Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare Error 1015 means that a website has temporarily rate-limited your requests. The website owner configured a rule that permits only a certain number of requests within a time window, and Cloudflare is refusing more requests from your traffic. Wait, stop refreshing, and try again later. If the block continues, contact the website owner with the page URL, what you were doing, the approximate time, and the Cloudflare Ray ID shown on the error page.

If you own the site, inspect the matching Cloudflare rate-limiting rule: its expression, counting characteristic, threshold, period, action, and mitigation duration. Adjust it cautiously so legitimate users are not blocked while abusive traffic remains controlled.

What Error 1015 says

Cloudflare labels this page “Error 1015: You are being rate limited.” Its explanation is precise: The website owner has configured rate limiting rules that restrict how many requests a visitor can make to their site in a given time period. The limit may apply to an IP address, user, session, API key, path, or another counting characteristic selected by the site owner.

Rate limiting protects login forms, APIs, search endpoints, checkout pages, and other resources from excessive traffic. Cloudflare’s examples include brute-force login attempts and unusually high API-call rates. A legitimate visitor can still trigger the rule because of rapid navigation, automatic retries, a shared corporate or mobile IP address, a busy integration, or a threshold that is too strict.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do when you are visiting a site

  1. Stop refreshing and wait. Repeated attempts in a short period can extend the block. Close automated tabs, scripts, download managers, or integrations that may continue requesting the page.
  2. Check for a Retry-After header. Cloudflare’s March 12, 2026 guidance lists a default 30-second value for Error 1015 responses. A WAF rate-limiting rule can provide a dynamic value instead, so do not assume every block ends exactly after 30 seconds. Honor the value when it is present.
  3. Try once after the waiting period. Do not run a rapid series of retries. If the page loads, continue normally and reduce any automation that caused the burst.
  4. Contact the website owner if you remain blocked. The owner controls the rule. Include the URL, approximate time, the action that preceded the error, and the Cloudflare Ray ID. Ask the owner to check whether legitimate traffic was matched accidentally.

Changing networks, buying a VPN, reinstalling your browser, or purchasing networking equipment is not Cloudflare’s documented fix. Those actions can also look like attempts to evade a site’s controls. The practical remedy is to wait and work with the site owner.

Finding the useful details

  • Ray ID: Usually displayed near the bottom of the Cloudflare error page. Copy it exactly.
  • Retry-After: Inspect the response headers in browser developer tools or with a command-line client. Follow the number supplied by the server.
  • Request context: Record whether you were logging in, searching, submitting a form, loading an API, or using an automation tool.

What site owners should check

Log in to Cloudflare and review the WAF rate-limiting rules affecting the hostname and path. Identify the first rule that matched the request, then verify each setting before changing it.

1. Expression and scope

Confirm that the expression targets the intended host, URL path, method, country, authenticated state, or API route. A broad expression can rate-limit an entire site when only a login or write endpoint needed protection.

2. Counting characteristic

Check what Cloudflare counts: for example, source IP, session, authenticated identity, API token, or another configured characteristic. Counting only by IP can penalize offices, schools, mobile carriers, and other groups that share an address.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Threshold and period

Compare the allowed request count with normal traffic for that endpoint. Cloudflare gives a short-window example: if a rule blocks requests over one second, increasing the period to ten seconds may help. This is an example to evaluate against your traffic and security objectives, not a universal setting. A longer period with an appropriate total can be safer than permitting a very high one-second burst.

4. Action and mitigation duration

Review whether the action is Block, Challenge, or another configured response, and how long mitigation lasts. Cloudflare says actions apply for the configured duration or mitigation timeout by default. Rule order matters: actions such as Block can stop evaluation of later rules, so an earlier rule may explain why a more permissive rule never runs.

5. Legitimate clients and automation

Separate browsers, trusted integrations, health checks, and internal services from untrusted traffic using narrowly scoped expressions or appropriate authentication. Do not simply disable rate limiting. Instead, create a measured allowance for known clients and keep protective limits on sensitive operations.

