[metadata]
algolia_content_type: Troubleshooting
algolia_product_filter: Cloudflare Fundamentals
description: Resolve common Cloudflare API token issues including verification failures, incorrect permissions, and syntax errors.
generator: Astro v7.1.4
generator: Nimbus v0.2.2
image: https://developers.cloudflare.com/og-docs.png
og:description: Resolve common Cloudflare API token issues including verification failures, incorrect permissions, and syntax errors.
og:image: https://developers.cloudflare.com/og-docs.png
og:locale: en
og:site_name: Cloudflare Docs
og:title: Troubleshooting
og:title: Troubleshooting · Cloudflare Fundamentals docs
og:type: article
og:url: https://developers.cloudflare.com/fundamentals/api/troubleshooting/
pcx_additional_products: Cloudflare Fundamentals,API documentation
pcx_content_group: Core platform
pcx_content_type: Troubleshooting
pcx_last_modified: 109
pcx_product: Cloudflare Fundamentals
twitter:card: summary_large_image
twitter:image: https://developers.cloudflare.com/og-docs.png
twitter:site: @cloudflare
viewport: width=device-width, initial-scale=1

[canonical-links]
https://developers.cloudflare.com/fundamentals/api/troubleshooting/

[document-links]
/
/cdn-cgi/ endpoint: /fundamentals/reference/cdn-cgi-endpoint/
AI Security: https://www.cloudflare.com/solutions/ai-security/
API deprecations: /fundamentals/api/reference/deprecations/
API token permissions: /fundamentals/api/reference/permissions/
API token template URLs: /fundamentals/api/how-to/account-owned-token-template/
API token templates: /fundamentals/api/reference/template/
API: /api/
About: https://www.cloudflare.com/about/
Account API tokens: /fundamentals/api/get-started/account-owned-tokens/
Account and domain management best practices: /fundamentals/reference/best-practices/
Account recovery: /fundamentals/user-profiles/account-recovery/
Accounts, zones, and profiles: /fundamentals/concepts/accounts-and-zones/
Add abuse contact: /fundamentals/account/account-security/abuse-contact/
Add multiple sites via automation: /fundamentals/manage-domains/add-multiple-sites-automation/
Agent setup ↗: /agent-setup/
Agent setup: /agent-setup/
Allow Cloudflare access: /fundamentals/account/account-security/cloudflare-access/
App innovation report: https://www.cloudflare.com/resource/app-innovation-report/
Athenian Project: https://www.cloudflare.com/athenian/
Audit Logs - v2: /fundamentals/account/account-security/audit-logs/
Authentik: /fundamentals/account/account-security/scim-setup/authentik/
Authorizing an application: /fundamentals/oauth/authorizing-an-application/
Available RSS Feeds: /fundamentals/new-features/available-rss-feeds/
Blocked Content: /fundamentals/reference/report-abuse/blocked-content/
Blog: https://blog.cloudflare.com/
Careers: https://www.cloudflare.com/careers/
Case studies: https://www.cloudflare.com/case-studies/
Change Super Administrator: /fundamentals/account/change-super-admin/
Change your domain version: /fundamentals/manage-domains/domain-version/
Changelog: /changelog/
Cloudflare AI Cloud: https://www.cloudflare.com/solutions/ai/
Cloudflare Cookies: /fundamentals/reference/policies-compliances/cloudflare-cookies/
Cloudflare Docs llms-full.txt ↗: /llms-full.txt
Cloudflare Docs llms.txt ↗: /llms.txt
Cloudflare Fundamentals llms-full.txt ↗: /fundamentals/llms-full.txt
Cloudflare Fundamentals llms.txt ↗: /fundamentals/llms.txt
Cloudflare Fundamentals: /fundamentals/
Cloudflare HTTP headers: /fundamentals/reference/http-headers/
Cloudflare IP addresses: /fundamentals/concepts/cloudflare-ip-addresses/
Cloudflare Radar: https://radar.cloudflare.com/
Cloudflare Ray ID: /fundamentals/reference/cloudflare-ray-id/
Cloudflare Skills ↗: https://github.com/cloudflare/skills
Cloudflare and Google Analytics: /fundamentals/reference/google-analytics/
Cloudflare crawlers: /fundamentals/reference/cloudflare-site-crawling/
Cloudflare dashboard ↗: https://dash.cloudflare.com/profile/api-tokens
