Turnstile error 110200 🟧 Cloudflare

Cloudflare Turnstile error 110200 / 300030 / 600010 (widget fails to load or verify)

The Turnstile widget couldn’t run or validate — wrong sitekey/domain, blocked scripts, or a client/network issue.

Seen on: Cloudflare

Meaning

110200 = domain not allowed for the sitekey; 110100/110110 = invalid sitekey; 300xxx/600xxx = client challenge failures (browser, extensions, network). Server-side, siteverify returns invalid-input-response or timeout-or-duplicate for reused/expired tokens.

Common causes

  • Hostname not added to the widget’s allowed domains (110200)
  • Wrong/test sitekey in production
  • Content-Security-Policy or ad-blocker blocking challenges.cloudflare.com
  • Token verified twice or after 300 s (timeout-or-duplicate)

⚡ Quick fix

  1. Add the domain in Turnstile widget settings
  2. Allow https://challenges.cloudflare.com in CSP script-src and frame-src
  3. Verify each token once on the server, promptly

Detailed fix by platform

PHP

  1. php
    $r = json_decode(file_get_contents('https://challenges.cloudflare.com/turnstile/v0/siteverify', false, stream_context_create(['http' => [
      'method' => 'POST', 'header' => 'Content-Type: application/x-www-form-urlencoded',
      'content' => http_build_query(['secret' => $secret, 'response' => $_POST['cf-turnstile-response'], 'remoteip' => $ip])]])), true);

How to diagnose

  1. Code — Error code family (110xxx config, 300/600xxx client)
  2. CSP — Console errors
  3. Server — error-codes from siteverify

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.