Was this helpful?
How to Bypass Cloudflare Turnstile Standalone on Postman
Technical engineer
Introduction
Modern authentication portals increasingly rely on Cloudflare Turnstile to mitigate bot traffic and credential stuffing. While this technology offers a frictionless experience for human users, it actively blocks standard automation scripts.
This guide provides a technical walkthrough on bypassing the standalone Turnstile widget—commonly encountered on identity platforms like Postman—using the 2captcha API v2. We will cover precise parameter extraction, task submission, and the correct mechanics for injecting the returned token to complete the authentication flow.
Note: This guide focuses on Standalone Turnstile (a widget embedded directly into a webpage). If you encounter a full-page Cloudflare Challenge (an interstitial screen), the approach requires additional parameters (
action,data,pagedata). Refer to our dedicated guide on bypassing Turnstile on Cloudflare Challenge pages for that scenario.
Task Parameters
For standalone widgets, the optimal choice is the TurnstileTaskProxyless task type. No proxy parameters are required in the payload, as the service resolves the challenge using its own managed infrastructure.
| Parameter | Type | Required | Description |
|---|---|---|---|
type |
String | Yes | Must be exactly TurnstileTaskProxyless |
websiteURL |
String | Yes | The absolute URL of the page hosting the widget |
websiteKey |
String | Yes | The public site key (identifiable by the 0x4... prefix) |
action |
String | No* | Required only for Challenge pages. Maps to the action parameter in turnstile.render |
data |
String | No* | Required only for Challenge pages. Maps to the cData parameter in turnstile.render |
pagedata |
String | No* | Required only for Challenge pages. Maps to the chlPageData parameter in turnstile.render |
* Omit these for standard standalone implementations.
Extracting the Parameters
Method 1: DOM Inspection (Recommended)
- Navigate to the target authentication page (e.g., the Postman identity portal).
- Open browser DevTools (
F12) and select the Elements panel. - Search (
Ctrl+F/Cmd+F) forcf-turnstileordata-sitekey. - Locate the container element:
<div class="cf-turnstile" data-sitekey="0x4AAAAAAA..." ...></div>. Thedata-sitekeyvalue is yourwebsiteKey. - Copy the exact URL from the browser's address bar to use as
websiteURL.
Method 2: Network Interception (For Dynamic Sessions)
- Open DevTools and switch to the Network panel.
- Enable Preserve log to prevent request history from clearing on redirects.
- Trigger the authentication flow (e.g., submit an email address).
- Filter the network requests by
turnstileorchallenges.cloudflare.com. - Inspect the outgoing request payload to find the
sitekey. - Copy the URL from the address bar at the exact moment the widget appears.
Critical: Turnstile cryptographically binds the token to the session URL. Omitting dynamic query parameters (such as
?state=...or?returnTo=...) will result in anERROR_INVALID_SITE_KEYor silent validation failure on the target server.
Implementation Examples
Direct API v2 Integration (Python + Requests)
This approach demonstrates raw HTTP communication with the 2captcha API. Note the absence of proxy fields in the TurnstileTaskProxyless payload.
python
import requests
import time
API_KEY = 'YOUR_API_KEY'
WEBSITE_URL = 'https://identity.getpostman.com/' # Include dynamic query params if present
WEBSITE_KEY = '0x4AAAAAAA...' # Replace with the extracted key
# 1. Submit the solving task
create_url = 'https://api.2captcha.com/createTask'
headers = {'Content-Type': 'application/json'}
payload = {
"clientKey": API_KEY,
"task": {
"type": "TurnstileTaskProxyless",
"websiteURL": WEBSITE_URL,
"websiteKey": WEBSITE_KEY
}
}
response = requests.post(create_url, headers=headers, json=payload).json()
if response.get('errorId') == 0:
task_id = response.get('taskId')
print(f"Task initiated. ID: {task_id}")
# 2. Poll for the result
result_url = 'https://api.2captcha.com/getTaskResult'
while True:
time.sleep(5)
res_payload = {"clientKey": API_KEY, "taskId": task_id}
res_response = requests.post(result_url, headers=headers, json=res_payload).json()
if res_response.get('status') == 'ready' and res_response.get('errorId') == 0:
token = res_response['solution']['token']
print(f"Success! Token: {token}")
break
elif res_response.get('errorId') != 0:
print(f"API Error: {res_response.get('errorDescription')}")
break
else:
print(f"Submission Error: {response.get('errorDescription')}")
Using Custom Proxies (TurnstileTask)
If the target environment enforces strict IP reputation checks, switch to the TurnstileTask type and supply your own proxy credentials.
