Logo of «2Captcha»To home page
Captcha bypass tutorials

Was this helpful?

How to Bypass Cloudflare Turnstile Standalone on Postman

Nick McBain
Nick McBain

Technical engineer

Introduction

Modern authentication portals increasingly rely on Cloudflare Turnstile to mitigate bot traffic and credential stuffing. While this technology offers a frictionless experience for human users, it actively blocks standard automation scripts.

This guide provides a technical walkthrough on bypassing the standalone Turnstile widget—commonly encountered on identity platforms like Postman—using the 2captcha API v2. We will cover precise parameter extraction, task submission, and the correct mechanics for injecting the returned token to complete the authentication flow.

Note: This guide focuses on Standalone Turnstile (a widget embedded directly into a webpage). If you encounter a full-page Cloudflare Challenge (an interstitial screen), the approach requires additional parameters (action, data, pagedata). Refer to our dedicated guide on bypassing Turnstile on Cloudflare Challenge pages for that scenario.

Task Parameters

For standalone widgets, the optimal choice is the TurnstileTaskProxyless task type. No proxy parameters are required in the payload, as the service resolves the challenge using its own managed infrastructure.

Parameter Type Required Description
type String Yes Must be exactly TurnstileTaskProxyless
websiteURL String Yes The absolute URL of the page hosting the widget
websiteKey String Yes The public site key (identifiable by the 0x4... prefix)
action String No* Required only for Challenge pages. Maps to the action parameter in turnstile.render
data String No* Required only for Challenge pages. Maps to the cData parameter in turnstile.render
pagedata String No* Required only for Challenge pages. Maps to the chlPageData parameter in turnstile.render

* Omit these for standard standalone implementations.

Extracting the Parameters

  1. Navigate to the target authentication page (e.g., the Postman identity portal).
  2. Open browser DevTools (F12) and select the Elements panel.
  3. Search (Ctrl+F / Cmd+F) for cf-turnstile or data-sitekey.
  4. Locate the container element: <div class="cf-turnstile" data-sitekey="0x4AAAAAAA..." ...></div>. The data-sitekey value is your websiteKey.
  5. Copy the exact URL from the browser's address bar to use as websiteURL.

Method 2: Network Interception (For Dynamic Sessions)

  1. Open DevTools and switch to the Network panel.
  2. Enable Preserve log to prevent request history from clearing on redirects.
  3. Trigger the authentication flow (e.g., submit an email address).
  4. Filter the network requests by turnstile or challenges.cloudflare.com.
  5. Inspect the outgoing request payload to find the sitekey.
  6. Copy the URL from the address bar at the exact moment the widget appears.

Critical: Turnstile cryptographically binds the token to the session URL. Omitting dynamic query parameters (such as ?state=... or ?returnTo=...) will result in an ERROR_INVALID_SITE_KEY or silent validation failure on the target server.

Implementation Examples

Direct API v2 Integration (Python + Requests)

This approach demonstrates raw HTTP communication with the 2captcha API. Note the absence of proxy fields in the TurnstileTaskProxyless payload.

python Copy
import requests
import time

API_KEY = 'YOUR_API_KEY'
WEBSITE_URL = 'https://identity.getpostman.com/' # Include dynamic query params if present
WEBSITE_KEY = '0x4AAAAAAA...' # Replace with the extracted key

# 1. Submit the solving task
create_url = 'https://api.2captcha.com/createTask'
headers = {'Content-Type': 'application/json'}
payload = {
    "clientKey": API_KEY,
    "task": {
        "type": "TurnstileTaskProxyless",
        "websiteURL": WEBSITE_URL,
        "websiteKey": WEBSITE_KEY
    }
}

response = requests.post(create_url, headers=headers, json=payload).json()

if response.get('errorId') == 0:
    task_id = response.get('taskId')
    print(f"Task initiated. ID: {task_id}")

    # 2. Poll for the result
    result_url = 'https://api.2captcha.com/getTaskResult'
    while True:
        time.sleep(5)
        res_payload = {"clientKey": API_KEY, "taskId": task_id}
        res_response = requests.post(result_url, headers=headers, json=res_payload).json()

        if res_response.get('status') == 'ready' and res_response.get('errorId') == 0:
            token = res_response['solution']['token']
            print(f"Success! Token: {token}")
            break
        elif res_response.get('errorId') != 0:
            print(f"API Error: {res_response.get('errorDescription')}")
            break
else:
    print(f"Submission Error: {response.get('errorDescription')}")

Using Custom Proxies (TurnstileTask)

If the target environment enforces strict IP reputation checks, switch to the TurnstileTask type and supply your own proxy credentials.

