Environment access & security

QA.tech + Cloudflare WAF & Turnstile

This setup covers Cloudflare-protected applications: configuration to get QA.tech's agents past Cloudflare WAF blocking and Turnstile challenges so tests can run, while your protection stays in place for everyone else.

Set it up

Connecting Cloudflare WAF & Turnstile

  1. 01

    Confirm whether the WAF, bot management, or Turnstile is what stops the run.

  2. 02

    Add the matching Cloudflare rule or exemption for QA.tech's test traffic.

  3. 03

    Re-run a login flow to verify the challenge no longer blocks the agent.

Full reference in the QA.tech docs.

Where teams use this

Cloudflare WAF & Turnstile in practice

Turnstile on the login page is the classic blocker, which makes this a prerequisite for authentication flows on Cloudflare-fronted apps. It comes up most in fintech and e-commerce, where edge protection is non-negotiable and the checkout still has to be tested. The same setup applies to any staging or preview environments behind protection.

FAQ

Common questions

Does this bypass Turnstile for real users?
No. It only clears the path for QA.tech's test traffic.

Related integrations

← Previous

Vercel Firewall

Next →

IP Access Control

Your team moves fast. Can your testing keep up?

QA.tech agents test your product autonomously, so moving fast never means shipping broken. See how it works in a 30-minute demo.

Get a demo