
Cloudflare error 524 "A timeout occurred" means Cloudflare opened a connection to your origin server and sent the request, but the origin did not return an HTTP response within the Proxy Read Timeout, currently 125 seconds. The server is up; it is just too slow for that request. The fix is on the origin side.
The error page shows three boxes, "You: Working", "Cloudflare: Working" and "Host: Error", plus a Ray ID you can match against logs. If you came here from Roblox: its error 524 is an unrelated in-game code and has nothing to do with websites.
What error 524 actually means
With the orange cloud enabled, a request travels over two separate connections: visitor to Cloudflare edge, and edge to your origin. A 524 is raised on the second leg, after the TCP connection succeeded and the origin acknowledged the request. That detail matters: the origin is reachable and accepting work, so this is not a firewall or DNS problem.
Per Cloudflare's connection limits reference, the Proxy Read Timeout is 125 seconds. You will still find "100 seconds" in many tutorials and forum answers; that value comes from older documentation. The limit is fixed on Free, Pro and Business plans. Enterprise zones can raise it to 6,000 seconds.
A second, rarely mentioned trigger returns the same code: the Proxy Write Timeout. If Cloudflare cannot finish sending the request body to the origin within 30 seconds, typically a large upload to a slow or saturated server, the visitor also gets a 524. That one is not adjustable on any plan.
One consequence catches many site owners out: when Cloudflare gives up, your application usually keeps running. The export finishes, the email is sent, the order is written. A user who clicks the button again after a 524 can create a duplicate.
Common causes
- Long-running work inside a request: CSV or XML exports, yearly reports, product imports, backups started from an admin panel, bulk image processing.
- Slow database queries: missing indexes, full scans of large tables, row locks held by another transaction.
- Third-party APIs without a timeout: a payment gateway or CRM stops responding and your HTTP client waits indefinitely.
- An overloaded origin: every PHP-FPM child or app worker is busy, so even a light page waits in the queue. Bot floods, newsletter traffic and sales are typical triggers.
- Origin timeouts set higher than Cloudflare's: if nginx and PHP are allowed to wait 300 seconds, the origin waits patiently while the edge has already given up.
If you are a visitor
Nothing on your device is involved, so clearing the browser cache, switching DNS resolvers or restarting the router will not help. Wait a few minutes and reload. Before resubmitting a payment or a form, check your email or account: the action may have gone through. If the error persists, send the site owner the time and the Ray ID. A global incident is easy to rule out on the Cloudflare status page, but 524 is almost always specific to one site.
How to fix error 524 on your site
1. Find the request that runs too long
nginx does not log request duration by default. Add a custom log_format with the timing fields and the Ray ID:
# http block
log_format timed '$remote_addr [$time_local] "$request" $status '
'$request_time $upstream_response_time "$http_cf_ray"';
# server block
access_log /var/log/nginx/access_timed.log timed;
Reload with nginx -t && systemctl reload nginx, then list requests slower than 60 seconds:
awk '$(NF-2) > 60' /var/log/nginx/access_timed.log | tail -n 20
Long requests logged with status 499 are the classic fingerprint of a 524: nginx uses that code when the client, here Cloudflare, closes the connection before the response is ready. On Apache, add %D (microseconds) to your LogFormat for the same effect. More on reading these files in our nginx logs guide.
2. Time the origin directly
Skip the proxy and measure how long the origin itself takes. --resolve pins the hostname to the origin IP; -k is needed if the origin uses a Cloudflare Origin CA certificate, which public clients do not trust.
curl -sk -o /dev/null \
-w "code=%{http_code} ttfb=%{time_starttransfer}s total=%{time_total}s\n" \
--resolve example.com:443:203.0.113.10 https://example.com/admin/export
On Windows 10 and 11, use curl.exe in PowerShell (plain curl is an alias for Invoke-WebRequest) and -o NUL instead of /dev/null. A time to first byte close to 125 seconds confirms the diagnosis.
3. See what the server is busy with
For PHP, enable the PHP-FPM slow log (request_slowlog_timeout = 10s and a slowlog path in the pool config): it dumps a stack trace of every script running past the threshold. The message server reached pm.max_children setting in the FPM log means requests are queuing. In MySQL or MariaDB, SHOW FULL PROCESSLIST; reveals stuck queries, and SET GLOBAL slow_query_log = 1; with a low long_query_time collects the slow ones. Give every outbound HTTP call a timeout so a hung API cannot hang your pages.
4. Move long work out of the request
This is the durable fix, and the one Cloudflare itself recommends as status polling:
- The request enqueues a job and immediately returns
202 Acceptedwith a job ID. - A background worker or cron job does the work, free of any edge timeout.
- The page polls something like
/jobs/123/statusevery few seconds and shows progress. - When the job is done, the user gets a download link or an email.
