Pre-clearance configuration
Pre-clearance allows Turnstile to issue clearance cookies that can be used across your Cloudflare-protected domains. This feature requires specific hostname configuration for proper functionality.
For pre-clearance to work correctly, you must:
-
Use a registered Cloudflare zone.
The hostname must be a zone registered in your Cloudflare account. When configuring your widget via the dashboard, you can select from existing zones.
-
Select the registered Cloudflare zone with intended WAF rule to set pre-clearance.
The zone you select must contain the WAF rule you wish to set pre-clearance through Turnstile.
For example, if you have
example.comandapp.example.comas registered zones and you want to have Turnstile issue pre-clearance forapp.example.com, you must selectapp.example.com.
The clearance cookie cf_clearance will only be accepted on domains that match the widget's configured hostnames, are registered as zones in your Cloudflare account, and have challenges enabled through Cloudflare's security settings.
If pre-clearance is configured incorrectly, clearance cookies may become invalid and lead to additional challenge requests.
Was this helpful?
- Resources
- API
- New to Cloudflare?
- Directory
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- © 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark
-