IRIDESC E UX · COMMAND
v30 · Program Primary Revision
INTERNALSTEP-BY-STEP

Cloudflare Team-Domain Recovery

The full recovery procedure for the exact “Unable to find your Access organization” failure, including API-token validation and account/zone checks.

Use this page only when the team domain itself is broken

Primary symptom:

Unable to find your Access organization!
It appears that you have attempted to reach an invalid URL.
Please enter a valid team name.

First test the team domain directly:

https://iridesceux.cloudflareaccess.com

If that direct URL works, do not overwrite the organization just because a Command callback is failing — first inspect the Access application/AUD/scope. If the direct team URL also fails, continue below.

A. Collect the IDs and create a temporary API token

1

Copy Account ID

Cloudflare Account home or Workers & Pages

Cloudflare documents the Account ID in Account home and Workers & Pages → Account details. It is 32 characters.

2

Optional: copy Zone ID

Cloudflare → iridesceux.com → Overview → API section

Use this only if you need to compare account-level vs zone-level Access records. Zone ID is also 32 characters.

3

Create a temporary Account API token

Manage Account → API Tokens → Create Token → Custom Token

Grant the minimum required permission to inspect/update the Access organization: Access: Organizations, Identity Providers, and Groups Write for the Iridesceux account. Give the token a short TTL if desired.

Do not paste this token into chat or screenshots.

B. Load token and IDs into Terminal safely

Copy the token to your clipboard, then:

unset CF_API_TOKEN
export CF_API_TOKEN="$(pbpaste)"
export ACCOUNT_ID='PASTE_32_CHARACTER_ACCOUNT_ID'

printf 'Token length: %s
' "${#CF_API_TOKEN}"
printf 'Account ID length: %s
' "${#ACCOUNT_ID}"

Token length must be non-zero. Account ID length must be 32.

If you open a new Terminal window, shell variables may be empty again. Re-export them before running API commands.

C. Verify the API token before touching the organization

curl -sS   "https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/tokens/verify"   -H "Authorization: Bearer ${CF_API_TOKEN}"   | python3 -m json.tool

Expected result contains:

"success": true
"status": "active"

If you get a route like /accounts//tokens/verify, your ACCOUNT_ID variable is empty. If you get “Missing Authorization headers,” your token variable is empty.

D. Read the account-level Zero Trust organization

curl -sS   "https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/access/organizations"   -H "Authorization: Bearer ${CF_API_TOKEN}"   -H "Content-Type: application/json"   | python3 -m json.tool

Look specifically at:

result.auth_domain
result.name
success

For this deployment, the intended auth_domain is:

iridesceux.cloudflareaccess.com

E. Force-set the intended account-level auth_domain only if the direct team domain is broken

Do not run a write request casually. Read the current organization first and save its JSON. The update endpoint changes organization configuration.
curl -sS   -X PUT   "https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/access/organizations"   -H "Authorization: Bearer ${CF_API_TOKEN}"   -H "Content-Type: application/json"   --data '{
    "auth_domain": "iridesceux.cloudflareaccess.com",
    "name": "Iridesceux"
  }'   | python3 -m json.tool

Expected: success: true, auth_domain: iridesceux.cloudflareaccess.com, and organization name Iridesceux.

F. Re-read and test the domain

  1. Run the GET organization command again.
  2. Confirm the backend still reports the intended auth_domain.
  3. Open a fresh private browser.
  4. Open https://iridesceux.cloudflareaccess.com.
  5. A valid result is an App Launcher/login/Welcome page — not “Unable to find your Access organization.”

Only after this succeeds should you create/recreate the Command Access application.

G. If team domain works but Command callback still fails

At that point the team organization exists. Do not keep rewriting auth_domain. Instead:

  1. Verify Pages custom domain is Active.
  2. Delete/recreate only the Command Access application after the team is healthy.
  3. Use Self-hosted and private → Add public hostname → command.iridesceux.com.
  4. Use OTP and exact-email Allow policy.
  5. Copy the new AUD and update CF_ACCESS_AUD.
  6. Redeploy Command.
  7. Test from fresh Incognito.

If the behavior suggests account-level vs zone-level stale Access state, you can read the zone-scoped organization with the same official endpoint form:

export ZONE_ID='PASTE_32_CHARACTER_ZONE_ID'

curl -sS   "https://api.cloudflare.com/client/v4/zones/${ZONE_ID}/access/organizations"   -H "Authorization: Bearer ${CF_API_TOKEN}"   | python3 -m json.tool

Do not overwrite zone-level state unless you have confirmed it exists and conflicts with the intended configuration.

H. Clean up the temporary API token

  1. After recovery is complete, return to Manage Account → API Tokens.
  2. Revoke/delete the temporary “team recovery” token.
  3. Clear the local shell value: unset CF_API_TOKEN.
  4. Remove the token from clipboard history/password-manager temporary note if applicable.
  5. Do not commit any recovery shell file containing the token.