Cloudflare Turnstile: a widget without Siteverify stops no bots

Turnstile tokens can be forged, so your backend must call Siteverify; Cloudflare now flags widgets that skip it with Fix with Spin.

Cloudflare Turnstile and Siteverify: four server-side checks before you ship a form

A bot check on your signup form can render perfectly and still stop nothing.

Turnstile is two halves. The widget in the browser issues a token. Your backend sends that token to Siteverify. Skip the second call and a bot posts any string it likes. Cloudflare's own docs say tokens can be forged.

Cloudflare can now see that gap. It sees every widget and every Siteverify call, so a widget serving traffic with no backend check gets a "Fix with Spin" banner. Your own coding agent then proposes a plan, waits for approval, and wires the missing server step.

It's the half a generated app can skip without anything looking broken.

For any client-side check, confirm four things:

  • the token is verified on the server,
  • missing or reused tokens are rejected,
  • hostname and action match what you expect,
  • expired tokens trigger a reset.

A widget asks the question. Your backend has to check the answer.

Watch the video on LinkedIn ↗