| Parameter | Type | Required | Description |
|---|---|---|---|
proxyType |
String | Yes | http, socks4, or socks5 |
proxyAddress |
String | Yes | Proxy server IP or hostname |
proxyPort |
Integer | Yes | Proxy server port |
proxyLogin |
String | No | Proxy authentication username |
proxyPassword |
String | No | Proxy authentication password |
python
# Modified payload for TurnstileTask
payload = {
"clientKey": API_KEY,
"task": {
"type": "TurnstileTask",
"websiteURL": WEBSITE_URL,
"websiteKey": WEBSITE_KEY,
"proxyType": "http",
"proxyAddress": "198.51.100.10",
"proxyPort": 8080,
"proxyLogin": "username",
"proxyPassword": "password"
}
}
Infrastructure Tip: For high-security identity providers, standard datacenter proxies often trigger immediate blocks. Utilizing Residential Proxies significantly improves success rates, as these IPs originate from legitimate ISP-assigned consumer devices. 2captcha provides a robust Residential Proxies network (90M+ IPs, 220+ countries) supporting HTTP and SOCKS5 protocols.
Alternative: If you are already orchestrating a browser via Selenium or Playwright, it is generally more efficient to use
TurnstileTaskProxylessand route the browser's native traffic through your proxy, rather than passing proxy credentials to the API.
Official Python SDK (Synchronous)
For cleaner code, the official 2captcha-python library abstracts the polling logic. The SDK conveniently returns the token in the result['code'] field.
python
import os
import sys
from twocaptcha import TwoCaptcha
api_key = os.getenv('APIKEY_2CAPTCHA', 'YOUR_API_KEY')
solver = TwoCaptcha(api_key)
try:
result = solver.turnstile(
sitekey='0x4AAAAAAA...',
url='https://identity.getpostman.com/',
)
print(f"Resolved Token: {result['code']}")
except Exception as e:
sys.exit(f"Failed to solve: {e}")
Official Python SDK (Asynchronous)
Ideal for concurrent, high-throughput automation pipelines.
python
import os
import sys
import asyncio
from twocaptcha import AsyncTwoCaptcha
api_key = os.getenv('APIKEY_2CAPTCHA', 'YOUR_API_KEY')
solver = AsyncTwoCaptcha(api_key)
async def main():
try:
result = await solver.turnstile(
sitekey='0x4AAAAAAA...',
url='https://identity.getpostman.com/',
)
print(f"Resolved Token: {result['code']}")
except Exception as e:
sys.exit(f"Failed to solve: {e}")
if __name__ == '__main__':
asyncio.run(main())
Token Injection Mechanics
Once the token is acquired, it must be passed back to the client application. Identity providers typically handle this in one of two ways:
1. Hidden Form Input (Standard)
The backend expects the token in a specific hidden field prior to form submission.
javascript
const tokenInput = document.querySelector('input[name="cf-turnstile-response"]') || document.createElement('input');
tokenInput.type = 'hidden';
tokenInput.name = 'cf-turnstile-response';
tokenInput.value = "YOUR_RESOLVED_TOKEN";
document.querySelector('form').appendChild(tokenInput);
// Proceed with form submission
2. Explicit JavaScript Callback
If the widget was initialized with a data-callback attribute, the frontend expects a function call.
javascript
// Replace 'onTurnstileSuccess' with the actual callback name found in the DOM
if (typeof onTurnstileSuccess === 'function') {
onTurnstileSuccess("YOUR_RESOLVED_TOKEN");
}
Browser Extension Alternative
For manual testing or non-programmatic workflows, the official Captcha Solver extension automates the entire process. It detects Turnstile widgets on the active tab and resolves them instantly using your linked 2captcha account.
Validation and Debugging
Before deploying to production, validate your parameters in the 2captcha Sandbox.
- Submit your
websiteURLandwebsiteKeyvia the API. - Switch the sandbox to Worker mode.
- If the worker can successfully load and solve the widget, your parameters are correct. An "Invalid domain" error indicates a mismatch between the provided URL and the domain registered to the sitekey.
Common Failure Modes
| Symptom | Root Cause | Resolution |
|---|---|---|
ERROR_INVALID_SITE_KEY |
Malformed sitekey or domain mismatch. | Verify the key starts with 0x4 and contains no trailing whitespace. |
Perpetual CAPCHA_NOT_READY |
The websiteURL is stale or missing dynamic session parameters. |
Capture the URL after the page has fully loaded and the challenge is active. |
| Silent form submission failure | Token injected into the wrong DOM element. | Inspect the Network tab during a manual, successful login to identify the exact payload field carrying the token. |