction
Cloudflare Turnstile is a privacy-friendly alternative to traditional CAPTCHAs, widely used on platforms like Chess.com to prevent automated bot activity during login or registration. While it operates invisibly for real users, automation scripts often get stuck on it.
In this guide, I will show you how to bypass the standalone Turnstile widget on Chess.com using the 2captcha API. We will cover how to extract the required parameters, send the task via API v2, and correctly inject the returned token back into the page.
Note: This guide covers Standalone Turnstile (a widget embedded in a page). If you're dealing with a full Cloudflare Challenge Page (an interstitial page shown before the actual site), you'll need additional parameters (
action,data,pagedata) and a different approach to intercept them. See the Turnstile on Cloudflare Challenge pages guide for details.
Task Parameters
To solve a standalone Turnstile captcha, we use the TurnstileTaskProxyless task type. The request does not include any proxy parameters, as the service uses its own internal proxy pool to solve the task.
| Parameter | Type | Required | Description |
|---|---|---|---|
type |
String | Yes | Must be set to TurnstileTaskProxyless |
websiteURL |
String | Yes | The full URL of the page where the captcha appears |
websiteKey |
String | Yes | The static site key (starts with 0x4...) |
action |
String | No* | Required for Cloudflare Challenge pages. The value of the action parameter of the turnstile.render call |
data |
String | No* | Required for Cloudflare Challenge pages. The value of the cData parameter of the turnstile.render call |
pagedata |
String | No* | Required for Cloudflare Challenge pages. The value of the chlPageData parameter of the turnstile.render call |
* Only required for Cloudflare Challenge pages, not for standalone captchas.
Finding the Parameters
Method 1: Elements Tab (Recommended for Standalone)
- Open the Chess.com page where the Turnstile appears (e.g., the login or registration page).
- Press
F12to open DevTools and switch to the Elements tab. - Press
Ctrl+F(orCmd+F) and search forcf-turnstileordata-sitekey. - You will find a
divelement that looks like this:<div class="cf-turnstile" data-sitekey="0x4AAAAAAAVrOwQWPlm3Bnr5" ...></div>. The value ofdata-sitekeyis yourwebsiteKey. - Copy the full URL from the browser's address bar. This is your
websiteURL.
Method 2: Network Tab (Useful for Dynamic Pages)
- Open DevTools and switch to the Network tab.
- Enable Preserve log to capture requests across page reloads.
- Trigger the captcha (e.g., enter an email and click the login button).
- In the filter, type
turnstileorchallenges.cloudflare.com. - Find the request to Cloudflare's API and extract the
sitekeyfrom the request parameters. - Copy the full URL from the address bar at the moment the captcha is active — it may contain dynamic parameters (like
state) that are critical for Turnstile validation.
Warning: Using a URL without the dynamic parameters, or with an outdated one, will cause the solve to fail, since Turnstile strictly checks that the URL matches the session.
Code Examples
Python + Requests (API v2 Direct)
This example demonstrates how to send the task and poll for the result using raw HTTP requests. Notice that the payload contains no proxy fields.
python
import requests
import time
API_KEY = 'YOUR_API_KEY'
WEBSITE_URL = 'https://www.chess.com/login'
WEBSITE_KEY = '0x4AAAAAAAVrOwQWPlm3Bnr5' # Replace with the actual key
# 1. Send the task (Proxyless request)
url = 'https://api.2captcha.com/createTask'
headers = {
'Content-Type': 'application/json'
}
payload = {
"clientKey": API_KEY,
"task": {
"type": "TurnstileTaskProxyless",
"websiteURL": WEBSITE_URL,
"websiteKey": WEBSITE_KEY
# No proxy parameters are needed for TurnstileTaskProxyless
}
}
response = requests.post(url, headers=headers, json=payload)
result = response.json()
if result.get('errorId') == 0:
task_id = result.get('taskId')
print(f"Task created, ID: {task_id}")
# 2. Wait for the solution
res_url = 'https://api.2captcha.com/getTaskResult'
while True:
time.sleep(5) # Pause between requests
res_payload = {
"clientKey": API_KEY,
"taskId": task_id
}
res_response = requests.post(res_url, headers=headers, json=res_payload).json()
if res_response.get('errorId') == 0 and res_response.get('status') == 'ready':
print("Captcha solved successfully!")
token = res_response['solution']['token']
print(f"Token: {token}")
break
elif res_response.get('errorId') != 0:
print(f"Error getting result: {res_response.get('errorDescription')}")
break
else:
print(f"Error creating task: {result.get('errorDescription')}")
Using Your Own Proxy (TurnstileTask)
If the target website strictly binds the session to a specific IP address, you should use the TurnstileTask type and provide your own proxy. This task type extends TurnstileTaskProxyless by adding proxy-related parameters.
