---
title: "How to Add Cloudflare Turnstile CAPTCHA in WordPress Form?"
url: https://nexterwp.com/docs/add-cloudflare-turnstile-captcha-in-wordpress-form/
date: 2025-04-17
modified: 2026-09-13
lang: en
author: "Aditya Sharma"
description: "Cloudflare Turnstile checks that a visitor is human, usually without making them solve a puzzle. The Form block in Nexter Blocks Pro adds Turnstile through its Security Code field. For..."
image: https://nexterwp.com/wp-content/uploads/2025/04/add-cloudflare-turnstile-captcha-in-wordpress-form-1024x519.jpg
word_count: 269
---

# How to Add Cloudflare Turnstile CAPTCHA in WordPress Form?

## Key Takeaways

- Nexter Blocks Form block adds Cloudflare Turnstile CAPTCHA to a WordPress form, and Cloudflare Turnstile silently verifies users without click boxes or puzzles.
- Cloudflare Turnstile setup requires a Site Key and Secret Key from Cloudflare Turnstile, where the user goes to Turnstile, clicks Add Widget, adds a widget name, adds hostnames, and creates the widget.
- Form block security uses the Security Code field and the Security Options dropdown set to Cloudflare, then the Site Key and Secret Key are entered in the Cloudflare Client Key and Cloudflare Secret Key fields.

Cloudflare Turnstile checks that a visitor is human, usually without making them solve a puzzle.

The Form block in Nexter Blocks Pro adds Turnstile through its Security Code field.

*For every Form setting in one place, see the [Form block guide](https://nexterwp.com/docs/add-a-form-in-wordpress/).*

[LIVE BLOCK LINK](https://nexterwp.com/nexter-blocks/blocks/)

## Before You Start

- **Edition:** **Pro** — The Security Code field needs Nexter Blocks Pro.- **Block to enable:** Form, switched on under **Nexter > Blocks** in your WordPress dashboard.- **A Turnstile Site Key and Secret Key:** add a Turnstile widget for your domain in the Cloudflare dashboard. See [Cloudflare's Turnstile get-started guide](https://developers.cloudflare.com/turnstile/get-started/).

## Steps

- Add the **Form** block and set up your fields.

- Click the **+** inside the form and add the **Security Code** field above the Submit button.

- With Security Code selected, set **Security Options** to **Cloudflare**.

- Paste the Site Key into **Cloudflare Client Key** and the Secret Key into **Cloudflare Secret Key**. Save.

![The Security Code field with Cloudflare Client Key and Cloudflare Secret Key](https://nexterwp.com/wp-content/uploads/2026/09/form-cloudflare.webp)

## How It Behaves

- The Turnstile widget loads with the form. Most visitors pass without clicking anything.- On submit, the token is checked with Cloudflare using your Secret Key. Only verified submissions run the form actions.

## Limitations

- **Pro only.**- The keys are set per form. Add them again for each form that uses Turnstile.- The widget only works on the hostnames you added to it in Cloudflare.

## Troubleshooting

### Visitors see "Cloudflare Turnstile validation failed"

The Secret Key does not match the Site Key, or your domain is missing from the widget's hostnames in Cloudflare.

### The widget does not appear

Check the Site Key is in Cloudflare Client Key and clear any page cache.

## Related Docs

- [Form block: all settings](https://nexterwp.com/docs/add-a-form-in-wordpress/)- [Add Google reCAPTCHA to a form](https://nexterwp.com/docs/add-google-recaptcha-in-wordpress-form/)- [Make a GDPR compliant form](https://nexterwp.com/docs/make-a-gdpr-compliant-form-in-wordpress/)