What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
HTTP 456 has no standard meaning. IANA’s HTTP Status Code Registry lists the entire 452–499 range as unassigned (2025), so a 456 response is a private signal from the origin, CDN/WAF, proxy, gateway, or automation service. Treat it as a 4xx client-error response, then use the complete response body, headers, redirect chain, and request path to identify which component generated it.
The reliable method is to reproduce the URL in four controlled paths—headful Chrome, headless Chrome without a proxy, headless Chrome through the production proxy, and a command-line client—while keeping the URL, method, credentials, and user-agent documented. The path that alone receives 456 points to the layer to investigate.
What HTTP 456 means in Chrome
HTTP status codes are extensible. RFC 7231 describes an unknown 4xx code as belonging to the client-error class, but it does not assign a universal definition to 456. Consequently, 456 might represent an allow-list rule, an account policy, a bot challenge, a proxy restriction, an authentication failure, or another vendor-specific condition. The number itself cannot tell you which one applies.
Do not assume that 456 means rate limiting, bot detection, or authentication. Find the emitting component first. A CDN or WAF may add a policy identifier; a proxy may add Via or its own Server value; an origin may return application JSON or HTML. The provider that generated the response—and its documentation or support team—is the only authoritative source for the private meaning.
#1 Best Overall
Capture the complete response before changing code
Save one failing transaction as an artifact. In browser automation, log the response event for every URL, not just the final page URL, because a redirect can end at 456.
- Request URL, HTTP method, timestamp, and redirect history.
- Status code, response headers, cookies, and a bounded copy of the response body.
Server,Via,Location, cache headers, request or trace IDs, and vendor-specific headers.- User agent, proxy route, authentication mode, viewport, and whether JavaScript was enabled.
- Any Chrome network error separately.
ERR_PROXY_CONNECTION_FAILED, TLS errors, and DNS failures are browser-level failures, not HTTP 456 responses.
Redact access tokens, session cookies, and personal data before sharing logs. Preserve the original request ID and timestamp so the provider can search its records.
Compare four execution paths
Run the same URL, method, credentials, and user-agent wherever possible. Change one variable at a time.
| Path | Example | What an exclusive 456 suggests |
|---|---|---|
| Headful Chrome | Open the URL normally with DevTools Network recording enabled. | A browser-visible policy, origin rule, or account condition if this path also fails. |
| Headless Chrome, direct | chrome --headless --remote-debugging-port=0 https://target.example |
Headless-specific cookies, JavaScript, TLS, headers, redirects, or fingerprint differences. |
| Headless Chrome, production proxy | Add the documented --proxy-server flag. |
The proxy, its credentials, routing policy, or a proxy-injected response. |
| Command-line client | curl -i -L https://target.example |
An origin/CDN response when browser-only behavior is absent; remember that curl does not execute page JavaScript. |
This comparison is a diagnostic inference, not a published prevalence statistic. If every path returns 456, start with the origin, WAF, account, or API policy. If only the proxied path does, investigate the intermediary. If only headless Chrome differs, inspect what the browser actually sent before rewriting automation code.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Make headless Chrome observable
Launch an inspectable session
Chrome for Developers documents launching headless mode with --remote-debugging-port. Port 0 asks Chrome to select an available port and print a WebSocket endpoint.
chrome --headless --remote-debugging-port=0 https://target.example
Copy the printed DevTools WebSocket address, open a separate headful Chrome window, navigate to chrome://inspect, choose Configure if needed, and inspect the listed target. Use the live DevTools panels to check the Network request, response body, console errors, cookies, redirects, and security details.
Keep the debugging endpoint on a trusted local interface. Do not expose it to the public network: a remote debugging connection can control the browser and read its data.
Capture 456 responses with Puppeteer
The following script records every response with status 456, including headers and a truncated body. Install Puppeteer in a test project with npm install puppeteer, then run node trace-456.js https://target.example.
Free tools Windows power users keep installed
One-click scans. No signup required.
const puppeteer = require('puppeteer');
(async () => {
const url = process.argv[2];
if (!url) throw new Error('Usage: node trace-456.js URL');
const browser = await puppeteer.launch({headless: true});
const page = await browser.newPage();
page.on('response', async (response) => {
if (response.status() !== 456) return;
console.log('456 URL:', response.url());
console.log('Headers:', response.headers());
try {
const body = await response.text();
console.log('Body:', body.slice(0, 4000));
} catch (error) {
console.log('Body unavailable:', error.message);
}
});
try {
await page.goto(url, {waitUntil: 'networkidle2', timeout: 90000});
} finally {
await browser.close();
}
})();
A page-load timeout does not prove that no 456 occurred; a subresource or an earlier redirect may have returned it. Keep the response log even when page.goto throws.
