Zero Trust woes

I have 2 applications in Zero trust

server.domain.com (allows only specific email - mine)
server.domain.com/api* (with bypass everyone rule)

I hit https://server.domain.com/api/v1/lala and still get Cloudflare "enter email" screen.

What is wrong and where can I see logs on why this matches the non-bypass? By documentation any Bypass app is processed first

thank you for your assistance!
Was this page helpful?