Skip to content
Blog

Cloudflare Bot Fight Mode vs. Bot Management

What Cloudflare's Bot Fight Mode, Super Bot Fight Mode, and Enterprise Bot Management each do, where each one stops, and when to move to the next level.

Frederick Jahn
Published
Cloudflare Bot Fight Mode vs. Bot Management

Cloudflare sells three bot products that are easy to confuse: Bot Fight Mode, Super Bot Fight Mode, and Bot Management. They differ in what they detect, what you can configure, and which plan you need. This guide summarizes each one from Cloudflare's documentation, then covers the limits that usually push a site from one level to the next.

Three products, three plan levels

  • Bot Fight Mode is on the Free plan.
  • Super Bot Fight Mode is included with the Pro, Business, and Enterprise plans. An Enterprise zone without the Bot Management add-on gets the Business version.
  • Bot Management is a paid Enterprise add-on that your Cloudflare account team enables. Zones with Bot Management do not see Bot Fight Mode or Super Bot Fight Mode.

What Bot Fight Mode does

Bot Fight Mode identifies traffic that matches patterns of known bots and issues computationally expensive challenges to it. Cloudflare's Free plan page says it detects simple bots from cloud hosting providers and headless browsers.

There is almost nothing to configure. Bot Fight Mode applies to the whole domain, with no way to limit it to certain endpoints. You cannot customize it, skip it, or bypass it with WAF custom rules or Page Rules, because it runs outside the Ruleset Engine. It does not trigger when an IP Access rule matches first. Challenged requests appear in Security Analytics with the label "Bot Fight Mode".

What Super Bot Fight Mode adds

Super Bot Fight Mode lets you choose an action per bot category, protect static resources, and see bot analytics. It runs after your WAF custom rules, so you can exempt traffic with a custom rule that uses the Skip action.

What you can act on depends on the plan. On Pro, you can allow, block, or challenge the "Definitely automated" and "Verified bots" groups, and analytics are limited to a Bot Report. Blocking or challenging "Likely automated" traffic is not available on Pro. Business and Enterprise add the "Likely automated" group, detection of many sophisticated bots, and dedicated Bot Analytics. Cloudflare suggests considering Bot Management when the Bot Report shows a double-digit percentage of automated traffic.

What Enterprise Bot Management adds

Bot Management gives every request a bot score from 1 to 99. A score of 1 means automated, 2 to 29 means likely automated, and 30 to 99 means likely human. Verified bots are a separate group. The detection engines that produce the score (heuristics, machine learning, and JavaScript Detections) apply only to Bot Management.

You act on the score in WAF custom rules or Workers, so a rule can target a single path, method, or IP range instead of the whole domain. Bot Management also exposes JA3 and JA4 fingerprints, bot tags, and detection IDs for rules and logs.

Side-by-side comparison

QuestionBot Fight ModeSuper Bot Fight ModeBot Management
PlanFreePro, Business, EnterpriseEnterprise add-on
DetectsSimple bots, headless browsersPro: simple bots, headless browsers. Business and up: many sophisticated botsScored 1 to 99 on every request
ActionComputationally expensive challengeAllow, block, or challenge per bot categoryAny WAF custom rule or Worker action
ScopeWhole domainWhole domain, with Skip exceptionsAny rule expression: path, IP, and more
ExceptionsIP Access rules onlyWAF custom rules with SkipWritten into your own rules
AnalyticsSecurity Analytics eventsBot Report (Pro) or Bot Analytics (Business and up)Bot Analytics, score, and detection IDs

The challenge script Bot Fight Mode injects

Bot Fight Mode turns on JavaScript Detections, and you cannot disable it while Bot Fight Mode is on. Cloudflare injects an invisible JavaScript snippet into HTML page responses. It is not added to AJAX responses. The script loads from /cdn-cgi/challenge-platform/, and a passing browser receives a cf_clearance cookie. A result lasts 15 minutes, and Cloudflare injects the code again before it expires.

Your Content Security Policy must allow /cdn-cgi/challenge-platform/. Cloudflare adds nonces it parses from the CSP response header, but nonces set in a <meta> tag are not supported. On the free and Pro tiers the detection runs, but you cannot enforce on its result: a rule on cf.bot_management.js_detection.passed requires Bot Management. The first request from a new visitor also carries no JavaScript Detections result yet.

Limits to plan around

  • Whole-domain scope. Bot Fight Mode cannot be limited to certain paths, so it applies to your API and login routes as much as to your marketing pages.
  • API and mobile app traffic. Cloudflare warns that Bot Fight Mode may challenge API or mobile app traffic. A native app or a server-to-server client cannot solve a browser challenge.
  • No bypass. Because WAF custom rules and Page Rules cannot skip it, the only exception mechanism is an IP Access rule. That rarely helps with partners or monitoring services whose IP addresses change.
  • Upgrade path. To move to Super Bot Fight Mode you have to turn Bot Fight Mode off first.

If legitimate users get stuck repeating a challenge, see how to fix bot challenge loops.

When to move beyond Bot Fight Mode

Move to Super Bot Fight Mode when you need exceptions for APIs, partners, or monitoring, or when you want to block rather than only challenge. Move to Bot Management when you need per-route rules, a per-request score, or enforcement on JavaScript Detections.

Some teams instead want to know whether a specialist product catches bots that their Cloudflare configuration misses. Centinel vs. Cloudflare compares the two, including Centinel's September 2026 benchmark observations, and Centinel vs. CDN and WAF bot protection explains how to test whether another layer is worth it. The bot management overview lists the requirements to check, and the bot management software comparison covers other vendors.