Cloudflare Team-Domain Recovery
The full recovery procedure for the exact “Unable to find your Access organization” failure, including API-token validation and account/zone checks.
Use this page only when the team domain itself is broken
Primary symptom:
Unable to find your Access organization!
It appears that you have attempted to reach an invalid URL.
Please enter a valid team name.First test the team domain directly:
https://iridesceux.cloudflareaccess.comIf that direct URL works, do not overwrite the organization just because a Command callback is failing — first inspect the Access application/AUD/scope. If the direct team URL also fails, continue below.
A. Collect the IDs and create a temporary API token
Copy Account ID
Cloudflare Account home or Workers & PagesCloudflare documents the Account ID in Account home and Workers & Pages → Account details. It is 32 characters.
Optional: copy Zone ID
Cloudflare → iridesceux.com → Overview → API sectionUse this only if you need to compare account-level vs zone-level Access records. Zone ID is also 32 characters.
Create a temporary Account API token
Manage Account → API Tokens → Create Token → Custom TokenGrant the minimum required permission to inspect/update the Access organization: Access: Organizations, Identity Providers, and Groups Write for the Iridesceux account. Give the token a short TTL if desired.
B. Load token and IDs into Terminal safely
Copy the token to your clipboard, then:
unset CF_API_TOKEN
export CF_API_TOKEN="$(pbpaste)"
export ACCOUNT_ID='PASTE_32_CHARACTER_ACCOUNT_ID'
printf 'Token length: %s
' "${#CF_API_TOKEN}"
printf 'Account ID length: %s
' "${#ACCOUNT_ID}"
Token length must be non-zero. Account ID length must be 32.
C. Verify the API token before touching the organization
curl -sS "https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/tokens/verify" -H "Authorization: Bearer ${CF_API_TOKEN}" | python3 -m json.tool
Expected result contains:
"success": true
"status": "active"If you get a route like /accounts//tokens/verify, your ACCOUNT_ID variable is empty. If you get “Missing Authorization headers,” your token variable is empty.
D. Read the account-level Zero Trust organization
curl -sS "https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/access/organizations" -H "Authorization: Bearer ${CF_API_TOKEN}" -H "Content-Type: application/json" | python3 -m json.tool
Look specifically at:
result.auth_domain
result.name
successFor this deployment, the intended auth_domain is:
iridesceux.cloudflareaccess.comE. Force-set the intended account-level auth_domain only if the direct team domain is broken
curl -sS -X PUT "https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/access/organizations" -H "Authorization: Bearer ${CF_API_TOKEN}" -H "Content-Type: application/json" --data '{
"auth_domain": "iridesceux.cloudflareaccess.com",
"name": "Iridesceux"
}' | python3 -m json.tool
Expected: success: true, auth_domain: iridesceux.cloudflareaccess.com, and organization name Iridesceux.
F. Re-read and test the domain
- Run the GET organization command again.
- Confirm the backend still reports the intended
auth_domain. - Open a fresh private browser.
- Open
https://iridesceux.cloudflareaccess.com. - A valid result is an App Launcher/login/Welcome page — not “Unable to find your Access organization.”
Only after this succeeds should you create/recreate the Command Access application.
G. If team domain works but Command callback still fails
At that point the team organization exists. Do not keep rewriting auth_domain. Instead:
- Verify Pages custom domain is Active.
- Delete/recreate only the Command Access application after the team is healthy.
- Use Self-hosted and private → Add public hostname →
command.iridesceux.com. - Use OTP and exact-email Allow policy.
- Copy the new AUD and update
CF_ACCESS_AUD. - Redeploy Command.
- Test from fresh Incognito.
If the behavior suggests account-level vs zone-level stale Access state, you can read the zone-scoped organization with the same official endpoint form:
export ZONE_ID='PASTE_32_CHARACTER_ZONE_ID'
curl -sS "https://api.cloudflare.com/client/v4/zones/${ZONE_ID}/access/organizations" -H "Authorization: Bearer ${CF_API_TOKEN}" | python3 -m json.tool
Do not overwrite zone-level state unless you have confirmed it exists and conflicts with the intended configuration.
H. Clean up the temporary API token
- After recovery is complete, return to Manage Account → API Tokens.
- Revoke/delete the temporary “team recovery” token.
- Clear the local shell value:
unset CF_API_TOKEN. - Remove the token from clipboard history/password-manager temporary note if applicable.
- Do not commit any recovery shell file containing the token.