Parameter Type Required Description
proxyType String Yes http, socks4, or socks5
proxyAddress String Yes Proxy server IP or hostname
proxyPort Integer Yes Proxy server port
proxyLogin String No Proxy authentication username
proxyPassword String No Proxy authentication password
python Copy
# Modified payload for TurnstileTask
payload = {
    "clientKey": API_KEY,
    "task": {
        "type": "TurnstileTask",
        "websiteURL": WEBSITE_URL,
        "websiteKey": WEBSITE_KEY,
        "proxyType": "http",
        "proxyAddress": "198.51.100.10",
        "proxyPort": 8080,
        "proxyLogin": "username",
        "proxyPassword": "password"
    }
}

Infrastructure Tip: For high-security identity providers, standard datacenter proxies often trigger immediate blocks. Utilizing Residential Proxies significantly improves success rates, as these IPs originate from legitimate ISP-assigned consumer devices. 2captcha provides a robust Residential Proxies network (90M+ IPs, 220+ countries) supporting HTTP and SOCKS5 protocols.

Alternative: If you are already orchestrating a browser via Selenium or Playwright, it is generally more efficient to use TurnstileTaskProxyless and route the browser's native traffic through your proxy, rather than passing proxy credentials to the API.

Official Python SDK (Synchronous)

For cleaner code, the official 2captcha-python library abstracts the polling logic. The SDK conveniently returns the token in the result['code'] field.

python Copy
import os
import sys
from twocaptcha import TwoCaptcha

api_key = os.getenv('APIKEY_2CAPTCHA', 'YOUR_API_KEY')
solver = TwoCaptcha(api_key)

try:
    result = solver.turnstile(
        sitekey='0x4AAAAAAA...',
        url='https://identity.getpostman.com/',
    )
    print(f"Resolved Token: {result['code']}")
except Exception as e:
    sys.exit(f"Failed to solve: {e}")

Official Python SDK (Asynchronous)

Ideal for concurrent, high-throughput automation pipelines.

python Copy
import os
import sys
import asyncio
from twocaptcha import AsyncTwoCaptcha

api_key = os.getenv('APIKEY_2CAPTCHA', 'YOUR_API_KEY')
solver = AsyncTwoCaptcha(api_key)

async def main():
    try:
        result = await solver.turnstile(
            sitekey='0x4AAAAAAA...',
            url='https://identity.getpostman.com/',
        )
        print(f"Resolved Token: {result['code']}")
    except Exception as e:
        sys.exit(f"Failed to solve: {e}")

if __name__ == '__main__':
    asyncio.run(main())

Token Injection Mechanics

Once the token is acquired, it must be passed back to the client application. Identity providers typically handle this in one of two ways:

1. Hidden Form Input (Standard)

The backend expects the token in a specific hidden field prior to form submission.

javascript Copy
const tokenInput = document.querySelector('input[name="cf-turnstile-response"]') || document.createElement('input');
tokenInput.type = 'hidden';
tokenInput.name = 'cf-turnstile-response';
tokenInput.value = "YOUR_RESOLVED_TOKEN";
document.querySelector('form').appendChild(tokenInput);
// Proceed with form submission

2. Explicit JavaScript Callback

If the widget was initialized with a data-callback attribute, the frontend expects a function call.

javascript Copy
// Replace 'onTurnstileSuccess' with the actual callback name found in the DOM
if (typeof onTurnstileSuccess === 'function') {
    onTurnstileSuccess("YOUR_RESOLVED_TOKEN");
}

Browser Extension Alternative

For manual testing or non-programmatic workflows, the official Captcha Solver extension automates the entire process. It detects Turnstile widgets on the active tab and resolves them instantly using your linked 2captcha account.

Validation and Debugging

Before deploying to production, validate your parameters in the 2captcha Sandbox.

  1. Submit your websiteURL and websiteKey via the API.
  2. Switch the sandbox to Worker mode.
  3. If the worker can successfully load and solve the widget, your parameters are correct. An "Invalid domain" error indicates a mismatch between the provided URL and the domain registered to the sitekey.

Common Failure Modes

Symptom Root Cause Resolution
ERROR_INVALID_SITE_KEY Malformed sitekey or domain mismatch. Verify the key starts with 0x4 and contains no trailing whitespace.
Perpetual CAPCHA_NOT_READY The websiteURL is stale or missing dynamic session parameters. Capture the URL after the page has fully loaded and the challenge is active.
Silent form submission failure Token injected into the wrong DOM element. Inspect the Network tab during a manual, successful login to identify the exact payload field carrying the token.