Tool pages / Wrangler

Cloudflare Wrangler 4.148.0: latest version, changes and gotchas

Latest: Wrangler 4.148.0, released (release notes).

Last verified 2026-10-07 against 4.148.0. Page updated . Also as Markdown and JSON.

The latest Cloudflare Wrangler is 4.148.0, published to npm on 2026-10-06 18:33 UTC. Upgrade inside your project with npm i -D wrangler@latest. Compared with 4.147.0 it adds four flags (wrangler dev --tunnel-allowed-mail, kv namespace create --experimental-mode, and two on queues subscription create), accepts assets.base_path, and fixes local R2 keys with spaces.

How do I install or upgrade to Wrangler 4.148.0?

In your project (Cloudflare's recommended install):

npm i -D wrangler@latest
npx wrangler --version   # 4.148.0

pnpm, yarn, bun:

pnpm add -D wrangler@latest
yarn add -D wrangler@latest
bun add -d wrangler@latest

Pin this exact version:

npm i -D wrangler@4.148.0

Wrangler key facts

What changed in the last 5 Wrangler releases?

Wrangler 4.148.0 (2026-10-06 18:33 UTC)

  • assets.base_path serves an asset directory under a public URL prefix (for example /docs). (source)
  • wrangler dev --tunnel-allowed-mail requires email authentication on Quick Tunnels. (source)
  • wrangler kv namespace create --experimental-mode instant creates KV Instant namespaces (private beta). (source)
  • wrangler queues subscription create adds --source-namespace and --source-repo-name, required for --source artifacts.repo. (source)
  • wrangler versions secret bulk deletes a secret whose JSON value is null. (source)
  • Local r2 object put and r2 bulk put keep keys with spaces, non-ASCII characters, # and % intact. (source)
  • --temporary account notices and the claim URL now go to stderr, not stdout; scripts that read the claim URL from stdout must read stderr. (source)

Wrangler 4.147.0 (2026-10-02 11:30 UTC)

  • Container applications accept constraints.jurisdiction: "us". (source)
  • wrangler containers list reports live instances in LIVE INSTANCES. (source)
  • wrangler workflows instances list and describe retry transient API failures. (source)

Wrangler 4.146.0 (2026-10-01 16:34 UTC)

  • Local development supports the Workflows createBatch() API. (source)
  • wrangler tunnel quick-start --allowed-mail (experimental; needs cloudflared 2026.9.2 or later). (source)
  • wrangler tail --header "Origin:https://app.example.com" keeps everything after the first colon. (source)

Wrangler 4.145.0 (2026-09-30 14:20 UTC)

  • Native support for the Analytics SQL binding. (source)
  • SQL, Catalog and Pipelines under wrangler basin graduate from beta to stable. (source)
  • Beta K2 stream management commands and producer bindings. (source)

Wrangler 4.144.0 (2026-09-29 21:12 UTC)

  • wrangler containers ssh --tty (-t) forces pseudo-terminal allocation. (source)
  • SSH settings for Durable Object-managed Containers in the configuration API. (source)

Which Wrangler commands and flags were added or removed?

Wrangler 4.147.0 → 4.148.0

0 commands added, 0 removed, 3 commands with flags added or removed; 5 help pages changed in any way.

Method: bin/tool-snapshot ran --help for every wrangler subcommand of both versions in a throwaway Linux sandbox (430 and 430 help pages), then bin/tool-diff compared them. Hidden flags do not appear in --help.

CommandFlags addedFlags removed
wrangler dev--tunnel-allowed-mailnone
wrangler kv namespace create--experimental-modenone
wrangler queues subscription create--source-namespace--source-repo-namenone
  • These are the last two minor versions. No command was added or removed; kv namespace create also gains the alias --x-mode, and the queues subscription create --events help now says to use pushed, not cf.artifacts.repo.pushed, for artifacts.repo.

What breaks when upgrading Wrangler, and how do I migrate?

VersionChangeMigration
4.148.0--temporary notices, the proof-of-work message and the claim URL moved from stdout to stderr.Read the claim URL from stderr; stdout now carries only the command's own output (for example JSON from kv namespace list --temporary).
4.131.0Removed the wrangler preview settings commands.Check wrangler preview --help in your installed version for the current Preview commands.
4.111.0Service environments, the legacy_env config field and the --legacy-env flag were removed; legacy_env in config is now an error.Delete legacy_env from the config. With the old default (legacy_env = true) nothing changes; with legacy_env = false each environment now deploys as a standalone Worker <name>-<environment>.
4.96.0Pipeline bindings: the pipeline field was renamed to stream.Rename pipeline to stream in pipeline binding configuration.

