Cloudflare: Turnstile, error 1020 and TLS fingerprint
Cloudflare protects a large share of the web: JavaScript challenges, Turnstile, application firewall. Here is how to identify blocks (including error 1020), understand their cause and approach them cleanly.
Cloudflare, gatekeeper of a large share of the web
Cloudflare sits between visitors and many sites: it filters traffic, caches resources and enforces security rules. A large share of the sites you want to reach goes through it.
For automated access, that often means meeting a JavaScript challenge, a Turnstile check or a firewall-rule block — hence the value of understanding what is at play.
Error 1020: access denied by the firewall
Error 1020 is returned by Cloudflare’s application firewall (WAF) when a rule blocks the request. It signals a rule-level refusal, not a rendering issue: the content is never served.
Common causes: a rule targeting a URL pattern, a User-Agent, an IP range or a country. The response is an explicit Cloudflare page, often HTTP 403.
- Returned by the WAF (a blocking rule)
- Often HTTP 403, a dedicated Cloudflare page
- Triggered by URL, User-Agent, IP or country
Turnstile and JavaScript challenges
Turnstile is Cloudflare’s alternative to CAPTCHA: a challenge, often invisible, that runs in the page. The client must produce a valid token to continue.
Other pages use a JavaScript challenge (“checking your browser”) that waits a few seconds then reloads. In both cases the page must run: a bare HTTP request stays blocked.
TLS fingerprint and headers
Cloudflare can analyse how the connection is established: TLS fingerprint (extension order, versions), HTTP headers, overall coherence. A client whose signature differs from a real browser is more easily suspected.
A modern, properly configured headless browser presents a fingerprint coherent with a real browser — which is what gets past this analysis.
Diagnosing a Cloudflare block
Before fixing, identify the nature of the block: HTTP code, presence of a Cloudflare page, mention of “Turnstile”, “checking your browser” or an error code (1020, 1015…).
Each clue points to a cause: error 1020 points to a WAF rule; a Turnstile challenge points to JavaScript execution; a 429 points to rate limiting.
- Read the HTTP code and the response body
- Spot the Cloudflare code (1020, 1015…)
- Distinguish WAF rule, JavaScript challenge and rate limiting
The ScraperFlow approach to Cloudflare
ScraperFlow runs a realistic headless browser, executes JavaScript and waits for rendering: Turnstile and “checking your browser” challenges unfold as for a visitor.
For rule-based or IP-based blocks, adapting the pace and spreading the load lower the risk. We do not promise to get past every configuration: some WAF rules deliberately aim to exclude automation.
Best practices and limits
Automate with restraint: respect robots.txt and the terms of use, limit the frequency, and scrape only what you need. Mass access is the first trigger for blocking.
Keep in mind that defenses evolve: what works today may change. Stable access relies on a realistic browser, a controlled pace and continuous monitoring.
- Respect robots.txt and terms of use
- Limit frequency and volume
- Monitor and adapt as defenses evolve
Frequently asked questions
What is Cloudflare error 1020?
It is an error returned by Cloudflare’s application firewall (WAF) when a rule blocks the request: the content is never served. It indicates a rule-level refusal (URL pattern, User-Agent, IP, country) rather than a rendering issue.
Is Turnstile a CAPTCHA?
Turnstile is Cloudflare’s alternative to CAPTCHA: a challenge, often invisible, that runs in the page and produces a token. It aims to verify a human is present without systematically imposing an image grid.
Why does Cloudflare block my Python script?
A script using a minimal HTTP library has a fingerprint (TLS, headers) that differs from a browser and does not run JavaScript: it fails the challenges and may trigger a WAF rule. A realistic headless browser gets past these steps for many sites.
Does ScraperFlow always get past Cloudflare?
No. ScraperFlow runs JavaScript and presents a realistic fingerprint, which gets past many protections, but some WAF rules explicitly aim to exclude automation. Results vary with the site’s configuration.