Cloudflare Error 1020: Access Denied
A Cloudflare firewall/WAF custom rule blocked the request — the visitor’s IP, country, user agent or request pattern matched a block rule.
Seen on:
Cloudflare
Meaning
The site owner (or a managed ruleset) configured Cloudflare to block matching traffic. Visitors can’t fix it themselves except by changing network/VPN; site owners find the rule in Security → Events using the Ray ID.
Common causes
- Custom WAF rule blocking a country/IP/ASN
- User agent or bot rules blocking scripts, curl or monitoring tools
- Rate-limiting or managed rules triggered by request patterns
- VPN/proxy IP with poor reputation
⚡ Quick fix
- Visitors: try another network/disable VPN, contact the site owner with the Ray ID
- Owners: Security → Events → filter by Ray ID to find the rule
- Add a skip/allow rule for legitimate traffic (your monitoring, APIs, webhooks)
Detailed fix by platform
Cloudflare
- Create a WAF custom rule with action “Skip” for trusted IPs or paths (e.g.
/webhooks/*) and place it above blocking rules.
How to diagnose
- Ray ID — Which rule matched (Security → Events)?
- Traffic — Legitimate client being blocked?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026