| Parameter | Type | Required | Description |
|---|---|---|---|
proxyType |
String | Yes | Proxy type: http, socks4, or socks5 |
proxyAddress |
String | Yes | Proxy IP address or hostname |
proxyPort |
Integer | Yes | Proxy port |
proxyLogin |
String | No | Login for basic authentication on the proxy |
proxyPassword |
String | No | Password for basic authentication on the proxy |
Python + Requests Example (with Proxy):
python
payload = {
"clientKey": API_KEY,
"task": {
"type": "TurnstileTask",
"websiteURL": WEBSITE_URL,
"websiteKey": WEBSITE_KEY,
"proxyType": "http",
"proxyAddress": "1.2.3.4",
"proxyPort": 8080,
"proxyLogin": "user23",
"proxyPassword": "p4$w0rd"
}
}
# The rest of the polling logic remains exactly the same
💡 Pro Tip: For the best success rate with strict sites like Chess.com, consider using Residential Proxies instead of datacenter proxies. Residential IPs belong to real devices, making them significantly harder to detect and block. 2captcha offers a reliable Residential Proxies service with 90M+ IPs across 220+ countries, supporting HTTP, HTTPS, and SOCKS5 protocols.
Note: If you are automating the browser yourself (e.g., via Playwright or Selenium), it is often better to use
TurnstileTaskProxylessand route the browser's traffic through your proxy at the browser level, rather than passing the proxy to the API.
Python SDK (Synchronous)
If you prefer not to handle HTTP requests manually, use the official 2captcha-python library. The SDK returns the token in the result['code'] field, which is equivalent to solution['token'] in the raw API response.
python
import sys
import os
from twocaptcha import TwoCaptcha
# Set your API key via environment variable or directly
api_key = os.getenv('APIKEY_2CAPTCHA', 'YOUR_API_KEY')
solver = TwoCaptcha(api_key)
try:
result = solver.turnstile(
sitekey='0x4AAAAAAAVrOwQWPlm3Bnr5',
url='https://www.chess.com/login',
)
except Exception as e:
sys.exit(str(e))
else:
# SDK returns the token in result['code']
print(f"Token: {result['code']}")
Python SDK (Asynchronous)
For high-load applications, the asynchronous version of the SDK is recommended.
python
import asyncio
import os
import sys
from twocaptcha import AsyncTwoCaptcha
api_key = os.getenv('APIKEY_2CAPTCHA', 'YOUR_API_KEY')
solver = AsyncTwoCaptcha(api_key)
async def solve_captcha():
try:
result = await solver.turnstile(
sitekey='0x4AAAAAAAVrOwQWPlm3Bnr5',
url='https://www.chess.com/login',
)
# SDK returns the token in result['code']
print(f"Token: {result['code']}")
return result
except Exception as e:
sys.exit(e)
if __name__ == '__main__':
asyncio.run(solve_captcha())
How to Use the Returned Token
Once you receive the token, you must pass it to the target page. There are two common ways Chess.com (and similar sites) handle this:
Option 1: Hidden Form Field (Most Common)
The site expects the token in a hidden input named cf-turnstile-response.
javascript
document.querySelector('input[name="cf-turnstile-response"]').value = "YOUR_TOKEN_HERE";
// Then submit the form
Option 2: JavaScript Callback
If the widget was initialized with a data-callback attribute, you need to call that function manually.
javascript
// Replace 'turnstileCallback' with the actual function name from the data-callback attribute
if (typeof turnstileCallback === 'function') {
turnstileCallback("YOUR_TOKEN_HERE");
}
Browser Extension Alternative
If you don't want to write code, you can use the official Captcha Solver browser extension. It automatically detects Turnstile widgets on pages like Chess.com and solves them with a single click using your 2captcha account.
Testing in Sandbox Mode
Before integrating the solution into your main script, verify that the extracted parameters are correct using the 2captcha sandbox.
- Submit the task through the API using your
websiteURLandwebsiteKey. - Go to the 2captcha Sandbox and switch to Worker mode.
- If you pick up the task and see the Turnstile widget loading correctly, the parameters were collected correctly. If the widget throws an "Invalid domain" error, double-check that the
websiteURLmatches the page exactly.
Common Errors and Fixes
| Error / Issue | Cause | Fix |
|---|---|---|
ERROR_INVALID_SITE_KEY |
Wrong websiteKey or domain mismatch |
Ensure the key starts with 0x4 and was copied without extra spaces. |
CAPCHA_NOT_READY indefinitely |
Stale or incorrect websiteURL |
Make sure you are sending the exact URL where the captcha was triggered, including any dynamic parameters. |
| Form doesn't submit after injection | Token placed in the wrong field | Check the Network tab while submitting manually to see which field carries the token. |