The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Cloudflare Error 1015 means the website owner’s rate-limit rule has temporarily blocked your requests. Stop the scraper, do not run a rapid retry loop, and read any Retry-After value in the response. Resume only when you have a valid reason and permission to access the content, using lower request pressure; if the block continues, contact the site owner or use an authorized API or licensed data source.
There is no universal “safe” requests-per-second number. Each site owner chooses thresholds and rules, so changing IP addresses or trying to evade anti-bot controls is not the documented solution.
What Cloudflare Error 1015 means
Cloudflare’s Error 1015 page describes the condition plainly: “The website you are trying to visit has received too many requests and has temporarily blocked you from accessing it.” The limit is configured by the website owner; Cloudflare is returning the owner’s decision on the owner’s behalf.
That distinction matters. Error 1015 is not a defect in your HTTP library, a universal Cloudflare quota, or proof that a particular IP is permanently banned. It is a signal to pause and reassess whether your access is permitted and whether your request pattern is appropriate.
#1 Best Overall
What to do immediately
- Stop the job. Terminate workers and scheduled retries for the affected host. Continuing to send requests can keep the rule triggered or extend the temporary block.
- Record the response. Save the status code, response headers, timestamp, requested URL, and a short body sample. Do not log credentials or personal data.
- Check for
Retry-After. If present, treat it as the server’s instruction. It may be a number of seconds or an HTTP date. - Confirm authorization. Check the site’s terms, published API documentation, account permissions, and any written agreement covering your collection. If you cannot establish a lawful, permitted basis, do not resume automated access.
- Wait without probing. Do not test the site every few seconds to see whether the block has cleared. If the limit persists after the indicated delay, contact the owner or support team.
How to use Retry-After correctly
Cloudflare’s error reference lists retry_after: 30 for Error 1015 responses, but that is not a promise that access will return after exactly 30 seconds. A dynamic value supplied by a WAF rule takes precedence. HTTP 429 responses may also include Retry-After.
| Response condition | Action | What not to assume |
|---|---|---|
1015 with numeric Retry-After |
Pause at least that many seconds, then reassess authorization and request pressure. | That the number is a universal interval for other sites. |
1015 with an HTTP-date Retry-After |
Wait until the specified time, accounting for clock differences, then make at most a cautious, authorized request. | That a date guarantees the rule will be removed. |
| 1015 without the header | Stop and contact the owner if access is needed. Any fallback delay is an operational choice, not a documented safe rate. | That you should immediately retry after a fixed number of seconds. |
429 with Retry-After |
Honor the server’s delay and reduce pressure before resuming. | That Cloudflare API quota figures apply to this unrelated website. |
Resume only with a lower-impact request pattern
If the owner confirms that automated access is allowed, change the behavior that caused the limit rather than trying to route around it.
Reduce concurrency and burstiness
Use fewer workers, a bounded queue, and a delay between requests. Avoid launching hundreds of requests at once after a pause. A single host-specific limiter is safer than independent delays in each worker, because it controls the aggregate rate.
Cache and deduplicate
Store successful responses and avoid fetching the same URL repeatedly. Use conditional requests such as If-None-Match or If-Modified-Since when the site supports them. Crawl only pages needed for the stated purpose.
Use the published access method
An official API, data export, feed, or licensed provider usually gives clearer quotas and support than HTML scraping. Ask the site owner for an allowlisted integration or a documented limit if your use case is legitimate and recurring.
Do not treat a proxy as a fix
Rotating addresses, spoofing identity, defeating challenges, or disguising traffic attempts to evade the owner’s control. Those actions are not recommended remedies for Error 1015 and may violate the site’s terms or applicable law.
A defensive Python pattern for 1015 and 429
The following example demonstrates the control flow, not a guaranteed scraping interval. It stops on Error 1015, honors a supplied delay, and leaves the decision to resume with the operator. Use it only for an authorized target.
import email.utils
import time
from datetime import datetime, timezone
import requests
def retry_after_seconds(value):
if not value:
return None
value = value.strip()
if value.isdigit():
return max(0, int(value))
try:
target = email.utils.parsedate_to_datetime(value)
if target.tzinfo is None:
target = target.replace(tzinfo=timezone.utc)
return max(0, int((target - datetime.now(timezone.utc)).total_seconds()))
except (TypeError, ValueError, OverflowError):
return None
def fetch_once(url, session):
response = session.get(url, timeout=30)
if response.status_code == 1015:
delay = retry_after_seconds(response.headers.get("Retry-After"))
if delay is None:
# Cloudflare documents 30 seconds as a 1015 retry_after default;
# it is not a guarantee and must not become a tight retry loop.
delay = 30
raise RuntimeError(
f"Cloudflare 1015; stopped. Wait at least {delay}s, "
"verify permission, and reassess before resuming."
)
if response.status_code == 429:
delay = retry_after_seconds(response.headers.get("Retry-After"))
raise RuntimeError(
f"HTTP 429; stopped. Retry-After={delay!r}; reduce pressure "
"and follow the site owner’s instructions."
