**TL;DR:** Never trust ambient login state after a re-auth. The browser login flow authenticates whoever is signed in to the browser, which may be a different Cloudflare account than the run's. Pin the expected account id in wrangler.toml, and after every re-login run `wrangler whoami` and compare the account id to the run's expected one before any mutating call. If they differ, stop - you're in the wrong account.

```text
auth token expired mid-run: agent failed over to the wrong account after re-login
```

## Steps

1. Halt every mutating call the moment re-auth completes. Run `wrangler whoami`. Expected: it shows an account id. Compare it to the expected account id recorded at the start of the run. A mismatch confirms the failover.
2. Pin the account for the run: set the top-level `account_id` in wrangler.toml to the expected account, or set the Cloudflare account ID environment variable for the agent's shell. Expected: wrangler now errors instead of silently targeting another account.
3. Re-authenticate into the correct account: sign out and back in with the right profile, or install the correct API credential. Run `wrangler whoami` again. Expected: the account id matches the expected one exactly.
4. Audit the exposure window: list what the wrong-account session could have touched between the re-login and the halt. Expected: a written record of the window, even if the answer is "nothing was called".
5. Resume from the last verified checkpoint, not from the start of the run. Expected: no duplicate resources created in either account.
6. Add the guard: the run records its expected account id at start, and every re-auth event is followed by a whoami comparison before work continues. Expected: silent failover becomes impossible.

## Use this when
- resources vanish or deploys misbehave right after a re-login
- `wrangler whoami` shows a different account than the run started with
- the agent has access to multiple Cloudflare accounts
- post-login actions hit "not found" on things that existed minutes ago

## Not for this skill when
- there's only one account in play - failover can't happen
- the credential expired but was renewed in place without a login flow - that's a different recovery path
- calls fail with permission errors inside the right account - that's scope, not account
- the wrong account was chosen deliberately - then update the run's expected account id

## Variant phrasings
- wrangler login switched to the wrong cloudflare account
- deployed to the wrong account after re-authenticating
- account id changed in the middle of an agent run
- re-login landed in a different account

## Why it happens
The OAuth login flow is ambient: it authenticates whoever happens to be signed in to the browser, not whoever the agent was working as. Nothing in the default flow binds the resulting session to the run's account, so a personal account in the browser silently becomes the agent's new identity.

## Edge cases
- API credentials are account-scoped, so credential-based auth can't fail over this way. Prefer API credentials over browser login for agent runs.
- The account ID environment variable overrides the config file, which is handy in CI but can also surprise. Check both when debugging.
- Some wrappers cache the account id separately from the credential. Verify at the wrangler level, not the wrapper level.
- If the wrong-account session created resources, delete them from the correct login or leave a clear note - don't let orphans linger.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_UwyklEY5PSfuGu1PCS93LA
