Skip to content

The browser check at sign-in

Why a small Cloudflare check appears under the sign-in buttons, what it looks at, and what to do when it does not load.

The sign-in and sign-up pages show a small Cloudflare Turnstile check under the Google and GitHub buttons. It tells automated scripts apart from people without a puzzle. Most of the time it finishes on its own in a second or two, and the buttons become active.

What it checks

Turnstile looks at signals from your browser, not at you. It never asks you to pick out traffic lights, and it stores nothing about your account. Avaloi sends the check's token to Cloudflare once, when you press a sign-in button, and Cloudflare answers whether the token is good. A token is good for one attempt. If sign-in fails, the check runs again before the next attempt.

When the check is required

Sign-up, the contact form, and the public support chat always need a passed check. Signing in with a password needs one only after several wrong tries for the same email address or from the same network, so most people never wait for it. When Avaloi asks, the sign-in button stays disabled until the check finishes. If the check service cannot be reached, Avaloi closes the step and asks you to try again in a moment instead of letting the request through.

When it does not load

The buttons stay disabled until the check finishes. If they stay disabled for more than a few seconds:

  1. Reload the page. A slow network can delay the script.
  2. Allow challenges.cloudflare.com in your content blocker or company proxy. The check loads from there.
  3. Try a private window. A browser extension that rewrites pages can stop the widget from rendering.

If the page shows "The browser check could not load", the script was blocked. Fix the block and reload.

Quick answers

Does the check track me across sites? No. Turnstile does not set tracking cookies or build a profile. See Cloudflare's own privacy notes for the service.

I use a screen reader. Is the check accessible? Yes. The widget is labelled "Browser check" and announces its state. It does not need a visual puzzle.

Why is there no check on my local copy? A developer running Avaloi locally without a Turnstile site key sees no widget, and the local API skips the check. Production always runs it: a production API without TURNSTILE_SECRET_KEY answers 503 on those steps and logs an error at boot, and never skips the check silently.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.