Troubleshooting
Cloudflare Error 1020 Access Denied: What It Means for Automation
Cloudflare error 1020 means a site owner's firewall rule blocked your request: what the page shows, why no token lifts it, and what to do next.
By ZeroCaptcha Engineering5 min readPublished Updated
Cloudflare error 1020, “Access denied”, means the site’s owner has a firewall rule in Cloudflare that matched your request and blocked it. Cloudflare’s documentation gives the cause as “A client or browser is blocked by a Cloudflare customer’s Firewall Rules (deprecated)”. The error page shows a Ray ID and your IP address, and Cloudflare blocks from most security features come with HTTP status 403. Nothing your client sends can pass it: only the site owner can change the rule or allow your address.
Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.
What the error 1020 page tells you
Cloudflare’s page for the error (checked 1 October 2026) says “access to the website is denied by a Cloudflare firewall rule”. The page a visitor sees carries two values that matter:
- The Ray ID, which identifies the request in Cloudflare’s logs.
- Your IP address, as Cloudflare saw it: the address of your proxy or VPN, if you use one.
The HTTP status and the error code are separate things. Cloudflare’s docs say that statuses such as
403 and 429 “are returned in the HTTP status header of a response, while 1XXX errors appear in
the HTML body of the response.” A Block action returns 403 for most security features, and
Cloudflare lists “Most 1xxx Cloudflare error codes” among its causes of a 403. On Pro plans and
higher, an owner can also replace the response body, content type and status code of a custom
rule, so a blocked request on some sites shows the owner’s own page instead of Cloudflare’s.
Where the rule comes from
Cloudflare’s 1020 page still names Firewall Rules, a feature Cloudflare marks as deprecated. On today’s WAF, the rules an owner writes are custom rules, and their Block action is described as “Matching requests are denied access to the site.” Block is a terminating action: once a rule with it matches, no later rule is evaluated for that request. How custom rules sit next to managed rules and rate limiting rules is covered in Cloudflare WAF rules explained.
What a rule can match
A rule is an expression in Cloudflare’s Rules language, written over fields of the request. These are a few of the documented fields, in Cloudflare’s words:
| Field | What it holds |
|---|---|
ip.src |
“The client TCP IP address” |
ip.src.country |
“The 2-letter country code in ISO 3166-1 Alpha 2 format” |
ip.src.asnum |
The Autonomous System (AS) number of the client IP address |
http.user_agent |
“The HTTP User-Agent request header” |
http.request.uri.path |
“The URI path of the request” |
http.request.method |
“The HTTP method, returned as a string of uppercase characters” |
http.request.headers |
“The HTTP request headers represented as a Map” |
cf.client.bot |
“Indicates whether the request originated from a known good bot or crawler” |
You cannot see which rule matched or which field it used. The owner can, by searching the Ray ID.
A block is not a challenge
Error 1020 and Cloudflare’s “Just a moment…” page both stand between a client and the site, but they differ in what can end them:
| Error 1020 | Challenge page | |
|---|---|---|
| What it is | A Block action | A challenge action (Managed, Non-Interactive or Interactive) |
| How to recognize it | Error code 1020 in the HTML body; status 403 in most cases |
Header cf-mitigated: challenge, content type text/html |
| Who can end it | Only the site owner | A supported browser that passes it, which earns a cf_clearance cookie |
Cloudflare documents the cf_clearance cookie as letting a visitor “bypass WAF Challenges”, at
the clearance level they earned. Nothing in the clearance docs describes lifting a Block action,
and a Block rule’s description is that matching requests are denied. A Cloudflare Turnstile token
does not change that either: it goes into a form field for the site’s own server to verify, and the
blocked request never reaches that server.
ZeroCaptcha does not get you past error 1020. It solves Cloudflare Turnstile widgets, and its challenge task passes challenge pages, a different response from a block, through your proxy. The Cloudflare WAF and 5-second challenge solver page and Cloudflare challenge page vs Cloudflare Turnstile explain those cases.
What to do when your client gets error 1020
- Check that you are allowed. If the site’s terms don’t permit automated access, stop there.
- Stop sending the same request. A rule’s expression is fixed until the owner edits it, so the same request from the same client matches it again. Retrying only adds blocked events to the owner’s logs.
- Contact the site owner. Cloudflare tells visitors to “provide the website owner with a
screenshot of the
1020error message you received.” For an automated client, send the Ray ID, the time of the request in UTC, your IP address, and what your client does and how often. - Wait for the owner’s decision. The owner searches Security Events for the Ray ID or your IP, converting the UTC time to their own time zone, then updates the rule or allows your address through IP Access rules. Cloudflare’s docs note that allowing an IP or ASN there “will bypass any configured custom rules, rate limiting rules, WAF Managed Rules, and firewall rules.”
Don’t change your IP address, user agent or headers until a request slips past the rule. The owner wrote the rule to refuse that traffic, and the way in is the owner’s permission.
If the site is yours
When your own monitor, test suite or integration hits 1020 on your zone, find the event in Security Events by its Ray ID, then either narrow the rule’s expression or add a custom rule with the Skip action for that traffic. Keep the exception as narrow as the traffic it is for, such as one path from one address.
Other Cloudflare block codes
- Error 1015: a rate limiting rule. This one ends on its own when you slow down.
- Error 1010: Browser Integrity Check refused your client’s signature.
- Error 1009: the owner banned your IP address’s country or region.
- Errors 1006, 1007 and 1008: the owner banned your IP address.
If you see a page that keeps asking you to wait rather than an error code, read why a Cloudflare challenge loops and the cf_clearance cookie explained.
Sources
- Cloudflare: Error 1020 (checked 1 October 2026)
- Cloudflare: 1xxx errors (checked 1 October 2026)
- Cloudflare: Error 403 (checked 1 October 2026)
- Cloudflare: Rules language actions (checked 1 October 2026)
- Cloudflare: Rules language fields reference (checked 1 October 2026)
- Cloudflare: WAF custom rules (checked 1 October 2026)
- Cloudflare: IP Access rules (checked 1 October 2026)
- Cloudflare: Detect a Challenge Page response (checked 1 October 2026)
- Cloudflare: Clearance (checked 1 October 2026)
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.