)
response.raise_for_status()
return response
with requests.Session() as session:
session.headers.update({"User-Agent": "AuthorizedResearchBot/1.0"})
page = fetch_once("https://example.com/page", session)
print(page.text[:200])
In production, add a shared per-host rate limiter, persistent caching, structured logs, and a manual stop switch. Do not automatically retry 1015 indefinitely. If the owner gives you a different quota or schedule, encode that agreement explicitly and monitor for changes.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
1015, HTTP 429, and other access errors
| Signal | Meaning | Operator response |
|---|---|---|
| Cloudflare 1015 | The owner’s Cloudflare rate-limit rule temporarily blocked the visitor. | Stop, honor retry guidance, lower pressure only with authorization, and contact the owner if needed. |
| HTTP 429 | The server received too many requests within a specified period; the response may include Retry-After. |
Apply the server’s delay and adjust the request pattern. Do not import quotas from Cloudflare’s own API documentation. |
| 403 or a challenge page | Access is denied for a reason that may be authentication, policy, or bot protection rather than rate alone. | Check credentials and published rules; ask the owner. Do not attempt to bypass the control. |
| 5xx, timeout, or blank response | A server or network failure, not proof that rate limiting is the cause. | Capture diagnostics, use modest timeouts, and investigate service status before changing collection behavior. |
robots.txt is guidance, not permission
RFC 9309 defines the Robots Exclusion Protocol. A crawler that successfully retrieves robots.txt is expected to follow its parseable rules. The same RFC explicitly says: “These rules are not a form of access authorization.”
Therefore, a permissive robots.txt file does not authorize you to ignore authentication, contractual restrictions, rate limits, or other access controls. Conversely, a restrictive file is an important signal to stop or seek clarification, but it does not replace a complete permission review.
Rank #3
If you operate the protected website
Error 1015 is also a configuration signal for the site owner. Cloudflare’s rate-limiting guidance treats limits as a way to constrain operations and protect against abuse, including content scraping. Review whether the rule’s matching fields, threshold, and period fit the traffic you intend to allow.
Check the rule window
A very short window can punish legitimate bursts. Cloudflare gives an example of changing a one-second period to ten seconds; that is owner-side tuning guidance, not a safe interval for unrelated scrapers.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsSeparate legitimate clients
Where appropriate, document an API, authenticate approved integrations, and give them explicit quotas. Monitor response codes and logs so you can distinguish a busy client from an abusive pattern without weakening protection for everyone else.
Troubleshooting common situations
The block returns immediately after the wait
Your previous concurrency or burst may still exceed the rule, or the owner may have configured a longer dynamic delay. Stop again, lower aggregate pressure only if authorized, and ask the owner for the required quota. Do not shorten the delay because a first test succeeded.
No Retry-After header is present
There is no server-provided schedule to follow. Keep the job stopped and contact the owner or switch to an authorized API. A self-selected 30-second pause is not a guarantee.
Only one endpoint fails
The rule may target a path, method, query pattern, account, or response behavior rather than the entire host. Compare your logs, but do not probe the blocked endpoint repeatedly. Ask the owner which resource and quota apply.
The browser works while the script receives 1015
Different clients can match different rules. A successful browser visit does not grant permission for automation. Verify the approved user agent, authentication method, and request schedule with the site owner.
You need the data continuously
Stop treating the public HTML page as an implicit feed. Request an API or licensed dataset, agree on quotas and attribution, and build your collector around that contract.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
When your actual task is generating page images or PDFs rather than crawling page data, ScreenshotNeo provides a single screenshot API request. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be disabled. Only clean shots are billed, while bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing. Responses identify the result with X-Page-Verdict and X-Billed headers. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf to Claude, Cursor, and other MCP clients.
Use the ScreenshotNeo API documentation for authentication and options. A one-call example:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
Equivalent Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
Equivalent Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`${res.status} ${res.statusText}`);
const fs = await import('node:fs/promises');
await fs.writeFile('shot.webp', Buffer.from(await res.arrayBuffer()));
ScreenshotNeo also supports full-page and element captures, lazy-image loading, dark mode, device presets and custom viewports, retina scale, PDF paper and page-range controls, HTML/CSS rendering, custom JavaScript and CSS, clicks, selector waits, network-idle waits, ad and tracker blocking, custom headers and cookies, timezone and geolocation, transparent backgrounds, resizing, configurable caching, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, a usage API, and an OpenAPI specification. Parameter names used by other screenshot APIs work as well.
Best Value
| Plan | Included shots | Price |
|---|---|---|
| Free | 1,000 per month | $0; no card |
| Starter | 3,000 | $5 |
| Growth | 15,000 | $15 |
| Pro | 60,000 | $39 |
| Scale | 250,000 | $99 |
| Business | 1,000,000 | $249 |
Every feature is available on every plan, and yearly billing gives two months free. Start with 1,000 free screenshots a month, with no card required.
FAQ
Is Error 1015 permanent?
Cloudflare describes it as a temporary block, but only the website owner controls the rule and its duration. Treat the block as active until the owner or response guidance indicates otherwise.
Can I keep collecting public pages after a 1015?
Only if you have an authorized basis and follow the owner’s limits. Public visibility alone is not a grant of automated-access permission.
Free tools Windows power users keep installed
One-click scans. No signup required.
Does a 429 always come from Cloudflare?
No. HTTP 429 is a standard status any server or intermediary can use to indicate too many requests.
What should I provide when contacting support?
Send the timestamp, affected URL or path, status code, request identifier if shown, and a description of your authorized use. Do not include secrets or unnecessary personal information.
Frequently Asked Questions
How long should I wait after Error 1015?
Use the response’s Retry-After value when supplied. If it is absent, there is no universal delay; keep the job stopped and ask the site owner.
Does robots.txt allow me to ignore a rate limit?
No. RFC 9309 says robots.txt rules guide crawler behavior but are not access authorization.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteShould I rotate proxies to clear Error 1015?
No. Rotating addresses to evade the owner’s control is not the documented remedy and may violate the site’s rules.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

