Cloudflare Error 524: A Timeout Occurred (Your Origin Is Too Slow)

524 means Cloudflare connected to your origin, but the response took over 100 seconds (free/pro plans). Your app really is too slow for the proxy's patience — cache, fix, or move long jobs to background work.

What you'll see

Root causes

Origin responses exceed the proxy timeout

Free/Pro plans cap at 100s. Slow DB queries, N+1s, or synchronous report generation regularly cross it. Time it yourself: curl -w '%{time_total}' against the origin.

Origin accepted the connection then stalled

Worker starvation, lock contention, or swap-death. The pattern: fast endpoints also degrade around the same time. Check load and slow query logs.

Fix it

  1. Measure the real response time at the origin
    curl -o /dev/null -s -w 'total: %{time_total}s\n' https://origin-host/heavy-endpoint
  2. Profile the slow endpoint's internals
    # enable slow-query log (MySQL long_query_time=1 / Postgres pg_stat_statements) + app-level timing around DB/HTTP calls
  3. Make slow work asynchronous
    # POST returns 202 + job id; client polls or gets a webhook. Long exports/reports must not occupy an HTTP request for minutes.
  4. Cache the expensive parts
    # Cache Rules / a page rule for the endpoint (short TTL beats computing), or Cloudflare Workers cache API for sub-request level caching
  5. If genuinely needed > 100s: Enterprise raises the limit
    # origin_response_timeout (Enterprise). On lower plans the answer is always: get under 100s or make it async.

Field note

524s leave the origin still running the request — users retry, the pile-up multiplies. Shed load early (queue + 202) instead. A slow endpoint behind Cloudflare also wrecks TTFB for everything else on that origin under concurrency — fixing it helps site-wide.

Common questions

Can I raise the 100-second limit on the free plan?

No — it's fixed on Free/Pro/Business. Enterprise can raise origin_response_timeout. On other plans the fix is architectural: async jobs, caching, or making the endpoint faster.

Why do users see 524 while my origin log shows a 200?

The origin finished after Cloudflare's 100s window. Cloudflare already answered the client with 524; your 200 went nowhere. That's the signal to go async or optimize below 100s.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.

Get new fixes by email

One short email when new fixes and production templates drop. No spam, unsubscribe anytime.

Partner pick — sponsored

Vultr — our lab-environment pick for this stack

Spin up a cloud server in 60 seconds and reproduce this fix yourself — pay by the hour.

Get Vultr →
Also vetted

Sentry — Free tier: see the exact line of code that broke, before users report it.

Get Sentry →

We earn a commission if you buy through our links — it never costs you extra. More vetted tools on our picks hub · comparing clouds? DigitalOcean vs Vultr and vs AWS · full deals: DigitalOcean · Vultr · NordLayer · Semrush