The Tech Dragon / Knowledgebase / Tech Dragon Divi Turnstile Nexus / Configure Your Cloudflare Turnstile Site and Secret Keys
Knowledgebase // Tech Dragon Divi Turnstile Nexus

Configure Your Cloudflare Turnstile Site and Secret Keys

Product Knowledgebase View Plugin

Tech Dragon Divi Turnstile Nexus needs a Cloudflare Turnstile site key and secret key. This article explains what each key is for, where to enter it, and why saving credentials is different from verifying them.

Create a Cloudflare Turnstile widget

In Cloudflare, create a Turnstile widget for the site where Tech Dragon Divi Turnstile Nexus will run.

Cloudflare provides two credentials:

  • Site key — intended for browser-side Turnstile use.
  • Secret key — private credential used for server-side verification.

Make sure the Turnstile widget is allowed to run on the hostname used by your WordPress site.

Add the keys to WordPress

  1. In WordPress admin, open Settings → Tech Dragon Divi Turnstile Nexus.
  2. Locate the Cloudflare credentials section.
  3. Enter the Site key.
  4. Enter the Secret key.
  5. Save the settings.

Secret-key handling

The secret key is private. After you save it, Tech Dragon Divi Turnstile Nexus does not display the saved value back in your browser.

If the settings screen indicates that a secret is already configured, leaving the secret field blank while saving preserves the current stored secret.

Use the explicit secret-removal control only when you intend to remove the configured secret.

Saved does not mean verified

Tech Dragon Divi Turnstile Nexus treats these as separate states:

Saved:

The plugin has credential values stored.

Verified:

The current keys have passed the plugin's built-in Turnstile verification test.

This helps catch common setup problems—such as mismatched keys, an incorrect hostname, or a server that cannot reach Cloudflare—before you enable Turnstile across multiple forms.

Verify the configuration

After saving both credentials, use the Verify Turnstile connection section.

Complete the Turnstile challenge and submit the test.

A successful result confirms that:

  • Turnstile can load in the browser;
  • the site can obtain a valid Turnstile response;
  • your WordPress server can contact Cloudflare for verification; and
  • Cloudflare accepts the response for the expected site and Turnstile action.

If either credential changes, the previous verified state is no longer considered current and the configuration should be verified again.

If verification fails

Check:

  • the site key and secret key came from the same Turnstile widget;
  • the Cloudflare widget includes the correct hostname;
  • your site can connect to Cloudflare;
  • the credentials do not contain copied spaces or extra characters.

Do not publish, screenshot, or send the real secret key to support.

Why verification matters

You must verify the current setup before the bulk-enable option becomes available. This helps prevent you from enabling Turnstile across multiple forms with keys that have not been confirmed to work.

Next step

Continue with “Enable Turnstile on a Supported Divi Form.”

Fuel the Dragon