How to Fix Cloudflare Error 1015 (You Are Being Rate Limited)
Find out how long the block lasts and what tripped it, with paced request code for scripts.
Updated
TL;DR
Error 1015 is Cloudflare's reply when your requests go over a rate limiting rule that the website's owner set, so the site, not your browser or proxy, is turning you away for a while. Stop reloading, wait for the block to end, then try once.
What error 1015 looks like
Cloudflare picks the format from your client's request headers. The Discord rows come from Discord's own API limits.
| Where | What you see |
|---|---|
| Browser tab title (Chrome, Firefox, Edge, Safari) | Access denied | example.com used Cloudflare to restrict access | example.com | Cloudflare |
| Browser page, under What happened? | The owner of this website (example.com) has banned you temporarily from accessing this website. |
| curl or Python urllib with default headers | error code: 1015 |
| Python requests, raise_for_status() | 429 Client Error: Too Many Requests for url: https://example.com/ |
| Discord API, user or global limit | "message": "You are being rate limited." |
| Discord API, shared resource limit | "message": "The resource is being rate limited." |
Why this happens
The site lets each visitor make only so many requests, and you went over.
A rule that counts per IP address, an option on every Cloudflare plan, adds up your fast reloads or a script with no pauses along with requests from strangers on your VPN exit.
Diagnose your 1015 first
Each check points to one cause, so you know whether waiting alone will clear it.
Read the number on the error page; if it says 1020 instead of 1015, a firewall rule blocked you, not a rate limit.
Recall the minute before it appeared; if you reloaded fast or opened many tabs at once, your own burst tripped the rule.
Open What is my IP; if the ISP shown is a VPN provider or a mobile carrier, other people's requests can share your count.
Open another page on the same site; if it loads, the rule covers only some paths, such as the login page or an API.
In a script, print the body of the 429; if 1015 is missing, the site's own server or a custom limit page sent it.
Solutions ranked by effectiveness
Start at the top; the last two matter when the error keeps coming back.
- Most common fix
Stop reloading and wait it out
Applies in a browser. The block lifts on its own once the rule's time is up, and reloading meanwhile may extend it.
Close the tab and pause extensions that refresh or preload this site.
Turn off any VPN or free proxy, and keep it off for this site.
Try once after a few minutes; if 1015 returns, leave it for an hour.
- For developers
Pace your script and honor Retry-After
Applies to your own scripts. Send one request at a time with a pause; after a 429, wait Cloudflare's default 30 seconds, or longer if Retry-After asks, and stop if the retry gets 429 again.
for n in $(seq 1 50); do curl -sS --fail --retry 1 --retry-delay 30 -o "page-$n.html" \ -w "%{http_code} page $n\n" "https://example.com/page/$n" || break sleep 5 done - If nothing else works
Ask the owner for a higher limit
Applies when a legitimate job still needs more than the rule allows. Only the owner can change the rule, and Cloudflare support takes requests only from owners.
Send the site's support the Ray ID, UTC time, URL and your public IP.
Move recurring jobs to the site's official API or data export, inside its quota.
Ask for a key or a higher limit, saying what you collect and how often.
Stop the 1015 from coming back
Set these up once, before a recurring script's first run.
Store the site's cookies and send them on every request, so a site that counts by cookie sees one visitor.
Give all workers on a site one shared request budget, so adding a worker never raises the total rate.
Keep each 429's cf-ray header and timestamp in your logs; owners search their events by both.
Skip paths that robots.txt or the site's terms rule out, and recheck both before each new job.
Related errors
Learn more
FAQ
Connect scheduled jobs by IP
Whitelist your server's IP in Geonode once, and jobs connect without proxy credentials.


