Cloudflare opens a direct line to browser teams
Cloudflare has launched a Browser Developer Program, aimed at giving browser development teams a formal channel to collaborate with Cloudflare on compatibility and security issues. Browser developers can apply to join the program through a dedicated application form.
The initiative addresses a tension Cloudflare has long had to manage: its bot-detection products, Challenges and Turnstile, are designed to stop malicious traffic, but the checks they perform can occasionally misfire for legitimate browsers, particularly those outside the mainstream. Cloudflare says the program is a way for browser teams to help ensure their users aren't caught in the crossfire.
What members get
Accepted browser developers will receive:
- A direct, two-way communication channel to Cloudflare engineers focused on browser-specific issues and feedback.
- Documented best practices for building and testing against Cloudflare Challenges and Turnstile.
- Access to a private community forum for discussions with Cloudflare engineers and other browser developers.
- Advance notice of updates or changes that could affect how their browser handles Cloudflare Challenges.
- Where applicable, integration into Cloudflare's testing pipeline so the browser is monitored against new releases.
Cloudflare says the program is a partnership: it will make its best effort to keep security products working across all browsers, and in return expects browser teams to share insights that help shape how those systems evolve. Participants are also expected to sign a program agreement and adhere to the community code of conduct. The company anticipates publishing clear browser requirements for running Cloudflare Challenges as an output of the collaboration.
Why browser diversity matters
Cloudflare's challenge traffic is dominated by a handful of browsers — Chrome leads at 68.0%, followed by Safari at 8.7%, Firefox at 6.3%, Edge at 4.8%, and Opera at 6.2%.

That leaves a long tail of browsers that collectively serve a significant share of traffic, each individually below 1%. This group includes experimental and emerging browsers, privacy-focused options like DuckDuckGo, embedded browsers within social media apps such as Facebook, Instagram, and TikTok, WebViews in mobile apps, gaming and VR browsers (including Oculus and console browsers), and even browsers on smart devices like classroom displays and appliances.
Supporting that range is not straightforward, Cloudflare notes. Many of these environments deviate from assumptions baked into mainstream browser behavior: some lack full support for modern Web APIs, others enforce stricter data privacy policies, and some run in settings where Cloudflare's verification script may be slowed or blocked. None of these browsers are malicious, but their behaviors can fall outside the patterns Cloudflare's systems expect, leading to failed or disrupted challenge flows.
The engineering trade-off is a fine one. Too rigid a model, tuned to the top five browsers, risks excluding legitimate users on less conventional platforms. Too lenient a standard expands the attack surface for abuse. Cloudflare says it can neither overfit to the majority nor treat every client as equally capable or trustworthy — and the Browser Developer Program is one mechanism for closing that gap by working with the teams that build those alternative environments.
Open to all
The program is free and open to any browser developer, regardless of project size or lifecycle stage. Cloudflare says the ultimate beneficiaries are end users: browser teams that participate will help shape solutions that balance business security needs with the many ways people actually reach the Internet. For end users on existing browsers, Cloudflare will continue to update its supported browser list based on program insights and says it is committed to making its challenge interstitial pages and Turnstile provide clear, actionable UI for error and failed states.



