1. The box is a formality
Cloudflare's check runs hidden tests in the background: small puzzles for the computer to solve, probes of what the browser can do, checks for browser quirks, and a learning model. It picks the checkbox or a silent check based on "visitor risk level." It can mark a finished check invalid if it spots bot-like signals. A newer system, called Precursor and launched 13 July 2026, watches mouse, typing and focus for the whole visit, and can cancel a pass midway.
Cloudflare Turnstile docs; Cloudflare blog, 2022-09-28 and 2026-07-13. High confidence.
2. Remote-controlled browsers aren't supported
Cloudflare says browsers driven by automation tools such as Selenium, Puppeteer, Playwright and Cypress "are not supported for solving production challenges." Browsers built into other apps "may have limited functionality." Cloudflare's own hosted browser "will always be identified as a bot." When it sees "strong bot signals," the check loops. That loop is what you saw.
Cloudflare supported-browsers and troubleshooting pages, 2026-08-18 and 2026-09-08. High confidence.
3. A browser that lies about itself fails
Cloudflare says changing the browser's identity during a visit makes the check fail. Another company's app browser, Orca, hit the same wall and published the fix on 5 September 2026. Their browser claimed to be plain Chrome but didn't send the extra details real Chrome sends, so it "reads as a spoof." Their fix was to go back to the browser's honest name and stop leaving the remote-control connection open all the time. T3 Code found the same thing on 12 September 2026: even just dropping the word "Electron" from the name broke the check. The Claude pane does exactly that.
Cloudflare mobile-implementation docs; github.com/stablyai/orca pull 18749; github.com/pingdotgg/t3code pull 7110. High confidence for those apps; inferred for the Claude pane.
4. Your connection counts too
Cloudflare's own fix list says to turn off VPNs and proxies and try another network. One Claude Code bug report, from 4 September 2026, shows Chrome and the Claude desktop app looping on a cloud-server IP address while Safari passed on the same one. Cloudflare doesn't publish how much the address matters.
Cloudflare challenge-solve troubleshooting; github.com/anthropics/claude-code issue 92094. Medium confidence.
5. You can't carry a pass over
Passing gives you a cookie called cf_clearance. Cloudflare says it's "securely tied to the specific visitor and device it was issued to, preventing reuse across machines." It lasts as long as the site sets: 30 minutes by default, and 15 to 45 minutes is recommended. Passing in Chrome doesn't carry over to the Claude pane, or the other way round. Cloudflare doesn't say exactly what the cookie is tied to.
Cloudflare clearance, cookies and Challenge Passage docs. High confidence on the quote, low on what it's tied to.
6. On Windows the pane can crash
At least six Claude Code bug reports say that opening a Cloudflare-checked page in the desktop pane on Windows crashes the whole app. Users traced it to a Windows security rule that blocks a graphics file Cloudflare's check loads. The main report was marked fixed on 15 September 2026 with no explanation. You're on Windows 11. Today's visit didn't crash, but no challenge appeared either.
github.com/anthropics/claude-code issues 80444, 81341, 90461, 90732. High confidence on the trigger; the fix is unconfirmed.