# Bot protection (Turnstile)

Defend forms against bot submissions with Cloudflare Turnstile.

## Bot protection (Turnstile)

Cloudflare Turnstile checks share-link submissions for you. It is always on for free forms and yours to control on Pro and Business. Most respondents never see it.

<h2 id="how-it-works">How it works</h2>
<p>
  When a respondent presses submit, formbase asks Turnstile for a token and verifies it on the server before the submission is written. The
  check normally runs silently; if it cannot resolve on its own, a small dialog appears and asks the respondent to confirm. There are no
  image puzzles. The dialog follows your form's theme and language.
</p>
<p>
  The check runs on the submit, not on page load, so it never delays the form opening. A submission that fails verification is rejected and
  the respondent is asked to try again.
</p>

> ℹ️ **Requests are not gated**
> <p>
>     Bot protection applies to <a href="/sharing-publishing/sharing-embedding">share links</a> only. A{' '}
>     <a href="/requests/overview">request</a> link already names one recipient and authorises one completion, so it skips Turnstile — as it
>     skips the sign-in requirement and response limits.
>   </p>

<h2 id="formbase-hosted">formbase-hosted forms</h2>
<p>
  For forms shared on <code>form.formbase.so</code> links, bot protection is built in — no setup, no keys, nothing to configure. formbase
  manages Turnstile for you.
</p>
<p>
  On the <strong>Free</strong> plan (and for guest forms), bot protection is <strong>always on and can't be turned off</strong>. The{' '}
  <strong>Bot protection (Turnstile)</strong> switch under <strong>Form settings → Access</strong> stays locked on.
</p>
<p>
  On a <strong>Pro or Business plan</strong>, the switch is yours. Turn bot protection on or off per form from{' '}
  <strong>Form settings → Access → Bot protection (Turnstile)</strong>.
</p>
<p>
  If your paid plan lapses, your own setting keeps applying for the first 30 days. From day 30 bot protection locks back on — the Free-plan
  default. See <a href="/subscription-billing/upgrading-downgrading#grace-period">upgrading &amp; downgrading</a>.
</p>

<h2 id="custom-domains">Custom domain forms (BYOK)</h2>
<p>
  Custom domains require a <strong>Pro or Business plan</strong>. If you share forms on a custom domain (for example{' '}
  <code>fill.yourdomain.com</code>), you bring your own Turnstile keys (BYOK): Cloudflare ties a Turnstile widget to specific hostnames, and
  formbase's own key only covers formbase.so.
</p>

dash.cloudflare.com</a> if you don\'t have one.',
    },
    {
      title: 'Create a Turnstile widget',
      description:
        'In <a href="https://dash.cloudflare.com/?to=/:account/turnstile" target="_blank" rel="noopener noreferrer">Turnstile</a>, add your custom domain hostnames to the allowed list. One widget with hostname validation disabled covers every domain in the workspace.',
    },
    {
      title: 'Copy your keys',
      description: 'Copy the <strong>Site key</strong> and <strong>Secret key</strong>.',
    },
    {
      title: 'Paste the keys in formbase',
      description:
        'Open <strong>Domains</strong> from the sidebar, find the <strong>Bot Protection</strong> card, paste both keys, and save. The keys are per workspace, not per form.',
    },
    {
      title: 'Turn it on per form',
      description: 'Switch bot protection on for individual forms in <strong>Form settings → Access</strong>.',
    },
  ]}
/>

<p>
  Until the keys are saved, the switch on a custom-domain form is disabled and shows as off, because no challenge can run there. What
  happens to submissions on that branded URL depends on the plan:
</p>

> ℹ️ **No custom domains? Skip this.**
> <p>If all your forms use the default formbase share links, you do not need Turnstile keys. Bot protection works automatically.</p>

<h2 id="submission-limits">Submission limits</h2>
<p>
  Turnstile does not change your monthly allowance — 1,000 submissions a month on Free, 50,000 on Pro and Business. See{' '}
  <a href="/subscription-billing/limits-quotas">limits &amp; quotas</a>.
</p>

<h2 id="layered-defense">Layered defense strategies</h2>
<p>
  Turnstile is one layer. Combine it with the access controls in <a href="/building-forms/form-settings#access">Form settings → Access</a>:
</p>

> ⚠️ **No protection is perfect**
> <p>
>     Sophisticated bots can bypass any CAPTCHA. For high-value forms, layer defenses: Turnstile, an authentication gate,{' '}
>     <a href="/building-forms/email-verification">email verification</a>, and a look at the submissions before you act on them.
>   </p>

<h2 id="next-steps">Next steps</h2>
<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [Submission inbox](/submissions-analytics/submission-inbox) — Review responses after bot protection is in place
  - [Share links](/sharing-publishing/sharing-embedding) — Create and manage share link URLs
  - [Custom domains](/branding-domains/custom-domains) — Set up branded form URLs
  - [Plans & pricing](/subscription-billing/plans-pricing) — Compare Free, Pro, and Business
</div>
