wrangler whoami": not authenticated after token rotation
Fixes 'wrangler whoami' reporting not authenticated after an API credential rotation. Use it when a deploy pipeline breaks right after rotating credentials. The key trigger is whoami failing while deploys fail; the fix is clearing the stale cached login and authenticating with the new credential.
TL;DR
Rotating the credential in the dashboard does not update the shells and CI jobs that still hold the old one. wrangler whoami fails because it is reading the stale cached login or an outdated environment variable. Clear the old auth state with wrangler logout, authenticate again with the new credential, and confirm whoami prints the right account.
You are not authenticated. Please run `wrangler login` or provide an API token.Steps
- Confirm the current state:
wrangler whoamiExpected: the not-authenticated error, matching the failure you are debugging.
- Drop the stale cached login so nothing old can win:
wrangler logoutExpected: wrangler confirms you are logged out.
- Authenticate with the new credential. Either run the interactive login:
wrangler loginor, for CI and headless shells, set the API credential in the CLOUDFLAREAPITOKEN environment variable for the session. Do not leave the old value exported anywhere. Expected: login completes without errors.
- Verify you are who you think you are:
wrangler whoamiExpected: wrangler prints the account name and account id. Check the account id matches the account you intend to deploy to, especially if you have access to several.
Use this when
wrangler whoamisays not authenticated right after a credential rotation- Deploys started failing at the same time the old credential was revoked
- CI worked yesterday and fails today with an auth error after rotation
Not for this skill when
- The credential is valid but lacks permission for the operation (a 403, not an auth failure)
wrangler logincannot open a browser at all (use the headless-login skill instead)- The failure is on the Cloudflare API side rather than your local auth state
Variant phrasings
- wrangler whoami not authenticated after rotating api token
- wrangler login expired token still cached
- wrangler deploy unauthorized after token rotation
Why it happens
Wrangler keeps a cached OAuth login on disk, and many setups also export an API credential as an environment variable. Rotating in the dashboard revokes the old credential but changes nothing locally, so wrangler keeps presenting the dead one. An environment variable, when set, takes precedence over the cached login, which is why exporting the new value (or clearing the old one) fixes it.
Edge cases
- If several terminal sessions or CI jobs export the old credential, every one of them must be updated; fixing one shell leaves the others broken.
- Logging in with the wrong account after re-login deploys to the wrong place; always check the account id in whoami output, not just that it succeeded.
- Service or bot users with restricted permissions can authenticate fine yet still fail deploys; that is a scopes problem, not this one.
- Some CI systems mask rotated secrets but keep old step outputs cached; re-run the pipeline from a clean state after updating the secret.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_cCn33QNMe6KTOz-RbnqJfw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.