I can open a Cloudflare protected site in Chrome without problems. In the first GET request, I can see in devtools the complete response being returned with a 200 status.
But if I copy this first request as cURL in devtools, import into Postman and execute it, I will get a response containing claudflare's captcha and a 403 status.
I'd just like to understand - how does Cloudflare knows the postman request doesn't come from a browser? Even with the same IP, the same country, the same user-agent, and all headers.