Verified error fix

Error 520 — web server returns an unknown error

Cloudflare Error 520: Web Server Returns Unknown Error: direct meaning, scoped diagnosis, corrective action, official source, and linked current limit.

Platform · CloudflareHTTP 520 Verified Aug 22, 2026
Quick answer

Cloudflare received an empty, unknown, or unexpected response from the origin.

Verified Aug 22, 2026

Why does this error happen?

  • An origin crash, malformed response, oversized response headers, or protocol problem produced an unusable reply.
  • The effective account, plan, runtime, model, region, or deployment scope may be more restrictive than a headline platform maximum.
  • Retries or parallel workers can amplify the condition when they are not bounded or coordinated.

How do you diagnose it?

  1. Correlate the Ray ID and timestamp with origin and load-balancer logs, including response-header size.
  2. Correlate the provider request identifier and UTC timestamp with application logs and metrics without recording secrets.
  3. Reproduce with the smallest safe request and verify the exact account, plan, endpoint, region, runtime, or model involved.

How do you fix it?

  1. Correct the origin response, reduce oversized headers, and verify the origin directly before re-enabling proxy traffic.
  2. Retry only when the documented error is temporary; use bounded attempts, jitter, idempotency, and a dead-letter path.
  3. Verify recovery with a controlled request, then monitor the same limiter or failure signal under normal traffic.

How do you prevent it from recurring?

Turn the confirmed cause of Error 520 — web server returns an unknown error into an observable boundary for Cloudflare. Track the relevant request count, token volume, payload size, execution time, connection pressure, billing state, or upstream health before it reaches the documented failure condition. Preserve the platform request ID and timestamp so future incidents can be correlated without logging sensitive payloads.

Test the fix under representative concurrency and failure injection, not only with one successful request. Alert on remaining headroom and repeated retries, and keep the linked limit page and official error source with the runbook so responders can distinguish a configuration problem from temporary service pressure or account state.

Do not paste API keys, database URLs, tokens, or sensitive payloads into public error reports. Redact secrets before sharing diagnostics.
Related

Linked limits, tools, and alternatives