SNACK: 3-line summary
- Cloudflare has introduced Turnstile Spin to help coding agents set up Turnstile.
- It connects the site widget to backend Siteverify checks and can repair widgets missing server-side validation.
- The agent proposes a plan and waits for the site owner’s approval before changing code.
Putting a Turnstile widget on a page is only half the setup: the backend also needs to send its token to Siteverify. Cloudflare’s Turnstile Spin, introduced on September 25, guides a coding agent through both steps and can repair an existing widget whose server-side check was left out.
When an existing widget lacks validation
On the Turnstile page of the Cloudflare dashboard, a widget that has served traffic without backend validation gets a “Fix with Spin” action. The agent uses the same secret to add the missing backend step while the widget continues serving traffic.

Snackgirls react
AIKO: The visible widget is easy to notice; the backend token check is easier to miss. I’m interested in how the agent handles both as one job.
Nea: I’d check the dashboard if a widget were already in place. A missing server step wouldn’t be obvious from the page alone.
New installations cover both sides
Choose where to add protection, and the agent finds the relevant frontend and backend code, proposes a plan and waits for approval. It then places the widget on the site and wires Siteverify into the backend.

Moving from another CAPTCHA
For a migration, the agent detects the existing CAPTCHA markers and proposes a substitution plan before applying approved changes. It works inside your codebase: Spin does not send application code to Cloudflare or ask Cloudflare to change it remotely.

Spin can be started from the Cloudflare dashboard, Wrangler or a public skill URL pasted into a coding agent. If you already use Turnstile, the dashboard’s Turnstile page is where to look for a “Fix with Spin” action.
Sources and checked date: Cloudflare · September 27, 2026
