Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

cf_clearance Cookie by Cloudflare – What It Does

cf_clearance is a cookie set by Cloudflare to confirm that a visitor has successfully passed the network's anti-bot or security checks. It is used across a very large number of websites running on Cloudflare's infrastructure, including Romanian sites. It is not used for advertising or tracking, only for the site's security system to function properly.

Name
cf_clearance
Provider
Cloudflare
Category
Necessary
Type
HTTP cookie
Lifetime
30 minutes
Consent
No, but it must be listed in the cookie policy
Prevalence
found on 4 Romanian sites scanned by CookieFix

What is the cf_clearance cookie?

cf_clearance is an HTTP cookie set by Cloudflare, the web infrastructure and security provider used by a very large number of websites, including Romanian ones. It appears in the browser when a visitor completes a Cloudflare-enforced security check, such as a "Verify you are human" challenge (Cloudflare Challenge/Turnstile) or an automatic JavaScript check triggered by the site's security rules.

Once set, the cookie tells Cloudflare that this browser has already been validated, so the visitor does not have to repeat the check on every page during the cookie's validity period.

What data it stores

The cookie stores an encrypted token, generated and interpreted exclusively by Cloudflare, attesting to the result of the security check (browser, IP address, behavior-related signals). The exact value format is not publicly documented and may change over time, being fully controlled by Cloudflare.

The value is sent to the Cloudflare network with every request to the protected domain, so the security system recognizes the already-validated session. It is not shared with other third-party services.

What it is used for

  • Confirms a visitor has already passed an anti-bot or security check
  • Avoids showing repeated "challenge" pages on every navigation
  • Helps filter automated traffic (bots, scrapers) from legitimate human traffic
  • Supports the operation of Cloudflare's web application firewall (WAF) and DDoS protection for the site

Does it require consent?

cf_clearance is, in practice, classified as a strictly necessary cookie, since it is generated directly by the site's security infrastructure and has no analytics, marketing, or personalization purpose. Under Article 5(3) of the ePrivacy Directive, cookies strictly necessary for the functioning and security of a service explicitly requested by the user do not require prior consent.

Even though it does not require consent, the site owner should still list it in the cookie policy, with a clear purpose and provider (Cloudflare), to meet GDPR transparency obligations.

How to block or delete cf_clearance

A visitor can delete or block cf_clearance from the browser's settings (per-site cookies/history) or by using private/incognito mode. Blocking it may cause Cloudflare's security checks to reappear on every visit, or even restrict access if the site enforces strict protection rules.

For site owners: since this is a strictly necessary security cookie, it should not be included among scripts blocked pending consent. A consent management platform like CookieFix can help classify this cookie correctly as "necessary" in the consent banner, automatically blocking only statistics and marketing scripts without interfering with Cloudflare's protection of the site.

Frequently asked questions

It's a cookie set by Cloudflare confirming that a visitor has already passed a security or anti-bot check on the site.

No, it's considered strictly necessary since it supports site security, but it should still be listed in the cookie policy.

Typically around 30 minutes, after which the browser may be challenged again by Cloudflare.

You will most likely have to go through a Cloudflare security check again on your next visit to the site.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.