Cloudflare for Campaigns: https://www.cloudflare.com/campaigns/
Cloudy AI agent Beta: /fundamentals/reference/cloudy-ai-agent/
Code Mode MCP Server ↗: https://github.com/cloudflare/mcp
Community: https://community.cloudflare.com/
Complaint types: /fundamentals/reference/report-abuse/complaint-types/
Compliance documentation: /fundamentals/reference/policies-compliances/compliance-docs/
Compliance resources: https://www.cloudflare.com/trust-hub/compliance-resources/
Connection limits: /fundamentals/reference/connection-limits/
Consuming RSS Feeds: /fundamentals/new-features/consuming-rss-feeds/
Contact sales: https://www.cloudflare.com/resource/contact-enterprise-sales/
Content Security Policies (CSPs): /fundamentals/reference/policies-compliances/content-security-policies/
Control API Access: /fundamentals/api/how-to/control-api-access/
Create API token: /fundamentals/api/get-started/create-token/
Create account: /fundamentals/account/create-account/
Create tokens via API: /fundamentals/api/how-to/create-via-api/
Create your OAuth client: /fundamentals/oauth/create-an-oauth-client/
Cryptographic Attestation of Personhood: /fundamentals/reference/cryptographic-personhood/
Customer abuse report obligations: /fundamentals/reference/report-abuse/abuse-report-obligations/
Data Protection: https://www.cloudflare.com/trust-hub/gdpr/
Delete your Cloudflare account: /fundamentals/user-profiles/delete-account/
Delivering Videos with Cloudflare: /fundamentals/reference/policies-compliances/delivering-videos-with-cloudflare/
Directory: /directory/
Docs: /
Documentation: https://developers.cloudflare.com/
Domain name search: https://domains.cloudflare.com/
Domain-specific MCP Servers ↗ MCP: https://github.com/cloudflare/mcp-server-cloudflare
Edit page: https://github.com/cloudflare/cloudflare-docs/edit/production/src/content/docs/fundamentals/api/troubleshooting.mdx
Email address and password: /fundamentals/user-profiles/change-password-or-email/
Error responses: /fundamentals/reference/error-responses/
Events: https://www.cloudflare.com/events/
Find a partner: https://partnerlocator.cloudflare.com/dashboard
Find account and zone IDs: /fundamentals/account/find-account-and-zone-ids/
Frontend Development Platform: https://www.cloudflare.com/solutions/frontends/
Get Global API key (legacy): /fundamentals/api/get-started/keys/
Get Origin CA keys Deprecated: /fundamentals/api/get-started/ca-keys/
Get started: /fundamentals/get-started/
Global network: https://www.cloudflare.com/network/
Glossary: /fundamentals/reference/glossary/
GraphQL API ↗: /analytics/graphql-api/
Home: /
How Cloudflare DNS works: /fundamentals/concepts/how-cloudflare-works/
Impact/ESG: https://www.cloudflare.com/impact/
Improve SEO: /fundamentals/performance/improve-seo/
Integrate your OAuth client with Cloudflare: /fundamentals/oauth/integrate-with-cloudflare/
Investors: https://cloudflare.net/
Leaked Password Notifications: /fundamentals/account/account-security/leaked-password-notifications/
Learning center: https://www.cloudflare.com/learning/
Licenses: /fundamentals/reference/policies-compliances/licenses/
Limitations and troubleshooting: /fundamentals/organizations/limitations/
Log In: https://dash.cloudflare.com/login
Log in to Cloudflare: /fundamentals/user-profiles/login/
Log in: https://dash.cloudflare.com/
Maintenance mode: /fundamentals/performance/maintenance-mode/
Make API calls: /fundamentals/api/how-to/make-api-calls/
Manage active sessions: /fundamentals/account/account-security/manage-active-sessions/
Manage subdomains: /fundamentals/manage-domains/manage-subdomains/
Manage: /fundamentals/manage-members/manage/
Markdown for Agents Beta: /fundamentals/reference/markdown-for-agents/
Members and permissions: /fundamentals/manage-members/
Microsoft Entra: /fundamentals/account/account-security/scim-setup/entra/
Minimize downtime: /fundamentals/performance/minimize-downtime/
