# Cloudflare Error 1020 Access Denied: What It Means for Automation

> Cloudflare error 1020 means a site owner's firewall rule blocked your request: what the page shows, why no token lifts it, and what to do next.

- Source: https://zerocaptcha.io/blog/cloudflare-error-1020
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

Cloudflare error 1020, "Access denied", means the site's owner has a firewall rule in Cloudflare
that matched your request and blocked it. Cloudflare's documentation gives the cause as "A client
or browser is blocked by a Cloudflare customer's Firewall Rules (deprecated)". The error page shows
a Ray ID and your IP address, and Cloudflare blocks from most security features come with HTTP
status 403. Nothing your client sends can pass it: only the site owner can change the rule or allow
your address.

Only automate sites you are allowed to: your own, a client's, or one whose terms permit it. See
[responsible captcha automation](https://zerocaptcha.io/guides/responsible-captcha-automation).

## What the error 1020 page tells you

Cloudflare's page for the error (checked 1 October 2026) says "access to the website is denied
by a Cloudflare firewall rule". The page a visitor sees carries two values that matter:

- **The Ray ID**, which identifies the request in Cloudflare's logs.
- **Your IP address**, as Cloudflare saw it: the address of your proxy or VPN, if you use one.

The HTTP status and the error code are separate things. Cloudflare's docs say that statuses such as
`403` and `429` "are returned in the HTTP status header of a response, while 1XXX errors appear in
the HTML body of the response." A Block action returns `403` for most security features, and
Cloudflare lists "Most 1xxx Cloudflare error codes" among its causes of a `403`. On Pro plans and
higher, an owner can also replace the response body, content type and status code of a custom
rule, so a blocked request on some sites shows the owner's own page instead of Cloudflare's.

## Where the rule comes from

Cloudflare's 1020 page still names Firewall Rules, a feature Cloudflare marks as deprecated. On
today's WAF, the rules an owner writes are custom rules, and their Block action is described as
"Matching requests are denied access to the site." Block is a terminating action: once a rule with
it matches, no later rule is evaluated for that request. How custom rules sit next to managed rules
and rate limiting rules is covered in [Cloudflare WAF rules explained](https://zerocaptcha.io/blog/cloudflare-waf-rules-explained).

### What a rule can match

A rule is an expression in Cloudflare's Rules language, written over fields of the request. These
are a few of the documented fields, in Cloudflare's words:

| Field | What it holds |
| --- | --- |
| `ip.src` | "The client TCP IP address" |
| `ip.src.country` | "The 2-letter country code in ISO 3166-1 Alpha 2 format" |
| `ip.src.asnum` | The Autonomous System (AS) number of the client IP address |
| `http.user_agent` | "The HTTP `User-Agent` request header" |
| `http.request.uri.path` | "The URI path of the request" |
| `http.request.method` | "The HTTP method, returned as a string of uppercase characters" |
| `http.request.headers` | "The HTTP request headers represented as a Map" |
| `cf.client.bot` | "Indicates whether the request originated from a known good bot or crawler" |

You cannot see which rule matched or which field it used. The owner can, by searching the Ray ID.

## A block is not a challenge

Error 1020 and Cloudflare's "Just a moment..." page both stand between a client and the site, but
they differ in what can end them:

| | Error 1020 | Challenge page |
| --- | --- | --- |
| What it is | A Block action | A challenge action (Managed, Non-Interactive or Interactive) |
| How to recognize it | Error code 1020 in the HTML body; status `403` in most cases | Header `cf-mitigated: challenge`, content type `text/html` |
| Who can end it | Only the site owner | A supported browser that passes it, which earns a `cf_clearance` cookie |

Cloudflare documents the `cf_clearance` cookie as letting a visitor "bypass WAF Challenges", at
the clearance level they earned. Nothing in the clearance docs describes lifting a Block action,
and a Block rule's description is that matching requests are denied. A Cloudflare Turnstile token
does not change that either: it goes into a form field for the site's own server to verify, and the
blocked request never reaches that server.

ZeroCaptcha does not get you past error 1020. It solves Cloudflare Turnstile widgets, and
its challenge task passes challenge pages, a different response from a block, through your proxy.
The [Cloudflare WAF and 5-second challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver) page and [Cloudflare challenge page
vs Cloudflare Turnstile](https://zerocaptcha.io/guides/cloudflare-challenge-vs-turnstile) explain those cases.

