Cloudflare's doing TLS fingerprint binding right at the edge before your token even gets close to the verification layer. So yea you can have a totally legit clearance cookie but if your cipher suite ordering is off or your HTTP/2 SETTINGS frames don't match up perfectly, you're getting hit with a 403 - I've watched it happen over and over with standard request clients, even when everything else looks good on paper like headers and IP stuff. For anything you're automating in production, you basically need either an actual browser session running or some specialized TLS library that can nail the exact fingerprint from when the clearance was originally generated. And one more thing - if you're dealing with those dynamic sitekeys that SPAs love to inject, they're not gonna show up in the static html, so you'll probably need to intercept the /cdn-cgi/ calls at the network level to grab them. Anyway the response-reading triage approach you mentioned is solid