Cloudflare API Tokens: Unresolved behavior of expires_on expiration enforcement
0 reputation · 01 Jun 2025, 03:31 UTC
0 reputation · 01 Jun 2025, 03:31 UTC
To determine whether the expires_on field on Cloudflare API Tokens actually causes the token to become invalid after the specified timestamp, and whether cached or in‑flight credentials continue to be honored beyond that point.
expires_on field is optional and its enforcement is undocumented./user/tokens/verify endpoint currently reports a token as active regardless of the expiration timestamp.expires_on value, does Cloudflare automatically reject all new requests that use that token with a 401/403 response?/user/tokens/verify endpoint reflect the token’s expired status, or does it continue to return “active” until the token is manually revoked?expires_on timestamp. This is the intended enforcement behavior.| Aspect | Confirmed (Documented/Observed) | Likely / Requires Verification |
|---|---|---|
Gateway rejection after expires_on | Design intent per Cloudflare architecture | Exact HTTP code (401 vs 403) and error body |
| Propagation delay | Global edge propagation can take seconds to minutes | Maximum observed delay in production |
| Worker token handling | No auto-refresh; manual update required | Whether Workers KV TTL interacts with token expiry |
/user/tokens/verify accuracy | Intended to show current status | Whether it lags behind gateway enforcement |
Run this once to confirm behavior in your account:
expires_on set to 5 minutes in the future (UTC). Scope it to a low-risk permission like Zone:Read.GET /client/v4/zones) and record the response code.expires_on time, then repeat the same request.GET /user/tokens/verify with the same token after expiration and note the status field.# Example verification calls (replace TOKEN and ZONE_ID)
curl -H "Authorization: Bearer TOKEN" \
"https://api.cloudflare.com/client/v4/zones"
curl -H "Authorization: Bearer TOKEN" \
"https://api.cloudflare.com/client/v4/user/tokens/verify"
If the verification shows the token is still accepted or /user/tokens/verify returns "active" after expiration, please report the exact expires_on value you set and the UTC time you observed the behavior. That timestamp precision determines whether the issue is propagation delay or a logic gap.
expires_on as enforced at the gateway, but plan for a propagation window of up to a few minutes./user/tokens/verify in automation only as a supplementary signal—gate on actual 401/403 responses from protected endpoints.Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.