turnstile-spin
Set up, repair, or migrate to Cloudflare Turnstile bot verification in an existing frontend and backend, including server-side Siteverify.
Install / Use
npx skills add cloudflare/skills --skill turnstile-spinInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Tags
Our assessment of turnstile-spin
turnstile-spin scores 86/100 on our quality scale, 1289th of 3,478 Development & Engineering skills we index (top 38%).
Its SKILL.md is 28 KB long, well organised into 11 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
With 2,898 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 6 days ago, so turnstile-spin is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
turnstile-spin compared with similar skills
All 4 of these similar skills score higher than turnstile-spin; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| turnstile-spin (this skill)by cloudflare | 86 | 2.9k | 6d ago | SKILL.md |
| ai-job-searchby MadsLorentzen | 100 | 44.4k | today | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 3d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 6d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 6d ago | SKILL.md |
Frequently asked questions
- How do I install turnstile-spin?
- Run
npx skills add cloudflare/skills --skill turnstile-spin. The install tabs above show the steps for each supported agent. - Which AI agents does turnstile-spin work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is turnstile-spin safe to use?
- It is Apache-2.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is turnstile-spin still maintained?
- The repository was last updated 6 days ago, so turnstile-spin is actively maintained.
Skill content
View source on GitHubname: turnstile-spin description: Set up, repair, or migrate to Cloudflare Turnstile bot verification in an existing frontend and backend, including server-side Siteverify.
Turnstile Spin skill
Turns the prompt "set up Turnstile" into a working end-to-end integration: a widget, frontend snippets at every chosen insertion point, canonical server-side siteverify in the customer's existing backend, and a real validation pass before reporting success.
You are the agent. Run the wizard below by invoking the scripts under scripts/ and branching on their JSON output. The scripts hold the deterministic logic (API calls, retry/error handling); your job is orchestration, codebase reading, confirmation, and the frontend + backend edits.
This file is the canonical machine-readable behavior. Product requirements come from the Turnstile documentation, and the hosted prompt must mirror this behavior.
Framework references
Read the reference for the existing frontend when wiring the integration:
| Frontend | Reference | |---|---| | Vanilla HTML | vanilla-html | | Next.js App Router | nextjs-app | | Next.js Pages Router | nextjs-pages | | Astro | astro | | SvelteKit | sveltekit | | Hugo | hugo |
When to load this skill
Load when the user's prompt mentions any of:
- "Turnstile", "CAPTCHA", "bot protection"
- "siteverify", "cf-turnstile-response"
- "protect this form", "protect this endpoint", "protect this button", "stop bot signups", "spam signups", "block bots on <target>"
- A specific signup, login, contact form, download, comment, API endpoint, or other user-triggered request combined with "Cloudflare" or "bot"
Do not load for unrelated Cloudflare tasks (Workers, Pages, R2, etc.) unless Turnstile is also mentioned.
Choose the flow before responding
Inspect the user's prompt before starting the numbered wizard. If it says the widget is already created and provides one or more sitekeys, go directly to the existing-widget flow below. Do not run, summarize, or propose the widget-creation flow. Otherwise, use the numbered creation wizard.
Conversation flow
The user pasted the prompt. You are in a multi-step dialog. Detect what you can, ask only when you have to, confirm before every irreversible step. Each numbered moment is one agent message. Items marked [wait for user] require a user response.
-
Brief acknowledge. One sentence: "I'll run Turnstile setup end to end. That's: check auth, scan the codebase, create the widget, embed it where visitor requests need verification, wire server-side siteverify, validate. Proceed?" [wait for user] Do NOT present a plan yet. Auth + scan come first.
