wrangler / Cloudflare API: Authentication error [code: 10000]
The Cloudflare API rejected the token — it’s invalid, expired, missing permissions, or scoped to another account/zone.
Seen on:
Cloudflare
Meaning
wrangler and API clients use CLOUDFLARE_API_TOKEN. Tokens need specific permissions (Workers Scripts:Edit, Account Settings:Read, Zone:Read…) on the right account and zones. Global API keys use different headers.
Common causes
- Token missing a permission for the action
- Token scoped to another account/zone
- Expired/rolled token, or IP filtering on the token
- Mixing API key and token headers
⚡ Quick fix
- Verify the token: /user/tokens/verify
- Recreate it from the “Edit Cloudflare Workers” template
- Set CLOUDFLARE_ACCOUNT_ID and the token in CI
Detailed fix by platform
Shell
- bash
curl -s https://api.cloudflare.com/client/v4/user/tokens/verify -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" | jq npx wrangler whoami
How to diagnose
- Token — Status from verify
- Permissions — Account/zone resources and scopes
- CI — Env vars set?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Cloudflare
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026