Cloudflare: Turnstile, error 1020 and TLS fingerprint

Cloudflare protects a large share of the web: JavaScript challenges, Turnstile, application firewall. Here is how to identify blocks (including error 1020), understand their cause and approach them cleanly.

  • Returned by the WAF (a blocking rule)
  • Often HTTP 403, a dedicated Cloudflare page
  • Triggered by URL, User-Agent, IP or country
  • Read the HTTP code and the response body
  • Spot the Cloudflare code (1020, 1015…)
  • Distinguish WAF rule, JavaScript challenge and rate limiting
  • Respect robots.txt and terms of use
  • Limit frequency and volume
  • Monitor and adapt as defenses evolve
What is Cloudflare error 1020?

It is an error returned by Cloudflare’s application firewall (WAF) when a rule blocks the request: the content is never served. It indicates a rule-level refusal (URL pattern, User-Agent, IP, country) rather than a rendering issue.

Is Turnstile a CAPTCHA?

Turnstile is Cloudflare’s alternative to CAPTCHA: a challenge, often invisible, that runs in the page and produces a token. It aims to verify a human is present without systematically imposing an image grid.

Why does Cloudflare block my Python script?

A script using a minimal HTTP library has a fingerprint (TLS, headers) that differs from a browser and does not run JavaScript: it fails the challenges and may trigger a WAF rule. A realistic headless browser gets past these steps for many sites.

Does ScraperFlow always get past Cloudflare?

No. ScraperFlow runs JavaScript and presents a realistic fingerprint, which gets past many protections, but some WAF rules explicitly aim to exclude automation. Results vary with the site’s configuration.

Ready to scrape a website?

Run your first scrape in seconds, for free.

Start a scrape