Move a domain between Cloudflare accounts: /fundamentals/manage-domains/move-domain/
Multi-Factor Email Authentication: /fundamentals/user-profiles/multi-factor-email-authentication/
Multi-Tenant Platform Development: https://www.cloudflare.com/solutions/platforms/
Network Layers: /fundamentals/reference/network-layers/
Network ports: /fundamentals/reference/network-ports/
Next Overview: /fundamentals/oauth/
Okta: /fundamentals/account/account-security/scim-setup/okta/
Onboard a domain: /fundamentals/manage-domains/add-site/
Optimize site speed ↗: /speed/
Organizations for Enterprise: /fundamentals/organizations/for-enterprise/
Organizations for MSSP and Distributors: /fundamentals/organizations/for-mssp-distributors/
Overview: /fundamentals/
Overview: /fundamentals/account/account-security/scim-setup/
Overview: /fundamentals/manage-domains/
Overview: /fundamentals/oauth/
Overview: /fundamentals/organizations/
Overview: /fundamentals/reference/report-abuse/
Overview: /fundamentals/user-profiles/
Partners: /fundamentals/reference/partners/
Partners: https://www.cloudflare.com/partners/
Pause Cloudflare: /fundamentals/manage-domains/pause-cloudflare/
Plans: https://www.cloudflare.com/plans/
Policies: /fundamentals/manage-members/policies/
Policy sharing: /fundamentals/organizations/policy-sharing/
Prepare for surges or spikes in web traffic ↗: /learning-paths/surge-readiness/concepts/
Press kit: https://www.cloudflare.com/press/press-kit/
Press: https://www.cloudflare.com/press/
Prevent DDoS attacks ↗: /learning-paths/prevent-ddos-attacks/concepts/
Previous SDKs: /fundamentals/api/reference/sdks/
Privacy policy: https://www.cloudflare.com/policies/privacy/
Profile settings: /fundamentals/user-profiles/customize-account/
Project Cybersafe Schools: /fundamentals/reference/policies-compliances/cybersafe/
Project Fairshot: https://www.cloudflare.com/fair-shot/
Project Galileo: https://www.cloudflare.com/galileo/
Protect your origin server: /fundamentals/security/protect-your-origin-server/
Providing specific URLs: /fundamentals/reference/report-abuse/provide-specific-urls/
REST API ↗ API: /api/
Rate limits: /fundamentals/api/reference/limits/
Recovering from a hacked site: /fundamentals/security/recovering-from-hacked-site/
Redirect one domain to another: /fundamentals/manage-domains/redirect-domain/
Redirects: /fundamentals/reference/redirects/
Remove a domain: /fundamentals/manage-domains/remove-domain/
Report abuse: https://www.cloudflare.com/trust-hub/abuse-approach/
Report issue: https://github.com/cloudflare/cloudflare-docs/issues/new/choose
Report security issues: https://www.cloudflare.com/disclosure/
Responsible AI: https://www.cloudflare.com/trust-hub/responsible-ai/
Restrict tokens: /fundamentals/api/how-to/restrict-tokens/
Review abuse policies: https://www.cloudflare.com/trust-hub/abuse-approach/
Review audit logs - v1: /fundamentals/account/account-security/review-audit-logs/
Role scopes: /fundamentals/manage-members/scope/
Roles: /fundamentals/manage-members/roles/
Roll tokens: /fundamentals/api/how-to/roll-token/
SCIM migration: /fundamentals/reference/migration-guides/scim-virtual-groups-migration/
SDK ecosystem support policy: /fundamentals/reference/sdk-ecosystem-support-policy/
SDKs: /fundamentals/api/reference/sdks/
SSE and SASE platform: https://www.cloudflare.com/sase/
Scan for PCI compliance: /fundamentals/security/pci-scans/
Scans and penetration testing policy: /fundamentals/reference/scans-penetration/
Secure compromised account: /fundamentals/account/account-security/secure-a-compromised-account/
Secure your website ↗: /learning-paths/application-security/account-security/
Set up SSO ↗: /fundamentals/manage-members/dashboard-sso/
Set up dashboard SSO: /fundamentals/manage-members/dashboard-sso/
Star domains: /fundamentals/manage-domains/star-zones/
Start Building: https://dash.cloudflare.com/sign-up
Startups: https://www.cloudflare.com/startups/
Status: https://www.cloudflarestatus.com/
