Guides ·
Stuck in a Cloudflare challenge loop on ChatGPT or Claude: causes and checks
You open chatgpt.com or claude.ai and get stuck on a “Just a moment…” spinner, or a “Verify you are human” checkbox that sends you straight back to where you started. That’s Cloudflare, which sits in front of both sites, running a human check. Cloudflare’s troubleshooting docs point to three kinds of cause: your browser can’t finish the challenge (an extension blocks the script, cookies or JavaScript are off, the clock is wrong), your exit IP changes partway through, or Cloudflare thinks the visit looks automated (a poor IP reputation, for example). You can check the first two yourself. Whether challenges are switched on, and for which traffic they’re stricter, is set by OpenAI and Anthropic in Cloudflare, and those settings aren’t public.
It’s a Cloudflare challenge page
Both sites are behind Cloudflare. On 1 October 2026 we requested both home pages with the command-line tool curl, and both answered 403 with a cf-mitigated: challenge header, which Cloudflare documents as the marker of a challenge page. curl can’t run JavaScript and is on Cloudflare’s list of unsupported environments, so this only shows that challenges are switched on, not that normal browsers get stopped.
Cloudflare’s challenge page docs describe three full-page challenge types, and the site picks one in its rules:
- Non-interactive challenge: the browser runs some JavaScript automatically, usually in under five seconds. You just wait.
- Managed Challenge: Cloudflare picks the kind of challenge from your browser’s signals. Most people are verified automatically and the page shows “Successful”; you’re asked to click only if Cloudflare sees non-human traits. Cloudflare recommends this type for most rules.
- Interactive challenge: you have to click to pass.
Then there’s Turnstile. It doesn’t block the whole page; it’s a small widget inside a form, such as login or sign-up. Usually it completes on its own, and sometimes it shows a checkbox. Cloudflare says Turnstile and challenge pages run on the same underlying system.
Once you pass, your browser stores a cf_clearance cookie, and requests that carry it aren’t challenged again. The site sets how long it lasts under Challenge Passage; the default is 30 minutes. According to Cloudflare’s clearance docs, sites that turn on a feature called Precursor keep evaluating the session, and if it looks suspicious you can be challenged again before the cookie expires.
What Cloudflare says it looks at
Cloudflare’s troubleshooting page says that when a real person is challenged unexpectedly, it’s usually because a security feature flagged the request. The sources it lists: a high-risk score for the IP; IP reputation, meaning the IP has a history of suspicious activity; traffic that looks automated; the site’s own WAF custom rules, which may target specific regions or user agents; and the Browser Integrity Check.
The automation check is the bot score: each request gets a score from 1 to 99, where 1 means Cloudflare is fairly sure it’s automated and 99 means it’s fairly sure it’s a person. The model’s inputs are request features, which Cloudflare lists as headers, session characteristics and browser signals; a request with no User-Agent gets a score of 1 straight away. The weights aren’t published.
Why it loops
Cloudflare’s challenge troubleshooting page says loops happen in specific cases where it detects strong bot signals, and lists these reasons:
- a poor or unstable network connection stops the challenge from completing;
- browser settings or extensions block the scripts the challenge needs, such as ad blockers, script blockers or anti-fingerprinting tools;
- the browser isn’t supported, or is out of date;
- JavaScript is disabled;
- detection errors: if bot-like behavior is suspected, you may be challenged over and over.
Other parts of the docs add a few more:
- You must allow JavaScript and cookies to pass any type of challenge (source).
- A wrong system clock can make the challenge time out or fail (Turnstile error codes 110600 and 200100). This means the computer’s time itself is off, not the time zone setting.
- If you receive a challenge on one IP and solve it from another, the solve isn’t valid and you may end up in a loop (source). Our reading: proxy software that switches routes or rotates exits mid-challenge could trigger this.
- Extensions that change the User-Agent or Web APIs like Canvas and WebGL aren’t supported, and device emulation or User-Agent overrides in developer tools also change the signals the challenge sees.
- Poor IP reputation is often seen with shared VPNs and corporate proxies.
What you can check
OpenAI’s help article Why can’t I log in to ChatGPT? has a section on Cloudflare verification loops (“Checking your browser…”), and it lines up with Cloudflare’s advice. From easiest to hardest:
- Try a private window, or a fresh browser profile, to rule out extensions and cached data.
