wrangler / Cloudflare API: Authentication error [code: 10000]

The Cloudflare API rejected the token — it’s invalid, expired, missing permissions, or scoped to another account/zone.

Seen on: Cloudflare

Meaning

wrangler and API clients use CLOUDFLARE_API_TOKEN. Tokens need specific permissions (Workers Scripts:Edit, Account Settings:Read, Zone:Read…) on the right account and zones. Global API keys use different headers.

Common causes

  • Token missing a permission for the action
  • Token scoped to another account/zone
  • Expired/rolled token, or IP filtering on the token
  • Mixing API key and token headers

⚡ Quick fix

  1. Verify the token: /user/tokens/verify
  2. Recreate it from the “Edit Cloudflare Workers” template
  3. Set CLOUDFLARE_ACCOUNT_ID and the token in CI

Detailed fix by platform

Shell

  1. bash
    curl -s https://api.cloudflare.com/client/v4/user/tokens/verify -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" | jq
    npx wrangler whoami

How to diagnose

  1. Token — Status from verify
  2. Permissions — Account/zone resources and scopes
  3. CI — Env vars set?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.