What Wrangler errors did we reproduce, and how do I fix them?

`wrangler deploy` in CI without an API token (Wrangler 4.148.0)

CI=1 npx wrangler deploy
✘ [ERROR] In a non-interactive environment, it's necessary to set a CLOUDFLARE_API_TOKEN environment variable for wrangler to work. Please go to https://developers.cloudflare.com/fundamentals/api/get-started/create-token/ for instructions on how to create an api token, and assign its value to CLOUDFLARE_API_TOKEN.

  To continue without logging in, rerun this command with `--temporary`. Wrangler will use a temporary account and print a claim URL.
# exit 1 (same text in 4.147.0)

Fix: Set CLOUDFLARE_API_TOKEN in the CI secrets, as the error says. --temporary uses a temporary account, not yours. (source)

`legacy_env` in the config is an error (Wrangler 4.148.0)

npx wrangler deploy --dry-run -c legacy.jsonc   # legacy.jsonc contains "legacy_env": false
✘ [ERROR] Processing legacy.jsonc configuration:

    - The "legacy_env" field is no longer supported, so please remove it from your configuration file.
      Service environments have been removed, and each environment is now deployed as its own Worker named "<name>-<environment>". This matches the behaviour of "legacy_env = true", which was the default, so removing the field will not change how your Worker is deployed.
      Refer to https://developers.cloudflare.com/workers/wrangler/environments/ for more information.
# exit 1

Fix: Remove legacy_env. If it was false, expect each environment to deploy as its own Worker. (source)

`assets.base_path` is silently ignored before 4.148.0 (Wrangler 4.147.0)

npx wrangler@4.147.0 deploy --dry-run -c assets.jsonc   # "assets": { "directory": "./public", "base_path": "/docs" }
▲ [WARNING] Processing assets.jsonc configuration:

    - Unexpected fields found in assets field: "base_path"

✨ Read 1 file from the assets directory /root/w-4.147.0/public
...
--dry-run: exiting now.
There is a newer version of Wrangler available (current: 4.147.0, latest: 4.148.0). Try upgrading, as it might support this configuration option.
# exit 0: the dry run passes and the field is dropped

Fix: Upgrade to 4.148.0 or later before relying on base_path; 4.148.0 accepts the same config without a warning. (source)

Local R2 object with a space in its key cannot be read back (Wrangler 4.147.0)

npx wrangler@4.147.0 r2 object put "test-bucket/my file.txt" --file hello.txt --local
npx wrangler@4.147.0 r2 object get "test-bucket/my file.txt" --local --pipe
Creating object "my file.txt" in bucket "test-bucket".
Upload complete.
✘ [ERROR] The specified key does not exist.

Fix: Upgrade to 4.148.0: the same two commands print the object (hello). Objects already stored by older versions stay under their percent-encoded keys. (source)

Wrangler release history by month

2026-10: 4.146.0 to 4.148.0 (3 releases to 2026-10-07)

  • 4.148.0: assets.base_path, email-protected Quick Tunnels, KV Instant namespaces, temporary-account notices on stderr. (source)

2026-09: 4.128.0 to 4.145.0 (25 releases)

  • 4.129.0 added --json to the wrangler workflows commands. (source)
  • 4.131.0 removed wrangler preview settings; 4.132.0 removed the gated Web Search binding and command. (source)
  • 4.136.0 added experimental --zone and --zone-id to wrangler deploy and wrangler triggers deploy. (source)

2026-08: 4.119.0 to 4.127.1 (11 releases)

  • 4.119.0 added OAuth 2.0 Device Authorization Grant to wrangler login. (source)
  • 4.121.0 honours DO_NOT_TRACK=1 as a telemetry opt-out; 4.122.0 detects Node.js compatibility from the compatibility date. (source)

2026-07: 4.107.0 to 4.118.0 (13 releases)

  • 4.111.0 (2026-07-15) removed service environments and legacy_env. (source)
  • 4.116.0 avoids Worker and workers.dev naming prompts in agent-driven deploys. (source)

2026-06: 4.95.0 to 4.106.0 (12 releases)

  • 4.99.0 introduced createTestHarness() and wrangler versions deploy --version-tag. (source)
  • 4.101.0 added --temporary (temporary account when there are no credentials). (source)
  • 4.106.0 added auth profiles for multiple OAuth logins. (source)

2026-05: 4.88.0 to 4.94.0 (10 releases)

  • 4.88.0 added builtin storage to wrangler ai-search create; 4.93.0 added wrangler ai models schema and --containers-rollout=none. (source)
  • 4.90.0 warns that delivery_delay in queue producer bindings has had no effect since 2024. (source)

Sources

Last verified: 2026-10-07.