- Plugin Setup Guides

How to Get Cloudflare Turnstile Invisible Mode Keys (Site Key & Secret Key)

Cloudflare Turnstile is a free, privacy-friendly alternative to Google reCAPTCHA. In Invisible mode (sometimes called hidden mode), it verifies visitors completely in the background — with no checkbox and no interaction for the user at all — making it ideal for a frictionless checkout or login. To use it you need two values: a Site Key and a Secret Key. This guide shows how to create an Invisible-mode widget and get both keys from your Cloudflare account.

You’ll need a Cloudflare account (free). Your site does not have to use Cloudflare’s DNS or CDN — a free account is enough. (Prefer the version that shows a checkbox when needed? See our Turnstile Managed (checkbox) mode guide.)

How to Get Cloudflare Turnstile Invisible Mode Keys

Step 1 — Open Turnstile in your Cloudflare dashboard

  1. Sign in to your Cloudflare account at dash.cloudflare.com.
  2. Click Turnstile in the left-hand menu.
Turnstile menu item in the Cloudflare dashboard

Step 2 — Add a widget

  1. Click the Add Widget button.
Add Widget button in Cloudflare Turnstile

Step 3 — Name the widget and add your hostname

  1. Enter a widget name, then click Add Hostnames.
Setting the Turnstile widget name and adding hostnames
  1. Enter your domain name and click Add.
Adding a domain name to the Turnstile widget
  1. Click the final Add button to confirm the hostname.
Adding a domain name to the Turnstile widget

Step 4 — Set the widget mode to Invisible and create

  1. Change the widget mode to Invisible — this runs the verification silently with no checkbox or challenge shown to the user. Then click Create.
get_turnstile_checkbox_mode_site_key_Secret_Key_step_invisible_mode

Step 5 — Copy your Site Key and Secret Key

  1. Cloudflare now shows your Site Key and Secret Key. Copy both and paste them into your Turnstile plugin settings.
Cloudflare Turnstile Site Key and Secret Key shown after creation

Adding Turnstile to Your Store

Paste the Site Key and Secret Key into your Turnstile plugin settings, enable it, and save. In Invisible mode, Turnstile protects your login, registration, checkout, and other forms — including the WooCommerce Block Checkout — without ever interrupting genuine customers.

Frequently Asked Questions

What is Turnstile Invisible mode?

Invisible mode (also called hidden mode) verifies visitors entirely in the background with no checkbox and no challenge shown. The user completes your form normally while Turnstile validates them silently. It offers the smoothest experience, with no interaction required from genuine visitors.

What is the difference between Turnstile Managed and Invisible modes?

Managed mode shows an interactive checkbox challenge when a visitor looks suspicious, while Invisible mode never shows a challenge and verifies everyone silently in the background. Managed gives a visible signal that a check occurred; Invisible is completely frictionless. Both use the same Site Key and Secret Key setup.

Is Cloudflare Turnstile free?

Yes. Cloudflare Turnstile is free to use, and you do not need a paid Cloudflare plan. You only need a free Cloudflare account to create a widget and get your Site Key and Secret Key.

Do I need to use Cloudflare for my website to use Turnstile?

No. Your website does not have to use Cloudflare’s DNS, CDN, or proxy. Any site can use Turnstile with just a free Cloudflare account by adding your hostname when creating the widget.

What is the difference between the Site Key and Secret Key?

The Site Key is public and goes in your website’s front-end code to load Turnstile. The Secret Key is private, stays on your server, and is used to verify responses with Cloudflare. Never expose the Secret Key in public code.


This guide is provided by i13 Web Solution. Looking to add captcha protection to WooCommerce? See our reCAPTCHA for WooCommerce plugin. Need help with setup? Contact us — we answer every email.



Block bots and brute - force attacks

About Nikunj Gandhi

Read All Posts By Nikunj Gandhi