Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Cloudflare Turnstile solver in Java

CI

Solve Cloudflare Turnstile in Java: a tested Maven example that gets a Cloudflare Turnstile token from the ZeroCaptcha API with java.net.http and Gson, with retries, idempotency keys and a deadline. Java 17+.

Website · Docs · Quickstart · API reference · Pricing

What it does

TurnstileSolver gets a valid Cloudflare Turnstile token for a page you are allowed to automate, and SolveTurnstile prints one from the command line. You give it the page's URL and the widget's sitekey; it creates a task on the ZeroCaptcha API, waits for it, and returns the token to submit as the browser would.

  • Small: java.net.http.HttpClient for the calls and Gson for JSON. Java 17 or later, built with Maven.
  • Safe to retry: every task is created with its own Idempotency-Key, so a retry after a lost reply returns the same task instead of paying for a second one. 429, 502, 503 and 504 are retried after the wait the API asks for.
  • Bounded: polls every 2 seconds, gives each request only the time left, and stops at the timeout you pass.
  • Checked failures: a refusal or a failed task throws ZeroCaptchaException with the API's code(), such as insufficient_funds or ERROR_CAPTCHA_UNSOLVABLE, and the requestId() to quote to support.

Quickstart

  1. Create an account on the ZeroCaptcha website, create an API key on the dashboard and add funds (crypto, from $10). A task is charged only when it succeeds.

  2. Put the API's address and your key in your environment, never in your code:

    export ZEROCAPTCHA_API=https://api.zerocaptcha.io
    export ZEROCAPTCHA_KEY=zc_live_...
  3. Read the widget's data-sitekey, and its data-action and data-cdata if it sets them (the sitekey guide shows where else they hide, such as the options of turnstile.render()), then run:

    mvn -q compile exec:java -Dexec.args="https://shop.example.com/login 0x4AAAAAAAB1cD2eF3gH4iJ5 login session-7f3a9c2e"

    Many sites check the action and cData when they verify the token, so pass both whenever the widget sets them.

    It prints the token. Set PROXY_URL=http://user:pass@proxy.example.net:8080 to solve through your own proxy.

Use it in your code

Copy TurnstileSolver.java and ZeroCaptchaException.java into your project, with Gson as a dependency:

TurnstileSolver solver = new TurnstileSolver(System.getenv("ZEROCAPTCHA_API"), System.getenv("ZEROCAPTCHA_KEY"));
try {
  String token = solver.solve(
      new TurnstileSolver.Task(
          "https://shop.example.com/login", // the page with the widget
          "0x4AAAAAAAB1cD2eF3gH4iJ5", // its data-sitekey
          "login", // its data-action, or turnstile.render()'s action option; null if it sets none
          "session-7f3a9c2e", // its data-cdata, or turnstile.render()'s cData option; null if none
          null), // your proxy, such as http://user:pass@proxy.example.net:8080, or null
      Duration.ofMinutes(3));
} catch (ZeroCaptchaException error) {
  log.warn("{} (request {})", error.code(), error.requestId());
}

TurnstileSolver is safe to share between threads; each solve blocks its thread while it waits.

Submit the token

The widget sends its token in the cf-turnstile-response form field, and the site checks it with Cloudflare's siteverify when the form arrives. Send yours the same way, straight after you get it:

String form = "email=" + URLEncoder.encode("me@example.com", UTF_8)
    + "&cf-turnstile-response=" + URLEncoder.encode(token, UTF_8);
HttpRequest request = HttpRequest.newBuilder(URI.create("https://shop.example.com/login"))
    .header("Content-Type", "application/x-www-form-urlencoded")
    .POST(HttpRequest.BodyPublishers.ofString(form))
    .build();
HttpResponse<String> response = HttpClient.newHttpClient().send(request, HttpResponse.BodyHandlers.ofString());

With Selenium for Java, set the field in the page instead: the Selenium example shows the script, which is the same in every language.

How it works

  1. POST /v1/tasks with the page, the sitekey, and the action and cData if the widget sets them. The task's price is held on your balance.
  2. GET /v1/tasks/{id} every 2 seconds while the task is queued or running.
  3. succeeded carries solution.token, and the held price is charged. failed or expired carries an errorCode, and the hold is released: nothing is charged.

The task lifecycle and the errors and retries guide have every detail.

Honest limits

  • A token works once, for 300 seconds. Get it just before you submit, and a new one for the next submission.
  • The action and cData must match the widget's. A token made without them can be refused by the site's siteverify check.
  • Proxies are http or https, with the port in the URL. SOCKS is not supported.
  • Only for sites you own or are allowed to automate. The Acceptable Use Policy applies to every task.

FAQ

Is there a Java SDK? Not yet: the official clients are for JavaScript, Python and Go. These two classes are small enough to copy.

Can I use Jackson instead of Gson? Yes: only solve, request and problem touch JSON. Swap JsonObject for Jackson's ObjectNode and the rest stays.

What does a solve cost? The pricing page lists the price per 1,000 solved tasks. Only a task that succeeds is charged.

Why is my token refused by the site? Most often it was used twice, used after 300 seconds, or made without the widget's action or cData. The siteverify errors article explains each code.

Run the tests

mvn -B test

The tests run the solver against a stand-in API (the JDK's com.sun.net.httpserver) on your machine: no key, no real task, nothing spent.

More from ZeroCaptcha

Licence

MIT: see LICENSE.

Disclaimer

ZeroCaptcha is an independent service, not affiliated with or endorsed by Cloudflare. Cloudflare and Turnstile are trademarks of Cloudflare, Inc. Use ZeroCaptcha only on sites you own or are allowed to automate, as the Acceptable Use Policy says; any site owner can opt out.

About

Solve Cloudflare Turnstile in Java: a tested Maven example that gets a Cloudflare Turnstile token from the ZeroCaptcha API with java.net.http and Gson, with retries, idempotency keys and a deadline. Java 17+.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages