How to Fix a 502 Bad Gateway Error
Five checks to find which server failed, then fixes for visitors, proxy users and site owners, with retry code.
Updated
TL;DR
502 Bad Gateway means a server that passes requests on, such as your proxy, Cloudflare or a site's nginx, got an invalid response from the server behind it. Usually the site's own server failed: reload after a short wait, and leave a lasting 502 to the site owner.
How each gateway and client words a 502
The server that got the bad response writes the page, so its wording shows where to look.
| Where | What you see |
|---|---|
| nginx (default page, server_tokens off) | 502 Bad Gateway nginx |
| Apache httpd (mod_proxy) | Proxy Error The proxy server received an invalid response from an upstream server. The proxy server could not handle the request Reason: Error reading from remote server |
| Cloudflare, site's server failed (branded page) | Bad gateway. Error code 502. The web server reported a bad gateway error. |
| Cloudflare itself (plain page) | 502 Bad Gateway cloudflare |
| curl via a proxy on https:// (older curl prints 56) | curl: (7) CONNECT tunnel failed, response 502 |
| Chrome (502 with an empty body) | This page isn't working. example.com is currently unable to handle this request. HTTP ERROR 502 |
| Python requests (raise_for_status) | requests.exceptions.HTTPError: 502 Server Error: Bad Gateway for url: https://example.com/ |
Why this happens
A server in the middle could not get a proper answer from the site's server.
Often the app behind the site's nginx or Apache has crashed or is restarting. nginx keeps 504 for timeouts, so its 502 means the app refused the connection, hung up early or sent an unusable reply.
Diagnose your 502 first
The first three need only a browser; the last two take a terminal or access to the server.
Turn off your proxy or VPN and reload, then try mobile data; if the page loads, your proxy, VPN or network caused the 502.
Read the error page; an nginx, Proxy Error or Cloudflare-branded page means the site's server failed, a plain page reading cloudflare means Cloudflare did.
Open another site through the same proxy; if it loads, only the proxy's path to this site failed; if not, the proxy itself is failing.
Run curl -sS -o /dev/null -D - via the proxy; if the CONNECT response carries the 502, the proxy sent it, not the site.
If you run the site, find the nginx error log line for the 502; the words after 'while' name the stage that failed.
Solutions ranked by effectiveness
Each card matches one outcome of the checks, most common first.
- Most common fix
Give the site time, then reload
Applies when the 502 also shows without your proxy or VPN: the site's own server failed.
Do not resubmit a payment or order; look for a confirmation email first.
If it keeps failing, send the site owner the URL and the exact time.
- Check next
Retry the request from a new IP
When the site opens directly but not through your proxy, retry GET requests on a new connection with growing pauses. On a Geonode rotating port each request gets a new IP.
curl -sS -o /dev/null -w '%{http_code}\n' \ --retry 2 --retry-all-errors \ -x http://USERNAME:PASSWORD@proxy.geonode.io:9000 \ https://example.com/ - Site owners
Match the nginx log line to its fix
For a 502 from your own nginx, apply the fix for its log message and run nginx -t before reloading.
connect() failed (111: Connection refused): start the app, or fix the proxy_pass address.
connect() to unix:... failed (13: Permission denied): set PHP-FPM's listen.owner and listen.group to nginx's user.
upstream prematurely closed connection: check the app's own log for a crash at that moment.
upstream sent too big header: set proxy_buffer_size 16k and proxy_buffers 8 16k together.
Stop the 502 from coming back
Three settings for site owners, then one logging habit for scraper authors.
Run the app under systemd with Restart=on-failure, so it starts again by itself after a crash.
List two or more servers in the nginx upstream block; after an error on one, nginx tries the next.
Log $upstream_addr and $upstream_status in your nginx log_format to see which app server each 502 involved.
In scrapers, log each 502's proxy port and headers, never the password, so your provider can trace it.
Related errors
Learn more
FAQ
Hold one IP for hours
Sticky ports keep one residential IP for 3 minutes to 24 hours, as you choose.


