auth token expired mid-run: agent failed over to the wrong account after re-login
Fixes wrong-account failover after an agent re-authenticates mid-run and the browser login lands in a different Cloudflare account. Covers halting mutating calls, comparing live whoami output to the run's expected account id, and pinning the account id. Use when resources vanish or deploys misbehave right after re-login. Key trigger: whoami account id differs from the run's expected account after re-auth.
TL;DR: Never trust ambient login state after a re-auth. The browser login flow authenticates whoever is signed in to the browser, which may be a different Cloudflare account than the run's. Pin the expected account id in wrangler.toml, and after every re-login run wrangler whoami and compare the account id to the run's expected one before any mutating call. If they differ, stop - you're in the wrong account.
auth token expired mid-run: agent failed over to the wrong account after re-loginSteps
- Halt every mutating call the moment re-auth completes. Run
wrangler whoami. Expected: it shows an account id. Compare it to the expected account id recorded at the start of the run. A mismatch confirms the failover. - Pin the account for the run: set the top-level
account_idin wrangler.toml to the expected account, or set the Cloudflare account ID environment variable for the agent's shell. Expected: wrangler now errors instead of silently targeting another account. - Re-authenticate into the correct account: sign out and back in with the right profile, or install the correct API credential. Run
wrangler whoamiagain. Expected: the account id matches the expected one exactly. - Audit the exposure window: list what the wrong-account session could have touched between the re-login and the halt. Expected: a written record of the window, even if the answer is "nothing was called".
- Resume from the last verified checkpoint, not from the start of the run. Expected: no duplicate resources created in either account.
- Add the guard: the run records its expected account id at start, and every re-auth event is followed by a whoami comparison before work continues. Expected: silent failover becomes impossible.
Use this when
- resources vanish or deploys misbehave right after a re-login
wrangler whoamishows a different account than the run started with- the agent has access to multiple Cloudflare accounts
- post-login actions hit "not found" on things that existed minutes ago
Not for this skill when
- there's only one account in play - failover can't happen
- the credential expired but was renewed in place without a login flow - that's a different recovery path
- calls fail with permission errors inside the right account - that's scope, not account
- the wrong account was chosen deliberately - then update the run's expected account id
Variant phrasings
- wrangler login switched to the wrong cloudflare account
- deployed to the wrong account after re-authenticating
- account id changed in the middle of an agent run
- re-login landed in a different account
Why it happens
The OAuth login flow is ambient: it authenticates whoever happens to be signed in to the browser, not whoever the agent was working as. Nothing in the default flow binds the resulting session to the run's account, so a personal account in the browser silently becomes the agent's new identity.
Edge cases
- API credentials are account-scoped, so credential-based auth can't fail over this way. Prefer API credentials over browser login for agent runs.
- The account ID environment variable overrides the config file, which is handy in CI but can also surprise. Check both when debugging.
- Some wrappers cache the account id separately from the credential. Verify at the wrangler level, not the wrapper level.
- If the wrong-account session created resources, delete them from the correct login or leave a clear note - don't let orphans linger.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_UwyklEY5PSfuGu1PCS93LA