What is the cf_clearance cookie?
This cookie stores proof that a visitor has successfully passed a Cloudflare bot or security challenge.
Table of Contents
About cf_clearance
| Vendor | Cloudflare |
|---|---|
| Category Category The functional category of the technology, such as Web Analytics or Social Media. Learn more | Advertising & Paid Media |
| Consent Category Consent Category The consent category this cookie most commonly falls under across sites we scan, normalized into four standard categories. Learn more | Strictly Necessary |
| Prevalence | Very Common |
| Popularity Popularity Popularity is calculated from our dataset of 4.5B+ cookies analyzed across hundreds of millions of web pages. Learn more | Found on 16.9% of scanned pages |
| Expiration Type | Timestamp |
| Party Type Party Type Whether the cookie is first-party or third-party. Learn more | Mixed |
| Risk Level Risk Level Rates how sensitive the data stored by this cookie is (High, Medium, or Low) based on data classification and distribution. Learn more | Low |
| Vendor Privacy Policy | https://www.cloudflare.com/privacypolicy/ |
| Vendor Website | https://www.cloudflare.com/ |
What is the purpose of cf_clearance?
The cf_clearance cookie is set by Cloudflare after a user successfully completes a security challenge, such as a Turnstile check, a managed web application firewall (WAF) challenge, or a background JavaScript detection. It securely stores proof of the successful challenge, along with the clearance level achieved and a timestamp. By persisting this clearance state in the browser, Cloudflare allows the verified visitor to seamlessly access other protected pages on the website without being repeatedly prompted to solve security challenges for the duration of the clearance period. The clearance period is configurable by the site owner via the Challenge Passage setting, with a default lifetime of 30 minutes (Cloudflare recommends a value between 15 and 45 minutes). The cookie is cryptographically tied to the visitor's session and device to prevent attackers from reusing or sharing a single valid clearance token across multiple clients.
What are the Privacy Risks of cf_clearance?
Risk Level: Low
The cookie is strictly necessary for security and site functionality. It does not contain any Personally Identifiable Information (PII) or unique tracking identifiers used for cross-site behavioral profiling. Instead, it holds encrypted proof that a user passed a security check, which is cryptographically bound to the user's session to prevent abuse.
How to Remove cf_clearance from a Website
Website administrators cannot independently remove the cf_clearance cookie while continuing to use Cloudflare's bot management and security challenges. To remove the cookie, an administrator must log into the Cloudflare dashboard and disable features that issue challenges, such as WAF custom rules, Bot Management, and Turnstile widgets. Disabling these features will remove the cookie but will significantly degrade the site's automated threat defenses and expose it to malicious bot traffic or DDoS attacks.