Inspect the same URL with Python
A direct HTTP client gives you a baseline without browser JavaScript. This script follows redirects and prints each intermediate status.
import sys
import requests
url = sys.argv[1]
response = requests.get(url, allow_redirects=True, timeout=30)
print('final:', response.status_code, response.url)
for item in response.history:
print('redirect:', item.status_code, item.url, '->', item.headers.get('Location'))
print('headers:', dict(response.headers))
print('body:', response.text[:4000])
Use the same authentication and relevant headers as the browser when making the comparison. A difference can be caused by missing cookies or JavaScript-generated tokens rather than by headless mode itself.
Test proxy routing deliberately
Chromium supports --proxy-server and --proxy-bypass-list. First reproduce the failure through the exact proxy used in production:
Rank #3
chrome --headless --remote-debugging-port=0
--proxy-server='http://proxy.example:8080'
https://target.example
Then perform a narrow bypass for only the target host:
chrome --headless --remote-debugging-port=0
--proxy-server='http://proxy.example:8080'
--proxy-bypass-list='*://target.example'
https://target.example
For a controlled direct fallback, Chromium accepts a proxy list containing direct://:
chrome --headless --remote-debugging-port=0
--proxy-server='http://proxy.example:8080,direct://'
https://target.example
Do not leave a broad bypass in production. It changes routing, may send sensitive traffic directly, and can hide the policy you are trying to diagnose. Verify the proxy scheme, hostname, port, credentials, and any PAC or environment configuration. A proxy that cannot connect usually produces a Chrome net error; a proxy that deliberately injects an HTTP response can produce 456.
Use headers and body to identify the emitting layer
Origin or application
If direct curl, headful Chrome, and both headless paths show the same body and request ID, the origin or its application policy is the leading candidate. Follow the site’s documented API authentication, robots, rate, or allow-list process. Send the provider the timestamp and request ID rather than guessing at a new user agent.
CDN or WAF
Look for challenge markers, policy names, CAPTCHA references, retry intervals, edge request IDs, or headers that identify a CDN/WAF. A redirect to a challenge page is evidence that the policy is in the redirect chain; record every hop. Ask the site owner to explain the policy and to allow the legitimate automation route when appropriate.
Proxy or gateway
A Via header, proxy-specific Server value, gateway request ID, or a response that appears only on the proxied path points to the intermediary. Check proxy credentials, routing rules, destination allow-lists, and whether the proxy rewrites headers or blocks the target category.
Apply the fix that matches the evidence
When the origin or WAF returns 456
- Use the provider’s supported API or authentication flow.
- Honor the documented request rate and retry guidance; do not create a retry storm.
- Complete any required allow-list or bot-verification process.
- Provide the request ID, URL, timestamp, and redacted response to support.
When the proxy returns 456
- Correct the proxy URL, scheme, credentials, and destination policy.
- Test a host-specific bypass only long enough to prove the source.
- Ask the proxy operator whether its policy intentionally emits 456 and what approval process applies.
When only headless Chrome differs
Inspect cookies, JavaScript completion, redirect timing, TLS details, viewport, and request headers in DevTools. Compare the actual request—not the settings you intended—with the headful request. A missing consent cookie or a script that has not completed can lead a policy to reject the session. Change one factor, rerun the four-path test, and keep the captured response for comparison.
When Chrome has a loading error instead
If no HTTP response exists and Chrome reports a connection, certificate, DNS, or proxy net error, troubleshoot that lower-level failure first. Check local connectivity, proxy interception, certificates, extensions, and the site owner’s availability. Do not label a non-HTTP failure as 456 merely because the page did not load.
