## TL;DR

Rotating the credential in the dashboard does not update the shells and CI jobs that still hold the old one. `wrangler whoami` fails because it is reading the stale cached login or an outdated environment variable. Clear the old auth state with `wrangler logout`, authenticate again with the new credential, and confirm whoami prints the right account.

```text
You are not authenticated. Please run `wrangler login` or provide an API token.
```

## Steps

1. Confirm the current state:
```sh
wrangler whoami
```
Expected: the not-authenticated error, matching the failure you are debugging.

2. Drop the stale cached login so nothing old can win:
```sh
wrangler logout
```
Expected: wrangler confirms you are logged out.

3. Authenticate with the new credential. Either run the interactive login:
```sh
wrangler login
```
or, for CI and headless shells, set the API credential in the CLOUDFLARE_API_TOKEN environment variable for the session. Do not leave the old value exported anywhere.
Expected: login completes without errors.

4. Verify you are who you think you are:
```sh
wrangler whoami
```
Expected: wrangler prints the account name and account id. Check the account id matches the account you intend to deploy to, especially if you have access to several.

## Use this when
- `wrangler whoami` says not authenticated right after a credential rotation
- Deploys started failing at the same time the old credential was revoked
- CI worked yesterday and fails today with an auth error after rotation

## Not for this skill when
- The credential is valid but lacks permission for the operation (a 403, not an auth failure)
- `wrangler login` cannot open a browser at all (use the headless-login skill instead)
- The failure is on the Cloudflare API side rather than your local auth state

## Variant phrasings
- wrangler whoami not authenticated after rotating api token
- wrangler login expired token still cached
- wrangler deploy unauthorized after token rotation

## Why it happens

Wrangler keeps a cached OAuth login on disk, and many setups also export an API credential as an environment variable. Rotating in the dashboard revokes the old credential but changes nothing locally, so wrangler keeps presenting the dead one. An environment variable, when set, takes precedence over the cached login, which is why exporting the new value (or clearing the old one) fixes it.

## Edge cases
- If several terminal sessions or CI jobs export the old credential, every one of them must be updated; fixing one shell leaves the others broken.
- Logging in with the wrong account after re-login deploys to the wrong place; always check the account id in whoami output, not just that it succeeded.
- Service or bot users with restricted permissions can authenticate fine yet still fail deploys; that is a scopes problem, not this one.
- Some CI systems mask rotated secrets but keep old step outputs cached; re-run the pipeline from a clean state after updating the secret.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_cCn33QNMe6KTOz-RbnqJfw
