Turnstile

Turnstile handles bot protection, and it is the odd one out in this list. Marked platform managed, which means nobody at your end configures it, rotates a key or gets a support ticket when it breaks.

What platform managed means

Four of the five integrations wait on something an admin pastes in. Turnstile does not. It arrives configured, and the settings page records its state rather than asking for input.

Its job is narrow. Screening automated submissions on forms, so a queue of requests stays a queue of real requests.

Nothing about it appears in the day-to-day product. No report counts it, no dashboard shows it, and the first time most administrators read the word is on the integrations page.

Being invisible is the intended behaviour. A bot check that a real person notices has usually gone wrong, and there is nothing here for an employee to pass, fail or complain about.

What it needs from you

Nothing. There is no key to obtain, no secret to rotate and no channel to pick.

Compare that with the other four and the difference is the whole story. Slack needs a bot token. OpenAI needs an API key. Fireflies needs a key and a webhook secret. ZKTeco needs a physical terminal on your network. Turnstile needs an administrator to read one line and move on.

It guards sign-in as well. People sign in with a one-time code sent to their work email, so there is no password to leak, and Turnstile screens out automated attempts.

Questions people ask

Do we need a Cloudflare account?

No. Turnstile is marked platform managed, so no account, key or configuration is needed at your end.

What does sign-in look like?

No password at all. People enter a one-time code sent to their work email, with Turnstile screening out automated attempts.

Where are integration keys stored?

In your own database, masked once saved and never shown again in full. Turnstile itself needs no key from you.