Cloudflare Error 1015 “You Are Being Rate Limited”: Causes and Fixes
Cloudflare error 1015 means you sent more requests than a site's rate limiting rule allows within its counting window, and Cloudflare is blocking you for a set period. The rule is written by the site owner, not by Cloudflare, and it expires on its own. Waiting works; so does sending fewer requests. Rotating IP addresses only helps if the rule counts by IP — and on many sites it counts by something else.
- troubleshooting
- cloudflare
- rate limiting
- 1015

Table of contents
Cloudflare's 1xxx codes each name the component that acted. 1015 is the rate limiter; its sibling 1020 is a firewall rule that never expires on its own. Mixing them up is the most expensive mistake here — one needs patience and pacing, the other needs a different request.
How a Cloudflare rate limiting rule works
A site owner defines three things: which requests count (for example, anything under /api/ or every POST to /login), how they are grouped (per IP by default), and the threshold — a number of requests within a counting period. Cross it, and Cloudflare applies the action for the mitigation period the owner chose.
| Setting | What it controls | Typical values |
|---|---|---|
| Matching expression | Which requests are counted | A path, method, host or content type |
| Counting characteristics | What one ‘visitor’ is | IP address; on higher plans also cookie, header, query, ASN, country or JA3/JA4 fingerprint |
| Threshold and period | How many requests per window | e.g. 100 requests per 10 seconds |
| Mitigation timeout | How long the block lasts | From seconds up to hours, set by the owner |
| Action | What happens when exceeded | Block (1015 page), managed challenge, or custom response |
Because each site writes its own rule, there is no universal ‘1015 limit’. A threshold that is generous on one site can be aggressive on another behind the same Cloudflare network.
How long does error 1015 last?
As long as the owner's mitigation timeout — commonly between ten seconds and an hour. If the response carries a Retry-After header, that is the number to wait. If not, back off exponentially from about thirty seconds and stop once a single request succeeds. Hammering the endpoint while blocked does not shorten the timer, and some rules count blocked requests too, so persistent retries keep you over the threshold indefinitely.
Fixing it as a normal visitor
- 1Wait a few minutes, then reload once — not repeatedly.
- 2Close duplicate tabs of the same site. Auto-refreshing dashboards and open tabs all count toward one limit.
- 3Pause extensions that prefetch or poll, such as price trackers and link previewers.
- 4Leave shared networks — office, university or mobile carrier NAT — where hundreds of people share your public IP and its budget.
- 5If it persists, contact the site with the Ray ID. Only the owner can see which rule fired and whether it is set too tight.
Fixing it as a developer or scraper
For automated traffic, a 1015 is useful information: you now know roughly where the threshold is. The fix is to stay under it, which means pacing first and spreading load second.
import random
import time
import requests
def polite_get(session: requests.Session, url: str, max_tries: int = 5):
delay = 30
for _ in range(max_tries):
r = session.get(url, timeout=30)
if r.status_code != 429:
return r
wait = int(r.headers.get("Retry-After", delay))
time.sleep(wait + random.uniform(0, 5))
delay = min(delay * 2, 900)
raise RuntimeError(f"still rate limited after {max_tries} tries: {url}")- Measure the threshold, then run at 60–70% of it. Slowly increase concurrency until the first 1015, note the rate, and back off well below it.
- Add jitter. Perfectly regular intervals are easier to spot than the threshold itself.
- Cache and deduplicate. The cheapest request is the one you do not send twice.
- Prefer the site's API or sitemap. They are often under a looser rule than the HTML front end.
Does rotating proxies fix 1015?
Only when the rule counts by IP address. Then each exit has its own budget, and spreading requests across a rotating residential pool multiplies the rate you can sustain. When the rule counts by something else, a new IP inherits the same counter:
| Rule counts by | Does a new IP help? | What does |
|---|---|---|
| IP address | Yes | Distribute load across exits |
| Session cookie | No | A fresh cookie jar per identity |
| API key or auth header | No | Stay within the key's quota |
| JA3/JA4 TLS fingerprint | No | Varying or realistic TLS clients |
| ASN | Only if the new IP is in another network | Residential or mobile instead of one hosting range |
The test is simple: hit the limit, then send one request from a fresh exit with the same cookies and client. If it passes, the counter is per IP. If it fails instantly, the counter is attached to something you carried across.
Spread load across real residential exits
Rotating residential from €1.20/GB with per-request or sticky sessions set in the username. Purchased data never expires.
If you own the site
- 1In Security → Events, filter to the rate limiting rule and check who it is catching.
- 2Raise the threshold or narrow the expression if real customers appear — shared corporate and carrier IPs are the usual collateral.
- 3Count by session cookie or API key rather than IP where users sit behind NAT.
- 4Use a managed challenge instead of a block for borderline traffic, so humans get through.
- 5Exclude your own uptime checks, webhooks and monitoring before they trip the rule.
Sources
Frequently asked questions
What does Cloudflare error 1015 mean?
You exceeded the request rate a website's Cloudflare rate limiting rule allows, and Cloudflare is temporarily blocking you. The rule and its limits are set by the site owner, not by Cloudflare.
How long does a Cloudflare 1015 ban last?
It lasts for the mitigation timeout the site owner configured, commonly from ten seconds to an hour. If the response includes a Retry-After header, wait that long. Continuing to send requests while blocked can keep you over the threshold.
Is error 1015 the same as HTTP 429?
Effectively yes. Cloudflare returns 1015 with an HTTP 429 Too Many Requests status by default, so clients should treat it as a rate limit and back off rather than as a permanent failure.
Will a VPN or proxy fix error 1015?
Only if the rule counts requests per IP address. If it counts by cookie, API key, TLS fingerprint or ASN, a new IP carries the same counter and the block continues.
What is the difference between Cloudflare 1015 and 1020?
1015 is a rate limit that expires by itself once you slow down. 1020 is a firewall rule that matched something about your request and will block it indefinitely until either the rule or the request changes.
The seamless team runs residential, ISP and datacenter proxy infrastructure and writes these guides from day-to-day operational experience.
Ready to try seamless proxies?
Residential, ISP and datacenter proxies with no data expiry.
Browse PlansKeep reading
HTTP 429 Too Many Requests: How Rate Limits Work and How to Survive Them
429 is the one error that gets worse the harder you try. Read the headers, back off properly, and spread load across identities instead of hammering one.
TroubleshootingCloudflare Error 1020 Access Denied: What Triggers It and How to Get Past It
1020 is not a rate limit and not a CAPTCHA — it is a rule someone wrote, matching something about your request. Finding out what it matched is the whole job.
GuidesHow to Avoid Getting Blocked When Web Scraping
The six layers a modern anti-bot system checks, in the order it checks them — and what to change at each one to stay unblocked.
