Skip to content

Troubleshooting

Cloudflare Error 1020 Access Denied: What It Means for Automation

Cloudflare error 1020 means a site owner's firewall rule blocked your request: what the page shows, why no token lifts it, and what to do next.

By 5 min readPublished Updated

Cloudflare error 1020, “Access denied”, means the site’s owner has a firewall rule in Cloudflare that matched your request and blocked it. Cloudflare’s documentation gives the cause as “A client or browser is blocked by a Cloudflare customer’s Firewall Rules (deprecated)”. The error page shows a Ray ID and your IP address, and Cloudflare blocks from most security features come with HTTP status 403. Nothing your client sends can pass it: only the site owner can change the rule or allow your address.

Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.

What the error 1020 page tells you

Cloudflare’s page for the error (checked 1 October 2026) says “access to the website is denied by a Cloudflare firewall rule”. The page a visitor sees carries two values that matter:

  • The Ray ID, which identifies the request in Cloudflare’s logs.
  • Your IP address, as Cloudflare saw it: the address of your proxy or VPN, if you use one.

The HTTP status and the error code are separate things. Cloudflare’s docs say that statuses such as 403 and 429 “are returned in the HTTP status header of a response, while 1XXX errors appear in the HTML body of the response.” A Block action returns 403 for most security features, and Cloudflare lists “Most 1xxx Cloudflare error codes” among its causes of a 403. On Pro plans and higher, an owner can also replace the response body, content type and status code of a custom rule, so a blocked request on some sites shows the owner’s own page instead of Cloudflare’s.

Where the rule comes from

Cloudflare’s 1020 page still names Firewall Rules, a feature Cloudflare marks as deprecated. On today’s WAF, the rules an owner writes are custom rules, and their Block action is described as “Matching requests are denied access to the site.” Block is a terminating action: once a rule with it matches, no later rule is evaluated for that request. How custom rules sit next to managed rules and rate limiting rules is covered in Cloudflare WAF rules explained.

What a rule can match

A rule is an expression in Cloudflare’s Rules language, written over fields of the request. These are a few of the documented fields, in Cloudflare’s words:

Field What it holds
ip.src “The client TCP IP address”
ip.src.country “The 2-letter country code in ISO 3166-1 Alpha 2 format”
ip.src.asnum The Autonomous System (AS) number of the client IP address
http.user_agent “The HTTP User-Agent request header”
http.request.uri.path “The URI path of the request”
http.request.method “The HTTP method, returned as a string of uppercase characters”
http.request.headers “The HTTP request headers represented as a Map”
cf.client.bot “Indicates whether the request originated from a known good bot or crawler”

You cannot see which rule matched or which field it used. The owner can, by searching the Ray ID.

A block is not a challenge

Error 1020 and Cloudflare’s “Just a moment…” page both stand between a client and the site, but they differ in what can end them:

Error 1020 Challenge page
What it is A Block action A challenge action (Managed, Non-Interactive or Interactive)
How to recognize it Error code 1020 in the HTML body; status 403 in most cases Header cf-mitigated: challenge, content type text/html
Who can end it Only the site owner A supported browser that passes it, which earns a cf_clearance cookie

Cloudflare documents the cf_clearance cookie as letting a visitor “bypass WAF Challenges”, at the clearance level they earned. Nothing in the clearance docs describes lifting a Block action, and a Block rule’s description is that matching requests are denied. A Cloudflare Turnstile token does not change that either: it goes into a form field for the site’s own server to verify, and the blocked request never reaches that server.

ZeroCaptcha does not get you past error 1020. It solves Cloudflare Turnstile widgets, and its challenge task passes challenge pages, a different response from a block, through your proxy. The Cloudflare WAF and 5-second challenge solver page and Cloudflare challenge page vs Cloudflare Turnstile explain those cases.

What to do when your client gets error 1020

  1. Check that you are allowed. If the site’s terms don’t permit automated access, stop there.
  2. Stop sending the same request. A rule’s expression is fixed until the owner edits it, so the same request from the same client matches it again. Retrying only adds blocked events to the owner’s logs.
  3. Contact the site owner. Cloudflare tells visitors to “provide the website owner with a screenshot of the 1020 error message you received.” For an automated client, send the Ray ID, the time of the request in UTC, your IP address, and what your client does and how often.
  4. Wait for the owner’s decision. The owner searches Security Events for the Ray ID or your IP, converting the UTC time to their own time zone, then updates the rule or allows your address through IP Access rules. Cloudflare’s docs note that allowing an IP or ASN there “will bypass any configured custom rules, rate limiting rules, WAF Managed Rules, and firewall rules.”

Don’t change your IP address, user agent or headers until a request slips past the rule. The owner wrote the rule to refuse that traffic, and the way in is the owner’s permission.

If the site is yours

When your own monitor, test suite or integration hits 1020 on your zone, find the event in Security Events by its Ray ID, then either narrow the rule’s expression or add a custom rule with the Skip action for that traffic. Keep the exception as narrow as the traffic it is for, such as one path from one address.

Other Cloudflare block codes

  • Error 1015: a rate limiting rule. This one ends on its own when you slow down.
  • Error 1010: Browser Integrity Check refused your client’s signature.
  • Error 1009: the owner banned your IP address’s country or region.
  • Errors 1006, 1007 and 1008: the owner banned your IP address.

If you see a page that keeps asking you to wait rather than an error code, read why a Cloudflare challenge loops and the cf_clearance cookie explained.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

What does Cloudflare error 1020 mean?

The site owner has a Cloudflare firewall rule that matched your request and denied it. Cloudflare's documentation titles it 'Error 1020: Access denied'; the block is the owner's setting, not a Cloudflare fault.

Can a Cloudflare Turnstile token or a cf_clearance cookie get past error 1020?

No. Both prove a passed check, and Cloudflare documents clearance as a way past challenges, not blocks. A Block rule denies the requests it matches until the owner changes it.

How is error 1020 different from a 'Just a moment...' page?

Error 1020 is a refusal. A 'Just a moment...' page is a challenge that a supported browser can pass, and Cloudflare marks every challenge page with the response header cf-mitigated: challenge.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key