Configuring Cloudflare Turnstile

Cloudflare Turnstile protects your forms from spam and bot abuse without showing CAPTCHAs or puzzles to real users. It runs a challenge invisibly in the background and only interrupts users when suspicious behavior is detected.

Before You Start

↑ Back to top

You will need a free Cloudflare account to get your Site Key and Secret Key. Sign up or log in at cloudflare.com and go to Turnstile from the dashboard sidebar.

Accessing Cloudflare Turnstile Settings

↑ Back to top

Go to WooCommerce > Settings > Accounts & Privacy > Customer Accounts and click on Cloudflare Turnstile.

Steps

↑ Back to top

Step 1: Get your Turnstile keys from Cloudflare

↑ Back to top
  1. Log in to your Cloudflare dashboard.
  2. Go to Turnstile from the sidebar.
  3. Click Add widget.

4. Enter widget name and add hostnames.

5. Choose managed widget mode

6. Copy the Site Key and Secret Key.

Step 2: Enable Cloudflare Turnstile

↑ Back to top

Under Cloudflare Turnstile, check Enable Cloudflare Turnstile.

Step 3: Select the forms to protect

↑ Back to top

Under Forms, select which forms you want Turnstile to appear on.

Supported forms

WooCommerce
  • Login
  • Registration
  • Reset Password
  • Classic Checkout
WordPress
  • Login
  • Registration
  • Reset Password
Enhanced Customer Accounts for WooCommerce
  • Send Login Email (Passwordless Login)
  • Verify Login (Passwordless Login)
  • Send Verification Email (Email Verification)
  • Verify Email (Email Verification)

For stronger checkout protection, consider enabling the Modern Login experience on checkout — the checkout form is only shown after the user is logged in, reducing exposure to spam and bots.

Step 4: Enter your Site Key and Secret Key

↑ Back to top
  • Paste your Site Key into the Site key field.
  • Paste your Secret Key into the Secret key field.

Step 5: Configure the widget appearance

↑ Back to top
  • Theme — choose Auto to match your site’s color scheme, or set it to Light or Dark manually. Default: Auto.
  • Size — choose Normal for standard forms, Flexible for full-width layouts, or Compact for tighter spaces. Default: Normal.

Step 6: Click Save changes

↑ Back to top

Click Save changes to apply your settings.

Combining with Rate Limiting

↑ Back to top

Cloudflare Turnstile and Rate Limiting work well together. Turnstile blocks bots at the form level before a request is processed, while Rate Limiting caps request frequency by IP for anything that slips through. Using both provides layered protection.

Related Products

Offer add-ons like gift wrapping, special messages or other special options for your products.

WooCommerce Subscriptions is a WooCommerce extension that lets customers subscribe to your products or...

Use of your personal data
We and our partners process your personal data (such as browsing data, IP Addresses, cookie information, and other unique identifiers) based on your consent and/or our legitimate interest to optimize our website, marketing activities, and your user experience.