- Turn off ad blockers, privacy tools and script blockers for now. OpenAI adds that cookie-consent overlays and cookie managers can also block the verification flow.
- Allow cookies (including third-party cookies) and JavaScript for chatgpt.com, openai.com and auth.openai.com.
- Update your browser and set the system clock to sync automatically. Cloudflare’s Turnstile troubleshooter runs a quick compatibility test.
- Switch off device emulation and User-Agent overrides in developer tools.
- Compare on another network, for example mobile data instead of office Wi-Fi. If that fixes it, the exit IP of your usual network is the likely cause. Both OpenAI and Cloudflare suggest turning off any VPN or proxy while you test.
- On managed networks at work or school, OpenAI says IT may need to allow Cloudflare challenges.
Checking your exit on IP Judge
To see whether the IP is involved, open “Browser and connection checks” on the home page or on the ChatGPT and Claude pages:
- “IP used for ChatGPT” and “IP used for Claude” come straight from chatgpt.com and claude.ai, so they’re the IPs Cloudflare sees. Look at their type and risk-list hits: an address flagged as proxy / VPN or listed for abuse is more likely to fall into what Cloudflare calls poor reputation. IP Judge checks public databases and lists, not Cloudflare’s own scores, so the two won’t always agree.
- Reload a few times and watch whether those two IPs change. An exit that keeps changing can run into the “challenged on one IP, solved on another” problem.
- The “Automation traces” row flags
navigator.webdriverset to true, a User-Agent that doesn’t match the platform, and headless browsers, all of which Cloudflare doesn’t support. - If Cloudflare WARP is on, you’ll get a separate note; see Cloudflare WARP and AI sites.
How IP types are decided is on the Method page and in Residential vs datacenter vs ISP IPs; how risk lists affect the score is in What is an IP purity score?
What only the site can change
Cloudflare is blunt about it in its docs: Cloudflare employees can’t remove a challenge you’re seeing; only the website owner can change the settings. Which challenge type to use, which regions or networks get stricter treatment, the bot score that triggers a challenge, and how long a pass lasts are all the site’s choices. The example rules in Cloudflare’s troubleshooting page even include blocking or challenging traffic from AWS and Google Cloud by ASN. OpenAI and Anthropic haven’t published their rules, so nobody outside can say for sure why a given IP gets challenged.
What the two help centers do say: besides the section above, OpenAI has a page explaining that “Sorry, you have been blocked” is an IP block by Cloudflare, possibly caused by a VPN or an IP from a high-risk area, and that temporary blocks may lift after a while. Claude’s help center has no article on Cloudflare challenges at the moment; its steps for login errors are to avoid using a VPN, disable browser extensions, and clear your cache and cookies.
If none of this helps, Cloudflare suggests noting the Ray ID from the challenge page and capturing a HAR file (with Preserve log turned on in developer tools) plus a console log, then sending them to the site. The Turnstile widget also has a Submit Feedback link. OpenAI likewise asks for a HAR file when you contact support.
FAQ
A private window works. What does that tell me?
The problem is most likely an extension, cookie or cached data in your usual profile. Turn extensions back on one at a time to find the one that blocks the challenge script. Cloudflare names ad blockers, script blockers, anti-fingerprinting tools, and extensions that change the User-Agent, Canvas or WebGL.
Is an endless spinner the same as “Sorry, you have been blocked”?
No. A spinner or checkbox is a challenge, which you can still pass. “Sorry, you have been blocked” is a block; per OpenAI it’s Cloudflare blocking the IP, and a clean browser profile won’t help. OpenAI’s suggestions are to turn off the VPN, connect from a different location, or wait.
Will a datacenter IP always get challenged?
Nothing public says so. Cloudflare lists IP reputation as one source and lets sites write rules by ASN, but whether OpenAI or Anthropic do that, and for which networks, isn’t public.
I passed, and a while later I’m challenged again. Is that normal?
Yes. cf_clearance expires: 30 minutes by default, and the site can change that. Sites using Precursor also keep evaluating the session. Clearing cookies removes it too.
I see a 401 in developer tools. Am I blocked?
Not necessarily. Cloudflare says the challenge page asks for a Private Access Token at /cdn-cgi/challenge-platform/…/pat/…. When your device, browser or network (including some VPNs) can’t provide one, that request returns 401; this is expected, and the page falls back to a standard challenge.
Which kind of IP do you have?
Check my IP for free