6. Validate after a change

Test the exact URL and method that produced the error, then watch security events and application logs. Look for a lower false-positive rate without a corresponding rise in brute-force attempts, scraping, or API abuse. Document the old and new threshold, period, action, and duration so you can roll back safely.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Error 1015 versus HTTP 429

These labels describe different parts of a response. Cloudflare’s 1xxx overview explains that a 1xxx error is commonly identified in the response body, while HTTP errors such as 429 are represented by the status code in the response headers. A rate-limited request may therefore return HTTP 429 while displaying a Cloudflare 1015 page. They can appear together, but they are not interchangeable in every implementation.

For software clients, handle both the status code and the body. Read Retry-After when present, stop retrying until the indicated time, and use exponential backoff with jitter for subsequent requests. Do not treat a successful TCP connection or an HTML response as evidence that the application request succeeded.

Retry-After and machine-readable responses

Cloudflare’s March 12, 2026 changelog says retryable Cloudflare-generated 1xxx responses include a standard Retry-After header. Error 1015 has a documented default of 30 seconds, but a WAF rule’s dynamic value takes precedence. Your client should therefore parse the header rather than hard-code 30 seconds.

Cloudflare error responses can expose structured fields such as retryable, retry_after, owner_action_required, and what_you_should_do. The representation depends on the request’s Accept header and the site’s custom error configuration; a normal browser may receive HTML while an API client receives machine-readable data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Safe retry pattern

  1. Record the status, response body, Ray ID, and Retry-After value.
  2. If the response is retryable, suspend the queue for at least that duration.
  3. Add randomized backoff to prevent many workers from retrying simultaneously.
  4. Cap attempts and surface a clear error to the operator instead of looping indefinitely.
  5. Reduce concurrency or request frequency before resuming.

A separate 1015 case: cache purge failures

Cloudflare also documents Error 1015 for an “Unable to purge” cache-purge problem. This is not the ordinary visitor rate-limit page. If you are an owner and see 1015 while purging cache, retry the purge. If it continues to fail, contact Cloudflare support through the support options available to your Cloudflare plan.

Troubleshooting common symptoms

Symptom Likely cause Action
The error appears after many refreshes Your requests exceeded the owner’s threshold. Stop retrying, wait, then make one request.
Several coworkers see it at once A shared public IP is being counted together. Give the owner the Ray ID and explain the shared network.
Only an API client is blocked Concurrency, burst size, or token-specific counting is too high. Honor Retry-After, lower concurrency, and ask the owner about API limits.
The page shows 1015 with HTTP 429 A rate-limit response has both a transport status and Cloudflare body. Handle the 429 status and inspect Retry-After.
1015 appears during cache purge Cloudflare’s separate purge failure case. Retry the purge, then contact Cloudflare support if it persists.
The block returns immediately after a rule change Another rule, rule order, or a broader expression is still matching. Inspect security events and evaluate rules in order.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is to capture a page for documentation or monitoring rather than debug the block interactively, ScreenshotNeo provides a website screenshot API and MCP server. It accepts consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; only clean shots are billed. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP tools—take_screenshot, get_page_info, and capture_pdf—work with Claude, Cursor, and other MCP clients.

One GET request returns PNG, JPEG, WebP, or PDF. See the ScreenshotNeo API documentation for all options.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is included on every plan. Create a free ScreenshotNeo account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When Cloudflare support is appropriate

For an ordinary visitor block, Cloudflare directs you to the website owner because the owner controls the rate-limit policy. Cloudflare’s technical support guidance says only the site owner can contact Cloudflare about these 1xxx errors. Owners should use the support channel available to their current plan after checking the rule, logs, and Ray ID.

Frequently Asked Questions

Will Error 1015 clear after exactly 30 seconds?

Not necessarily. Cloudflare lists 30 seconds as the default Retry-After value, but a WAF rule can provide a dynamic value. Follow the header when present.

Can I bypass Error 1015 by changing my IP?

Cloudflare’s documented remedy is to wait and contact the website owner, not to evade the limit. Changing networks may also trigger another rule.

Who can change the rate limit?

The website owner or administrator controlling the Cloudflare zone. A visitor cannot edit the rule.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

Error 1015 is a temporary, owner-configured rate limit. Visitors should stop retrying, honor Retry-After, and contact the site owner with the Ray ID if the block persists; owners should tune the matching rule rather than disable protection blindly.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.