cf-mitigated: challenge 🟧 Cloudflare

API/app requests get 403 with cf-mitigated: challenge (Bot Fight Mode / challenge on non-browser clients)

Cloudflare is answering API calls, webhooks or mobile-app requests with a challenge page (HTML 403) because bot protection treats them as bots.

Seen on: Cloudflare

Meaning

Non-browser clients can’t solve challenges, so they receive a 403 with header cf-mitigated: challenge and an HTML body — your app then fails to parse JSON. Bot Fight Mode can’t be skipped per path on free plans; WAF skip rules work for Super Bot Fight Mode and custom rules.

Common causes

  • Bot Fight Mode or Super Bot Fight Mode enabled
  • Security Level/Under Attack challenging all traffic
  • WAF rule with Managed Challenge on API paths
  • Webhook providers’ IPs challenged

⚡ Quick fix

  1. Detect cf-mitigated header in clients
  2. Create WAF skip rules for API/webhook paths (or disable Bot Fight Mode)
  3. Serve the API from a hostname without challenges

Detailed fix by platform

Cloudflare

  1. # Security → WAF → Custom rules: (http.request.uri.path wildcard "/api/*") → Skip: all Super Bot Fight Mode rules, Security Level

Shell

  1. curl -sI https://example.com/api/health | grep -i cf-mitigated

How to diagnose

  1. Header — cf-mitigated present?
  2. Events — Security Events for the Ray ID
  3. Settings — Bot Fight Mode status

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.