Geonode logo
Website blocks

How to Fix Cloudflare Error 1015 (You Are Being Rate Limited)

Find out how long the block lasts and what tripped it, with paced request code for scripts.

Updated

TL;DR

Error 1015 is Cloudflare's reply when your requests go over a rate limiting rule that the website's owner set, so the site, not your browser or proxy, is turning you away for a while. Stop reloading, wait for the block to end, then try once.

What error 1015 looks like

Cloudflare picks the format from your client's request headers. The Discord rows come from Discord's own API limits.

WhereWhat you see
Browser tab title (Chrome, Firefox, Edge, Safari)Access denied | example.com used Cloudflare to restrict access | example.com | Cloudflare
Browser page, under What happened?The owner of this website (example.com) has banned you temporarily from accessing this website.
curl or Python urllib with default headerserror code: 1015
Python requests, raise_for_status()429 Client Error: Too Many Requests for url: https://example.com/
Discord API, user or global limit"message": "You are being rate limited."
Discord API, shared resource limit"message": "The resource is being rate limited."

Why this happens

The site lets each visitor make only so many requests, and you went over.

A rule that counts per IP address, an option on every Cloudflare plan, adds up your fast reloads or a script with no pauses along with requests from strangers on your VPN exit.

Diagnose your 1015 first

Each check points to one cause, so you know whether waiting alone will clear it.

  • Read the number on the error page; if it says 1020 instead of 1015, a firewall rule blocked you, not a rate limit.

  • Recall the minute before it appeared; if you reloaded fast or opened many tabs at once, your own burst tripped the rule.

  • Open What is my IP; if the ISP shown is a VPN provider or a mobile carrier, other people's requests can share your count.

  • Open another page on the same site; if it loads, the rule covers only some paths, such as the login page or an API.

  • In a script, print the body of the 429; if 1015 is missing, the site's own server or a custom limit page sent it.

Solutions ranked by effectiveness

Start at the top; the last two matter when the error keeps coming back.

  1. Most common fix

    Stop reloading and wait it out

    Applies in a browser. The block lifts on its own once the rule's time is up, and reloading meanwhile may extend it.

    1. Close the tab and pause extensions that refresh or preload this site.

    2. Turn off any VPN or free proxy, and keep it off for this site.

    3. Try once after a few minutes; if 1015 returns, leave it for an hour.

  2. For developers

    Pace your script and honor Retry-After

    Applies to your own scripts. Send one request at a time with a pause; after a 429, wait Cloudflare's default 30 seconds, or longer if Retry-After asks, and stop if the retry gets 429 again.

    for n in $(seq 1 50); do
      curl -sS --fail --retry 1 --retry-delay 30 -o "page-$n.html" \
        -w "%{http_code} page $n\n" "https://example.com/page/$n" || break
      sleep 5
    done
  3. If nothing else works

    Ask the owner for a higher limit

    Applies when a legitimate job still needs more than the rule allows. Only the owner can change the rule, and Cloudflare support takes requests only from owners.

    1. Send the site's support the Ray ID, UTC time, URL and your public IP.

    2. Move recurring jobs to the site's official API or data export, inside its quota.

    3. Ask for a key or a higher limit, saying what you collect and how often.

Stop the 1015 from coming back

Set these up once, before a recurring script's first run.

  1. Store the site's cookies and send them on every request, so a site that counts by cookie sees one visitor.

  2. Give all workers on a site one shared request budget, so adding a worker never raises the total rate.

  3. Keep each 429's cf-ray header and timestamp in your logs; owners search their events by both.

  4. Skip paths that robots.txt or the site's terms rule out, and recheck both before each new job.

Keep your job on one IPSticky ports hold a residential IP for up to 24 hours while you pace requests.
Try residential proxies

Related errors

Learn more

FAQ

It means a rate limiting rule the website's owner set in Cloudflare counted too many requests from you, so Cloudflare answers with HTTP 429 until the block time ends. The owner decides who gets limited, not Cloudflare.

Send nothing to that site until the owner's timer runs out, then come back once from your normal connection. Scripts need a pause between requests before they restart.

It depends on the site's Cloudflare plan: 10 seconds on Free, up to an hour on Pro and up to a day on Business. Enterprise owners can set their own length, or block only the requests over the limit.

A rule can count only failed requests, so a few wrong passwords may trip it. On sites that count by cookie, private windows on a shared network all fall into one counter.

Discord's API sends that message in its own 429 when a bot or user goes over a per-route or global limit. Wait the seconds given in retry_after or the Retry-After header, as Discord's docs advise, before sending again.

It means the Discord resource you called hit its per-resource limit, not your own (X-RateLimit-Scope: shared). Such 429s do not count toward the 10,000 invalid requests per 10 minutes that get an IP temporarily banned.

Connect scheduled jobs by IP

Whitelist your server's IP in Geonode once, and jobs connect without proxy credentials.