## What to do when your client gets error 1020

1. **Check that you are allowed.** If the site's terms don't permit automated access, stop there.
2. **Stop sending the same request.** A rule's expression is fixed until the owner edits it, so the
   same request from the same client matches it again. Retrying only adds blocked events to the
   owner's logs.
3. **Contact the site owner.** Cloudflare tells visitors to "provide the website owner with a
   screenshot of the `1020` error message you received." For an automated client, send the Ray
   ID, the time of the request in UTC, your IP address, and what your client does and how often.
4. **Wait for the owner's decision.** The owner searches Security Events for the Ray ID or your
   IP, converting the UTC time to their own time zone, then updates the rule or allows your address
   through IP Access rules. Cloudflare's docs note that allowing an IP or ASN there "will bypass any
   configured custom rules, rate limiting rules, WAF Managed Rules, and firewall rules."

Don't change your IP address, user agent or headers until a request slips past the rule. The owner
wrote the rule to refuse that traffic, and the way in is the owner's permission.

### If the site is yours

When your own monitor, test suite or integration hits 1020 on your zone, find the event in
Security Events by its Ray ID, then either narrow the rule's expression or add a custom rule with
the Skip action for that traffic. Keep the exception as narrow as the traffic it is for, such as
one path from one address.

## Other Cloudflare block codes

- [Error 1015](https://zerocaptcha.io/blog/cloudflare-error-1015): a rate limiting rule. This one ends on its own when you
  slow down.
- [Error 1010](https://zerocaptcha.io/blog/cloudflare-error-1010): Browser Integrity Check refused your client's signature.
- [Error 1009](https://zerocaptcha.io/blog/cloudflare-error-1009): the owner banned your IP address's country or region.
- [Errors 1006, 1007 and 1008](https://zerocaptcha.io/blog/cloudflare-error-1006-1007-1008): the owner banned your IP
  address.

If you see a page that keeps asking you to wait rather than an error code, read [why a Cloudflare
challenge loops](https://zerocaptcha.io/blog/cloudflare-challenge-loop) and [the cf_clearance cookie
explained](https://zerocaptcha.io/guides/cf-clearance-cookie-explained).

## Sources

- [Cloudflare: Error 1020](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-1xxx-errors/error-1020/) (checked 1 October 2026)
- [Cloudflare: 1xxx errors](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-1xxx-errors/) (checked 1 October 2026)
- [Cloudflare: Error 403](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/4xx-client-error/error-403/) (checked 1 October 2026)
- [Cloudflare: Rules language actions](https://developers.cloudflare.com/ruleset-engine/rules-language/actions/) (checked 1 October 2026)
- [Cloudflare: Rules language fields reference](https://developers.cloudflare.com/ruleset-engine/rules-language/fields/reference/) (checked 1 October 2026)
- [Cloudflare: WAF custom rules](https://developers.cloudflare.com/waf/custom-rules/) (checked 1 October 2026)
- [Cloudflare: IP Access rules](https://developers.cloudflare.com/waf/tools/ip-access-rules/) (checked 1 October 2026)
- [Cloudflare: Detect a Challenge Page response](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/detect-response/) (checked 1 October 2026)
- [Cloudflare: Clearance](https://developers.cloudflare.com/cloudflare-challenges/concepts/clearance/) (checked 1 October 2026)

## Questions

### What does Cloudflare error 1020 mean?

The site owner has a Cloudflare firewall rule that matched your request and denied it. Cloudflare's documentation titles it 'Error 1020: Access denied'; the block is the owner's setting, not a Cloudflare fault.

### Can a Cloudflare Turnstile token or a cf_clearance cookie get past error 1020?

No. Both prove a passed check, and Cloudflare documents clearance as a way past challenges, not blocks. A Block rule denies the requests it matches until the owner changes it.

### How is error 1020 different from a 'Just a moment...' page?

Error 1020 is a refusal. A 'Just a moment...' page is a challenge that a supported browser can pass, and Cloudflare marks every challenge page with the response header cf-mitigated: challenge.