-
CLI check. Spin's helper scripts use
curlagainstapi.cloudflare.com. Account enumeration requires either an explicit$CLOUDFLARE_ACCOUNT_IDor a user-approved canonical absoluteWRANGLER_BINoutside the project with exactWRANGLER_VERSION. Never usenpx,pnpm exec, a package script, a project-local binary, or an unapproved executable for a credential-bearing command. Never install Wrangler automatically during the flow. -
Auth + scope probe (FIRST irreversible action). Run
scripts/auth-probe.sh. If account enumeration needs Wrangler, setPROJECT_ROOT, approved canonicalWRANGLER_BIN, and exactWRANGLER_VERSIONfirst. Branch onstatus:ok: continue to Step 4. The script already picked the account (single-account token, or one matching$CLOUDFLARE_ACCOUNT_ID).missing_tokenormissing_scope: ask the user to create a token at https://dash.cloudflare.com/profile/api-tokens → Custom token → permissionAccount.Turnstile:Edit→ include the target account in Account Resources. Do NOT direct them towrangler loginunless wrangler's OAuth scope includesAccount.Turnstile:Edit(varies by wrangler version). Offer two ways to provide the token without chat, cleanest first:- Export + relaunch (token enters neither chat nor shell history):
read -rsp 'Cloudflare API token: ' token; echo; export CLOUDFLARE_API_TOKEN="$token"; unset token, then restart the agent from that terminal. - Save to file (token in a user-only file):
umask 077; read -rsp 'Cloudflare API token: ' token; echo; printf '%s' "$token" > ~/.cf-turnstile-token; unset token, then load it without printing it. Do not ask the user to paste the API token into chat. When auth is established, re-runauth-probe.shand resume from Step 4.
- Export + relaunch (token enters neither chat nor shell history):
network_failure: the probe could not reachapi.cloudflare.com. Show the diagnostic (VPN/proxy, TLS interception, DNS). Do not treat this as a scope problem. Ask the user to fix connectivity, then re-runauth-probe.sh.upstream_failure: the API returned an unexpected response (http_codenon-4xx). Do not assume the token is bad. Show the code, ask the user to retry after a brief wait, and re-runauth-probe.sh.multiple_accounts: the token covers more than one account and$CLOUDFLARE_ACCOUNT_IDis unset. Present the numberedaccountslist. [wait for user] Then exportCLOUDFLARE_ACCOUNT_ID=<chosen>and re-runauth-probe.sh.account_mismatch:$CLOUDFLARE_ACCOUNT_IDis set but isn't one of the token's accounts. Show theaccountslist and ask the user to eitherunset CLOUDFLARE_ACCOUNT_IDor set it to one of those IDs.
-
Account selection. If
auth-probe.shreturnedokafter amultiple_accountsround-trip, this is already done. Otherwise the script picked the single account silently and you continue to Step 5. -
Domain. Always include
localhostand127.0.0.1. For production, scanpackage.jsonhomepage,wrangler.toml,README.md,AGENTS.md, git remote. Confirm: "I'll register forlocalhost,127.0.0.1, and<domain>. OK?" [wait for user] If no production domain is found, ask. Registering local and production domains on one widget is safe only when each backend deployment validates the exact frontend hostname returned by siteverify. Never includelocalhostor127.0.0.1in a production backend's expected-hostname allowlist. -
Codebase scan. Detect three things silently:
- Frontend framework (Next.js, Astro, SvelteKit, Hugo, vanilla, etc.) → drives the widget embed snippet.
- Backend handler location (Express route, Next.js API route, Rails controller, Workers fetch handler, Pages Function, etc.) → drives the siteverify snippet.
- Existing CAPTCHA (reCAPTCHA / hCaptcha) → switches Step 7 to migration mode.
