Oculix Experts
← Back to blog

Cloudflare Access Blocking an Endpoint Despite a Correct-Looking Policy? What We Found

Featured

September 30, 2026

You added or changed a Cloudflare Access policy, it looks right, and the endpoint is still blocked. Before you rewrite the policy again, check which Access application actually covers the path that is failing.

What Actually Happened: Our Blocked Ingest Endpoint

In our own production systems, an ingest endpoint was blocked even though the policy looked correct. The cause was how our Access setup was organized: each of our ingest paths had its own dedicated single-path Access application. Access policies belong to an application, so a policy on one application does not cover a path that belongs to a different one.

The fix was to add a second destination to the existing single-path Access application, and then to test the endpoint end to end to confirm it worked.

This is exactly the kind of small configuration detail Oculix helps teams find.

How to Check Whether You Have the Same Problem

  1. Write down the exact hostname and path that is blocked. Include any subpath.
  2. Open the list of Access applications in Cloudflare Zero Trust and note every application that could apply to that hostname.
  3. Check each application's destinations. Find the application whose destinations actually match the failing path. That application's policy is the one that applies, not the policy you have been editing.
  4. If no application covers the path, or a different single-path application does, add the path as a destination on the application whose policy you want, and make sure that is a deliberate choice, since every destination on an application shares its policy.
  5. Test end to end from a client that should have access and one that should not, after every change.

Common Mistakes to Avoid

Cloud Health Check Bundle: Oculix Diagnostic Services

If you would like a second pair of eyes on your setup, Oculix offers expert diagnostic services for early-stage SaaS teams running on Google Cloud Run and Cloudflare. Our Cloud Health Check Bundle, priced at $225, covers your Cloud Run and Cloudflare setup, deploy flow and cost, and is delivered as a recorded video walkthrough or written report with a stated root cause and fix. We work from read-only access or a screen share and never need secret values.

Want a second pair of eyes on your Cloud Run and Cloudflare setup? Oculix diagnostic services work from read-only access or a screen share.

cloudflare access · cloudflare access blocking endpoint · cloudflare access application destinations · cloudflare zero trust · google cloud run · saas deployment · production incident · early stage saas

Related Articles