Turnstile never changes a gate’s result. Verified and Unavailable come from the human check alone; BotShield does not score, and a Turnstile failure is never reported as “a bot.” See Result states.
What connecting it does
- The widget loads Turnstile for you. On any page that has
<botshield-verify>, the widget renders an invisible Turnstile challenge with your site key. No second script tag, no visible widget. - You receive the token with the result. The
botshield:successevent carriesturnstile_tokenalongsidetokenandrequest_id. Validate it with Cloudflaresiteverifyon your server, and decline the submission if it fails. - Fail closed. Require both: a valid Turnstile token and a verified BotShield result. A missing or failed Turnstile token means the request did not come through the widget on a real page.
Connect it in the Console
1
Get your Turnstile keys
In the Cloudflare Dashboard, open Turnstile and create a widget for your site. Copy the site key and the secret key.
2
Open the Cloudflare card
In the BotShield Console, go to Integrations and select Configure on the Cloudflare card.
3
Save the keys
Switch the integration on, paste the Site Key and Secret Key, and select Save. The card shows Connected.
Validate the token on your server
What it is not
- Not a score. BotShield does not read, weigh, or store the Turnstile result. The gate’s answer is the human check.
- Not required. Every BotShield Gate works without it.
- Not a substitute. Turnstile tells you a browser session looks human enough to proceed. BotShield Gate tells you a real person confirmed, with a signed result your server can check.
Next steps
Verify on your server
Check the BotShield result before you trust it.
Web component
Every attribute and event of
<botshield-verify>.Result states
What Verified and Unavailable mean, and why there is no third state.
Place a gate
Create the gate whose key goes in
scope.