-
Insertion plan. Show the candidate list with
[recommended]/[skip by default]markers; ask the user to confirm (numbers, "all", "recommended", or a list). Assign each chosen surface a stable action such assignup,login, orcontact. Actions must be 1–32 characters and contain only letters, numbers, underscores, or hyphens. Show the action-to-handler mapping for confirmation. [wait for user] If an existing CAPTCHA was detected, present a migration plan instead (see "Migrating from another CAPTCHA"). -
Widget creation. Prefer the approved Wrangler executable when its
turnstile widgetsubcommand is available:WRANGLER_WRITE_LOGS=false WRANGLER_LOG=log WRANGLER_LOG_SANITIZE=true \ "$WRANGLER_BIN" turnstile widget create "<name>" \ --domain <d1> --domain <d2> ... --mode managed --jsonIn a
set +xsubshell, capture the complete stdout JSON in one shell variable. ParseSITEKEYand a non-empty, non-whitespaceWIDGET_SECRETwithjq, then unset the response variable. If the approved Wrangler executable is missing or older than the Turnstile subcommand, use the same capture pattern withscripts/widget-create.sh --account-id <id> --name <name> --domains <list> --mode managed. Do not fall back after an authentication or API failure. Report only the sitekey. Never print the complete response or write the secret to disk except into the user's own secret store in Step 9. -
Wire the integration. State the contract: "I'll embed the widget at each chosen surface and add a canonical siteverify call inside its existing handler. The handler will require
success === true, the expected action, and an approved frontend hostname. The existing handler logic stays the same. The secret lives in your env asTURNSTILE_SECRET." Ask "yes" / "show". [wait for user] If "show", print unified diffs and ask again. Do NOT propose alternate behavior (mail delivery, custom backends).Canonical server-side siteverify (Node / fetch idiom; adapt to the detected backend):
const expectedAction = 'signup'; const expectedHostnames = new Set( (process.env.TURNSTILE_HOSTNAMES ?? '') .split(',') .map((hostname) => hostname.trim()) .filter(Boolean), ); if (typeof token !== 'string' || token.length === 0 || token.length > 2048 || expectedHostnames.size === 0) { return res.status(403).send('forbidden'); } let result; try { const r = await fetch('https://challenges.cloudflare.com/turnstile/v0/siteverify', { method: 'POST', headers: { 'Content-Type': 'application/x-www-form-urlencoded' }, signal: AbortSignal.timeout(10_000), body: new URLSearchParams({ secret: process.env.TURNSTILE_SECRET, response: token, // cf-turnstile-response from the request remoteip: clientIp, // X-Forwarded-For / req.ip / etc. }), }); if (!r.ok) throw new Error(`siteverify ${r.status}`); result = await r.json(); } catch (err) { // Network error, non-2xx, or non-JSON body from siteverify. Fail closed. return res.status(403).send('forbidden'); // adapt to your framework } if ( !result.success || result.action !== expectedAction || !expectedHostnames.has(result.hostname) ) { return res.status(403).send('forbidden'); } // existing handler logic runs here, unchangedSet
TURNSTILE_HOSTNAMESto the deployment-specific frontend hostnames. A production value must not includelocalhostor127.0.0.1. Write the secret into the user's existing secret store (.envfor Node/Rails/Python, standard"$WRANGLER_BIN" secret put TURNSTILE_SECRETfor a confirmed existing Worker, or the platform's secret manager). Before writing to any.env-style file, rungit check-ignore -q <path>from within a git working tree; if the file is not ignored (or the project is not under git), stop and ask the user to add it to.gitignoreor point you at the platform's secret manager. For Workers, resolve the exact name, configuration, and environment, then runsecret listwith the same target arguments immediately before the write. Never inline the secret or ask the user to paste it into chat. For an existing widget, follow the guarded retrieval flow below. -
Validation. For a newly created widget, set
EXPECTED_DOMAINS_JSONto the user-approved JSON array and run(set +x; printf '%s' "$WIDGET_SECRET" | scripts/validate.sh --sitekey "$SITEKEY" --account-id "$ACCOUNT_ID" --expected-domains "$EXPECTED_DOMAINS_JSON"), then unsetWIDGET_SECRET. The validator reads the secret only from standard input and never writes it to disk or command arguments. For an existing widget, the guarded flow validates the retrieved secret before storing it. In both flows, exercise the actual protected backend with a fresh real Turnstile token, verify one successful request, then verify that replaying the token is rejected. If the backend cannot be run, report destination validation as pending and do not claim end-to-end success. [wait for user if anything fails] -
Persist skill. Ask: "Save the Spin skill to
.claude/skills/turnstile-spin/SKILL.mdso I can reuse it
Truncated for display — read the full file on GitHub.
Related Skills
ai-job-search
44.4kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
