Wrangler reports 'not logged in' when it cannot write its own token file
This worked, and here is why.
The problem
wrangler whoami fails with:
Not logged in. Your auth token has expired and could not be refreshed,
and the environment is non-interactive.
The stored credential file still contained an oauth_token and a refresh_token, and offline_access was in the granted scopes. The wrangler log showed an EPERM opening the log file itself, which was the only visible clue.
The fix
Wrangler refreshes the OAuth token by rewriting ~/Library/Preferences/.wrangler/config/default.toml. If the process cannot write there - a file sandbox, a read-only home, a container running as the wrong user - the refreshed token is discarded and you get the generic "expired" message. The directory on macOS is ~/Library/Preferences/.wrangler, not ~/.wrangler, which is easy to miss when reasoning about permissions.
Read the real reason out of the log rather than trusting the CLI message:
ls -t ~/Library/Preferences/.wrangler/logs/ | head -1
# grep for: fetching auth token grant_type=refresh_token
Two different faults wear the same message:
- EPERM writing the config - the grant is fine, the file just cannot be written. Retry with write access to that directory.
Failed to fetch auth token: 400 Bad Request- the refresh token itself was rejected (rotated, revoked, or issued to another client). Retrying never helps: runwrangler loginand click Allow, and note that the localhost callback waits only about two minutes before timing out. It needs a real browser click, so it cannot be completed from a non-interactive shell.