## TL;DR

`wrangler login` needs a browser, and headless machines do not have one, so the flow can never complete there. Skip it entirely: create an API credential in the Cloudflare dashboard with Workers permissions, put it in the CLOUDFLARE_API_TOKEN environment variable, and wrangler authenticates with no browser involved.

```text
Failed to open browser for login. Please open the following URL manually, or set an API token.
```

## Steps

1. In the Cloudflare dashboard, go to My Profile, then API Tokens, and create a credential with permission to edit Workers scripts and read your account. Copy the value once; it is shown only at creation time.
Expected: a new credential string in your clipboard.

2. In your shell session on the headless machine, place that value in the CLOUDFLARE_API_TOKEN environment variable. Keep it out of shell history and out of any committed file.
Expected: the variable is set for the session (verify with a length check, never by printing it).

3. Confirm wrangler picks it up:
```sh
wrangler whoami
```
Expected: wrangler prints your account name and account id with no browser involved.

4. Run your original command again, for example `wrangler deploy`.
Expected: it proceeds past authentication.

## Use this when
- `wrangler login` fails because no browser opens in a headless environment
- Logging in over SSH, in a Docker container, or on a CI runner
- The login hangs waiting for a browser callback that never comes

## Not for this skill when
- A browser opens fine but the login itself is rejected (account or permission problem)
- The credential is set but deploys fail with a 403 (scopes problem, not login)
- You are on a machine with a working browser; just use the normal login

## Variant phrasings
- wrangler login browser did not open headless
- wrangler login fails on ssh server no browser
- how to authenticate wrangler without browser

## Why it happens

The default wrangler login is an OAuth flow that opens your browser to approve the CLI. On a machine with no display and no browser, that step cannot run, so wrangler errors out or hangs. API-credential auth is the documented headless path: wrangler reads the environment variable and never touches a browser.

## Edge cases
- Newer wrangler versions print the login URL for you to open manually on another machine; that works for a one-off SSH session but an API credential is better for anything repeatable.
- The credential needs the right permissions; a credential that can only read zones will authenticate fine and then fail the deploy.
- If both a cached OAuth login and the environment variable exist, the environment variable wins; a stale cached login cannot interfere once the variable is set.
- Rotate the credential if it ever lands in logs or chat; dashboard-created credentials can be rolled without touching anything else.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_uN9CCiUfxMun8KGNjUCFdQ