Support: https://support.cloudflare.com/
TCP connections: /fundamentals/reference/tcp-connections/
Terms of use: https://www.cloudflare.com/policies/terms/
Test speed: /fundamentals/performance/test-speed/
Token formats: /fundamentals/api/get-started/token-formats/
Trademark: https://www.cloudflare.com/trademark/
Traffic flow through Cloudflare: /fundamentals/concepts/traffic-flow-cloudflare/
Transparency report: https://www.cloudflare.com/transparency/
Troubleshooting: /fundamentals/account/account-security/scim-setup/troubleshooting/
Troubleshooting: /fundamentals/api/troubleshooting/
Troubleshooting: /fundamentals/reference/troubleshooting/
Trust Hub: https://www.cloudflare.com/trust-hub/
Two-factor authentication: /fundamentals/user-profiles/2fa/
Under Attack mode: /fundamentals/reference/under-attack-mode/
Under a DDoS attack?: /fundamentals/security/under-ddos-attack/
Under attack?: https://www.cloudflare.com/under-attack-hotline/
User Groups New: /fundamentals/manage-members/user-groups/
Verify email address: /fundamentals/user-profiles/verify-email-address/
View and submit reports: /fundamentals/reference/report-abuse/submit-report/
View as Markdown: index.md
Web Security Platform: https://www.cloudflare.com/solutions/security/
Wrangler API ↗: /workers/wrangler/api/
Zone holds: /fundamentals/account/account-security/zone-holds/
https://github.com/cloudflare/cloudflare-docs

[structured-data]
{"@context":"https://schema.org","@id":"https://developers.cloudflare.com/fundamentals/api/troubleshooting/#page","@type":"TechArticle","dateModified":"2026-04-20","description":"Resolve common Cloudflare API token issues including verification failures, incorrect permissions, and syntax errors.","headline":"Troubleshooting · Cloudflare Fundamentals docs","image":"https://developers.cloudflare.com/og-docs.png","inLanguage":"en","isPartOf":{"@id":"https://developers.cloudflare.com/#website","@type":"WebSite","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"},"publisher":{"@type":"Organization","name":"Cloudflare","url":"https://www.cloudflare.com/"},"url":"https://developers.cloudflare.com/fundamentals/api/troubleshooting/"}

[content]
Troubleshooting · Cloudflare Fundamentals docs
Skip to content
Documentation Index
Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt
Use this file to discover all available pages before exploring further.
Docs
Directory
API
SDKs
Changelog
Search
Ctrl
K
Log in
Cloudflare Fundamentals
/
Overview
Concepts
How Cloudflare DNS works
Traffic flow through Cloudflare
Accounts, zones, and profiles
Cloudflare IP addresses
Get started
Accounts
Create account
Account security
Add abuse contact
Allow Cloudflare access
Leaked Password Notifications
Manage active sessions
Review audit logs - v1
Audit Logs - v2
SCIM provisioning
Overview
Authentik
Microsoft Entra
Okta
Troubleshooting
Secure compromised account
Set up SSO ↗
Zone holds
Find account and zone IDs
Change Super Administrator
Organizations
Beta
Overview
Organizations for Enterprise
Organizations for MSSP and Distributors
Policy sharing
Limitations and troubleshooting
Members and permissions
Members and permissions
Manage
Policies
Roles
Role scopes
User Groups
New
Set up dashboard SSO
User profiles
Overview
Verify email address
Log in to Cloudflare
Profile settings
Account recovery
Delete your Cloudflare account
Email address and password
Multi-Factor Email Authentication
Two-factor authentication
Domains
Overview
Add multiple sites via automation
Change your domain version
Manage subdomains
Move a domain between Cloudflare accounts
Onboard a domain
Pause Cloudflare
Redirect one domain to another
Remove a domain
Star domains
Performance
Improve SEO
Maintenance mode
Minimize downtime
Optimize site speed ↗
Prepare for surges or spikes in web traffic ↗
Test speed
Security
Prevent DDoS attacks ↗
Protect your origin server
Recovering from a hacked site
Scan for PCI compliance
Secure your website ↗
Under a DDoS attack?
