Cloudflare Error 1020: Access Denied

A Cloudflare firewall/WAF custom rule blocked the request — the visitor’s IP, country, user agent or request pattern matched a block rule.

Seen on: Cloudflare

Meaning

The site owner (or a managed ruleset) configured Cloudflare to block matching traffic. Visitors can’t fix it themselves except by changing network/VPN; site owners find the rule in Security → Events using the Ray ID.

Common causes

  • Custom WAF rule blocking a country/IP/ASN
  • User agent or bot rules blocking scripts, curl or monitoring tools
  • Rate-limiting or managed rules triggered by request patterns
  • VPN/proxy IP with poor reputation

⚡ Quick fix

  1. Visitors: try another network/disable VPN, contact the site owner with the Ray ID
  2. Owners: Security → Events → filter by Ray ID to find the rule
  3. Add a skip/allow rule for legitimate traffic (your monitoring, APIs, webhooks)

Detailed fix by platform

Cloudflare

  1. Create a WAF custom rule with action “Skip” for trusted IPs or paths (e.g. /webhooks/*) and place it above blocking rules.

How to diagnose

  1. Ray ID — Which rule matched (Security → Events)?
  2. Traffic — Legitimate client being blocked?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.