Question
Cloudflare API Tokens: Unresolved behavior of expires_on expiration enforcement
Rey River
0 reputation · 01 Jun 2025, 03:31 UTC
100.4K views0
Goal
To determine whether the expires_on field on Cloudflare API Tokens actually causes the token to become invalid after the specified timestamp, and whether cached or in‑flight credentials continue to be honored beyond that point.
Constraints & Uncertainty
- API Tokens default to no expiration; the
expires_onfield is optional and its enforcement is undocumented. - Tokens may be stored in Workers, Edge‑Cache, or other services that could cache the bearer token.
- The
/user/tokens/verifyendpoint currently reports a token as active regardless of the expiration timestamp.
Unresolved Questions
- When the current UTC time surpasses the
expires_onvalue, does Cloudflare automatically reject all new requests that use that token with a 401/403 response? - If a token is cached in a Cloudflare Worker or Edge‑Cache, will those cached credentials still be accepted for requests after expiration, or does the worker automatically refresh the token?
- Does the
/user/tokens/verifyendpoint reflect the token’s expired status, or does it continue to return “active” until the token is manually revoked?