Cloudflare's API
Get started
Create API token
Get Global API key (legacy)
Get Origin CA keys
Deprecated
Token formats
Account API tokens
How to
Make API calls
Create tokens via API
Control API Access
Restrict tokens
Roll tokens
API token template URLs
Reference
REST API ↗
API
GraphQL API ↗
Wrangler API ↗
API token permissions
API deprecations
API token templates
Rate limits
SDKs
Troubleshooting
OAuth Applications on Cloudflare
Overview
Create your OAuth client
Integrate your OAuth client with Cloudflare
Authorizing an application
Reference
Migration guides
SCIM migration
Policies
Cloudflare Cookies
Compliance documentation
Content Security Policies (CSPs)
Delivering Videos with Cloudflare
Licenses
Project Cybersafe Schools
Abuse
Overview
Review abuse policies
Complaint types
Providing specific URLs
Customer abuse report obligations
View and submit reports
Blocked Content
SDK ecosystem support policy
Troubleshooting
/cdn-cgi/ endpoint
Account and domain management best practices
Cloudflare and Google Analytics
Cloudflare crawlers
Cloudflare HTTP headers
Cloudflare Ray ID
Cloudy AI agent
Beta
Connection limits
Cryptographic Attestation of Personhood
Error responses
Glossary
Markdown for Agents
Beta
Network Layers
Network ports
Partners
Redirects
Scans and penetration testing policy
TCP connections
Under Attack mode
RSS Feeds
Available RSS Feeds
Consuming RSS Feeds
Agent resources
Agent setup ↗
Cloudflare Skills ↗
Code Mode MCP Server ↗
Domain-specific MCP Servers ↗
MCP
Cloudflare Fundamentals llms.txt ↗
Cloudflare Fundamentals llms-full.txt ↗
Cloudflare Docs llms.txt ↗
Cloudflare Docs llms-full.txt ↗
Home
/
Cloudflare Fundamentals
/
Cloudflare's API
/
Troubleshooting
Troubleshooting
Last updated
Apr 20, 2026
|
Copy as Markdown
|
View as Markdown
|
Agent setup
Overview
The token is not verified
The token has incorrect permissions
The incorrect syntax is used
You have the incorrect user permissions
The token is not verified
Ensure the token has been verified by running the following
curl
command and confirming that the response returns
"status": "active"
.
curl
"https://api.cloudflare.com/client/v4/user/tokens/verify"
\
--header
"Authorization: Bearer <API_TOKEN>"
{
"success"
:
true
,
"errors"
: [],
"messages"
: [],
"result"
: {
"id"
:
"f267e341f3dd4697bd3b9f71dd96247f"
,
"status"
:
"active"
,
"not_before"
:
"2018-07-01T05:20:00Z"
,
"expires_on"
:
"2020-01-01T00:00:00Z"
}
}
The token has incorrect permissions
Review the permissions groups for your token in the
Cloudflare dashboard
↗
. Refer to
API token permissions
for more information.
The incorrect syntax is used
Occasionally customers will attempt to use an API token with an API key syntax. Ensure you are using the Bearer option rather than the email and API key pair.
You have the incorrect user permissions
You cannot create a token that exceeds the permission granted to you on your account. For example, if you have been granted an
Admin (Read only)
role, you would need your Super Administrator to update your role so that you could create a token for yourself.
Previous
SDKs
Next
Overview
Was this helpful?
Yes
No
Edit page
Report issue
On this page
Overview
The token is not verified
The token has incorrect permissions
The incorrect syntax is used
You have the incorrect user permissions
Edit page
Report issue
Getting started
Plans
Contact sales
Partners
Find a partner
Startups
Under attack?
Domain name search
Company
About
Careers
Investors
Press
Press kit
Global network
Public interest
Project Galileo
Athenian Project
Cloudflare for Campaigns
Project Fairshot
Impact/ESG
Compliance
Compliance resources
Trust Hub
Data Protection
Responsible AI
Transparency report
Report abuse
Resources
App innovation report
Cloudflare Radar
Case studies
Status
Support
Events
Blog
Developers
Documentation
Learning center
Community
Solutions
SSE and SASE platform
Cloudflare AI Cloud
AI Security
Frontend Development Platform
Multi-Tenant Platform Development
Web Security Platform
Start Building
Log In
© 2026 Cloudflare, Inc.
Privacy policy
|
Report security issues
|
Terms of use
|
Trademark
|
Your privacy choices
Docs
