
Cloudflare Turnstile 绕过工具 | Cloudflare Bypass Tool based on SeleniumBase UC Mode | 支持 Mac/Windows/Linux
A multi-strategy toolkit for researching and testing Cloudflare Turnstile / Challenge flows on macOS, Windows, and Linux.
面向 Cloudflare Turnstile / Challenge 的多方案研究与授权测试工具集,支持 Mac / Windows / Linux。
English
This project is intended for educational research and authorized automation testing only. You must comply with applicable laws and the terms of service of any target website.
中文
本项目仅供学习研究与已授权的自动化测试使用。使用时须遵守当地法律法规及目标站点服务条款。
English
Cloudflare defenses in 2025–2026 are layered: network reputation, TLS/HTTP fingerprinting, JavaScript challenges, Turnstile interaction, and automation-protocol signals. A single HTTP client is not sufficient for Turnstile.
This repository provides five runnable strategies plus one class-based wrapper, so you can choose the right path for single-session research, batch jobs, pure CDP control, or TLS-level reuse of an already-solved session.
Recommended baseline (open-source path):
Headed real Chrome
+ optional residential / high-quality egress IP
+ UC reconnect or pure CDP
+ OS-level captcha click when interaction is required
Not recommended as a primary Turnstile path:
True headless hard-target Managed Turnstile
Pure curl_cffi / tls-client against Turnstile
playwright-stealth alone as a “one-click” solution
中文
2025–2026 年 Cloudflare 检测已分层:网络信誉、TLS/HTTP 指纹、JS Challenge、Turnstile 交互,以及自动化协议特征。单靠 HTTP 客户端无法完成 Turnstile。
本仓库提供 5 套可运行方案 与 1 个类封装入口,覆盖单会话研究、批量任务、纯 CDP 控制,以及浏览器解出后的 TLS 层会话复用。
开源场景下更稳妥的基线:
有头真实 Chrome
+ 可选住宅或高质量出口 IP
+ UC 断连重连 或 纯 CDP
+ 需要交互时使用操作系统级点击
不建议作为 Turnstile 主路径:
真无头模式硬刚 Managed Turnstile
纯 curl_cffi / tls-client 直打 Turnstile
单独依赖 playwright-stealth 作为“一键方案”
| # | Script | Strategy / 策略 | Turnstile | Best for / 适用场景 |
|---|---|---|---|---|
| 1 | bypass.py | SeleniumBase UC Mode | Yes | Default single-session path / 默认单会话主路径 |
| 2 | simple_bypass.py | UC + parallel / proxy rotation | Yes | Batch jobs; GUI click contention possible / 批量任务;并行时可能争抢系统鼠标 |
| 3 | bypass_nodriver.py | nodriver pure CDP | Yes | Chromedriver-free CDP; needs OpenCV; AGPL-3.0 / 无 chromedriver;需 OpenCV;注意 AGPL |
| 4 | bypass_curl_cffi.py | TLS fingerprint / cookie reuse | No | Legacy JS Challenge or post-solve cookie reuse only / 仅旧版 Challenge 或 Cookie 复用 |
| 5 | bypass_cdp.py | SeleniumBase CDP Mode | Yes | 2026 successor path to plain UC / UC 后继路径 |
| — | bypass_seleniumbase.py | UC class wrapper | Yes | Embeddable API for secondary development / 可 import 的二次开发封装 |
| Priority / 优先级 | Choice / 选择 | Notes / 说明 |
|---|---|---|
| 1 | bypass.py or bypass_cdp.py | Primary research entry / 主入口 |
| 2 | bypass_nodriver.py | Strong CDP alternative; check AGPL / 强备选;注意许可证 |
| 3 | simple_bypass.py | Throughput / rotation; serialize GUI clicks if needed / 吞吐与轮换;GUI 点击宜串行 |
| 4 | Browser solve then curl_cffi reuse | Keep the same UA and egress IP / 须保持 UA 与出口 IP 一致 |
| Avoid | Pure HTTP against Turnstile | Will not execute JS / interact / 无法执行 JS 与交互 |
| Limitation / 限制 | Detail / 说明 |
|---|---|
| No JS runtime | Cannot complete Turnstile / modern Challenge PoW |
| No DOM / Web APIs | Missing navigator, WebGL, canvas signals |
| No interaction | Managed mode requires a real checkbox click |
| TLS is only one signal | JA3/JA4 matching is not sufficient alone |
| Feature / 功能 | Description / 说明 |
|---|---|
| SeleniumBase UC Mode | Driver disconnect-reconnect + OS-level captcha click |
| SeleniumBase CDP Mode | Pure CDP path with reduced WebDriver attachment signals |
| nodriver CDP | No chromedriver; verify_cf() template click (OpenCV) |
| Parallel / proxy rotation | Batch workers and proxy file rotation in simple_bypass.py |
| Timeout control | End-to-end timeout on primary flows |
| Cookie export | JSON and Netscape formats where applicable |
| Cross-platform | macOS, Windows, Linux (Linux needs Xvfb when headless host) |
| Item / 项目 | Requirement / 要求 |
|---|---|
| Python | 3.9+ |
| Browser | Google Chrome (or Chromium on non-amd64 Linux) |
| Display | Headed GUI preferred; Linux servers: Xvfb / virtual display |
| OS | macOS, Windows, Linux |
| Optional proxy | HTTP / HTTPS / SOCKS5 with working HTTPS CONNECT |
Python packages are listed in requirements.txt (SeleniumBase, nodriver, curl_cffi, OpenCV headless, pyvirtualdisplay, etc.).
Python 依赖见 requirements.txt(含 SeleniumBase、nodriver、curl_cffi、OpenCV headless、pyvirtualdisplay 等)。
git clone https://github.com/1837620622/cloudflare-bypass-2026.git
cd cloudflare-bypass-2026
pip install -r requirements.txt
Install Google Chrome before running browser-based scripts.
请先安装 Google Chrome,再运行浏览器方案。
git clone https://github.com/1837620622/cloudflare-bypass-2026.git
cd cloudflare-bypass-2026
sudo bash install_linux.sh
Manual alternative / 手动安装:
sudo apt-get update
sudo apt-get install -y xvfb libglib2.0-0 libnss3 libatk1.0-0 libatk-bridge2.0-0 \
libcups2 libdrm2 libxkbcommon0 libgbm1 libasound2
python3 -m pip install -r requirements.txt
Notes / 说明
.deb packages are primarily amd64. On ARM hosts, install a matching Chromium/Chrome build yourself.# Install dependencies / 安装依赖
pip install -r requirements.txt
# Method 1 — UC Mode (recommended default) / 方案1 默认推荐
python bypass.py https://example.com
python bypass.py https://example.com -p http://127.0.0.1:7890 -t 90
# Method 5 — CDP Mode / 方案5 CDP
python bypass_cdp.py https://example.com
# Method 3 — nodriver / 方案3
python bypass_nodriver.py https://example.com
Replace https://example.com with a target you are authorized to test.
请将示例 URL 替换为你有权测试的目标地址。
bypass.py (default)