Recommended Free Tools
Common symptoms and targeted fixes
| Symptom | Likely explanation | Next action |
|---|---|---|
| 456 from every client and network | Origin, account, or site-wide policy. | Read the body and headers; contact the provider with the request ID. |
| 456 only with the production proxy | Proxy or gateway policy, credentials, or route. | Run a narrow bypass and inspect Via, Server, and gateway IDs. |
| 456 only in headless mode | Different cookies, JavaScript state, redirects, TLS, viewport, or headers. | Inspect the live target through chrome://inspect and compare requests. |
| Final page is 456 after several redirects | A redirect target or challenge endpoint emitted it. | Log every response and each Location value. |
| Body names a CAPTCHA, policy, or retry interval | Provider-specific enforcement. | Follow that provider’s documented process; the number alone is insufficient. |
ERR_PROXY_CONNECTION_FAILED appears |
Chrome could not establish the proxy connection; this is not an HTTP response. | Fix proxy reachability, DNS, credentials, or TLS before analyzing status codes. |
Reliability, retries, and operational safety
Do not blindly retry an unknown 456. The response may represent a hard policy, and repeated attempts can worsen an account or WAF block. Retry only when the body or headers provide a documented interval, and use bounded exponential backoff with a request identifier in your logs.
For repeatable diagnosis, pin the Chrome version and proxy configuration, record the user agent and viewport, and run one variable change per experiment. Keep direct and proxied tests separate. A command-line client is useful for isolating network behavior but cannot prove that a JavaScript challenge would pass. Headless Chrome is more expensive than a single HTTP request in CPU and memory, so capture the smallest useful trace, close the browser after the test, and avoid high-concurrency retries while the emitting layer is unknown.
There is no authoritative statistic for how often HTTP 456 occurs or how often it is caused by headless Chrome. The standards and browser documentation establish how to classify and observe the response, not its prevalence.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
If your goal is to obtain a clean screenshot rather than diagnose your own Chrome session, ScreenshotNeo returns an image or PDF from one GET request. Its consent step accepts cookie banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be disabled. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and every response reports the result in X-Page-Verdict and X-Billed headers.
Use the API documentation at https://screenshotneo.com/docs/ for all parameters. This cURL request captures Stripe as a WebP file:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
The equivalent Python request is:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
In Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
const data = new Uint8Array(await res.arrayBuffer());
await require('node:fs').promises.writeFile('shot.webp', data);
ScreenshotNeo also provides an MCP server with take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. Its 63 options include full-page captures with lazy images loaded, CSS-selector element captures, dark mode, 12 device presets plus custom viewports, retina scale, PDF paper size/margins/orientation/page ranges, custom CSS and JavaScript, pre-capture clicks, hidden selectors, waits for selectors/delays/network idle, ad/tracker/request/resource blocking, custom headers/cookies/user agents and Authorization, timezone and geolocation, transparent backgrounds, resizing, TTL-controlled caching, signed image links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, a usage API, and an OpenAPI specification. Parameter names used by other screenshot APIs are accepted to ease migration.
| Plan | Included shots per month | Price |
|---|---|---|
| Free | 1,000 | No charge; no card |
| Starter | 3,000 | $5 |
| Growth | 15,000 | $15 |
| Pro | 60,000 | $39 |
| Scale | 250,000 | $99 |
| Business | 1,000,000 | $249 |
Yearly billing gives two months free, and every feature is available on every plan. Create a free ScreenshotNeo account to use 1,000 screenshots each month without a card.
FAQ
Can a 456 response tell me whether the request consumed an origin quota?
No. Quota accounting is private to the provider. Ask the origin, CDN/WAF, or proxy operator and include its request ID; the HTTP number does not expose billing or quota behavior.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsShould I make Chrome’s remote-debugging port reachable from another machine?
Only through a controlled, authenticated tunnel or secured development network. Keep the port local by default and firewall it, because a debugging client can control the browser and read cookies and page data.
Is changing the user agent a valid fix?
It can be required by a documented provider policy, but changing it without evidence destroys a useful comparison. First capture the original request and identify the emitting layer; then make the smallest policy-compliant change.
Frequently Asked Questions
Can a 456 response tell me whether the request consumed an origin quota?
No. Quota accounting is private to the provider; ask the origin, CDN/WAF, or proxy operator with the request ID.
Should I make Chrome’s remote-debugging port reachable from another machine?
Keep it local by default and firewall it. Use a secured tunnel only when necessary, because a debugging client can control the browser and read page data.
Is changing the user agent a valid fix?
Only when the provider documents that requirement. Capture the original request and identify the emitting layer before changing it.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