Laravel queues, Symfony Messenger, Celery, Sidekiq and BullMQ all cover this pattern. For WordPress, run imports, search-replace and backups through WP-CLI over SSH instead of wp-admin.
5. Use a DNS-only subdomain for heavy admin tasks
If some operations are unavoidably slow, put them on a subdomain such as ops.example.com and set its record to DNS only (grey cloud). Traffic then goes straight to the origin with no 125-second cap. Two trade-offs: the origin IP becomes public, so lock the subdomain down with an IP allowlist or authentication, and it needs its own publicly trusted certificate, since Origin CA certificates are not accepted by browsers.
6. Stream the response when the task allows it
Output that is produced row by row, such as a large CSV, can be streamed: headers go out at once and data follows as it is ready. Buffering must be off end to end, with flush() in PHP and fastcgi_buffering off; or an X-Accel-Buffering: no header in nginx. Test through Cloudflare on a staging URL before relying on it.
7. Enterprise: raise the Proxy Read Timeout
Enterprise zones can raise the limit up to 6,000 seconds with a Cache Rule using the Proxy Read Timeout setting or zone-wide via the API, as described in the Cloudflare error 524 documentation. Other plans have no such switch.
What does not help
Raising fastcgi_read_timeout, proxy_read_timeout or max_execution_time past 125 seconds changes nothing, because the edge still stops waiting. The opposite is more useful: keep origin timeouts slightly below Cloudflare's, so a runaway request is killed by your own nginx with a 504 and a clear error.log entry. Pausing Cloudflare is fine as a quick test, not as a fix.
Cloudflare 520, 521, 522, 523, 524, 525 and 526 compared
The 52x codes are not part of the HTTP standard; Cloudflare generates them to describe where the conversation with your origin broke down.
| Code | Message | What happened | Look at |
|---|---|---|---|
| 520 | Web server is returning an unknown error | Empty, malformed or unexpected response | Crashes, response headers over 128 KB, HTTP/2 on the origin |
| 521 | Web server is down | Origin refused the connection | Web server stopped, firewall blocking Cloudflare IPs |
| 522 | Connection timed out | TCP connection not completed in 19 seconds | Overload, firewall drops, packet loss |
| 523 | Origin is unreachable | No route to the origin | Wrong IP in A/AAAA records, routing |
| 524 | A timeout occurred | Connected, request accepted, no response in 125 seconds | Slow code, database, worker queue |
| 525 | SSL handshake failed | TLS handshake with the origin failed | Protocols, ciphers, SNI, port 443 |
| 526 | Invalid SSL certificate | Origin certificate rejected in Full (strict) mode | Expiry, hostname mismatch, incomplete chain |
For 521, allow all Cloudflare IP ranges and make sure the origin listens on port 80 for Flexible or 443 for Full and Full (strict). Detailed walkthroughs: error 522 Connection Timed Out and error 525 SSL Handshake Failed.
524 vs 504
Both are timeouts, raised by different hops. A 504 comes from a gateway you run, usually nginx in front of PHP-FPM, when the backend exceeds its timeout (60 seconds by default). A 524 comes from Cloudflare when the whole origin stays silent. A Cloudflare-styled page showing 504 rather than 524 usually means your own nginx timed out first. See 504 Gateway Timeout for that case.
How to check
- HTTP header check shows the status code, response time and headers;
server: cloudflareandcf-rayconfirm the request went through the proxy. - DNS lookup shows which records point at Cloudflare and which at the origin, useful for 523 and for a DNS-only subdomain.
- Uptime monitoring checks a URL on a schedule, keeps response-time history and alerts on 5xx, so creeping latency shows up before it becomes a 524.
To tell a site outage from a local connection problem, use the checklist in how to check if a website is down.
Frequently asked questions
Is error 524 a Cloudflare outage?
No. Cloudflare reports that your origin did not answer in time; its own network is marked "Working" on the error page.
How long does Cloudflare wait before a 524?
125 seconds for the response and 30 seconds to deliver the request body. Only the first is adjustable, on Enterprise, up to 6,000 seconds.
Why do I only see 524 in the admin panel?
That is where exports, imports, price recalculations and backups run. Move them to background jobs or a DNS-only subdomain.
Did my request go through if I got a 524?
Often yes. The origin keeps working after Cloudflare stops waiting, so check your account or inbox before retrying a payment.
Can I just turn Cloudflare off?
Only to test. You lose caching and protection, and the slow request will then hit your own server timeouts instead.