Introducing Highlights: the context that matters

What Is a 526 Status Code?

A 526 status code is a Cloudflare error, "Invalid SSL certificate", returned when Cloudflare cannot validate the origin server’s certificate while the SSL mode is Full (strict). The certificate may be expired, revoked, self-signed, missing the hostname, or served without its intermediate chain. Only the site owner can fix it.

Code
526
Name
Invalid SSL Certificate
Class
Cloudflare extension
Retry?
No, fix the cause first

What causes error 526?

  • →An expired or revoked certificate on the origin.
  • →A self-signed certificate rather than one issued by a certificate authority.
  • →The hostname missing from the certificate’s Common Name or Subject Alternative Names.
  • →An incomplete chain, or an origin that does not accept connections on port 443.

How do you fix error 526 when web scraping?

  • →Do not retry in a loop. Nothing changes until the certificate is fixed.
  • →Use a cached copy of the page, or check back later.

How do you fix error 526 on your own server?

  • →Renew or replace the certificate, or install a Cloudflare Origin CA certificate.
  • →Make sure the certificate covers the hostname and is served with its full chain on port 443.
  • →As a short-term fix, switch the zone from Full (strict) to Full while you repair the certificate.

How do you handle error 526 in a retry loop?

526 is not in RETRYABLE, so raise_for_status() raises on the first response instead of spending retries on a request that will fail the same way. Fix the cause, then send the request again.

import random
import time

import requests

RETRYABLE = {408, 429, 500, 502, 503, 504, 520, 521, 522, 523, 524}


def fetch(url: str, max_attempts: int = 5) -> requests.Response:
    for attempt in range(max_attempts):
        try:
            response = requests.get(url, timeout=(10, 60))
        except requests.Timeout:
            time.sleep(2**attempt + random.uniform(0, 1))
            continue
        if response.status_code not in RETRYABLE:
            response.raise_for_status()
            return response
        retry_after = response.headers.get("Retry-After", "")
        backoff = 2**attempt + random.uniform(0, 1)
        time.sleep(min(int(retry_after) if retry_after.isdigit() else backoff, 60))
    raise RuntimeError(f"Gave up on {url} after {max_attempts} attempts")

How does Context.dev handle error 526?

Context.dev retries the fetch for you, and by default Scrape can reuse a capture made in the last 3 days (maxAgeMs), so a page that is briefly down may still come back from cache. If no capture is available, the failed output carries an error_code and message inside an HTTP 200 response, and a request where every output fails is not charged.

See what the web scraping API does on every request, or read how to fix HTTP errors in web scraping for a longer walkthrough.

Frequently asked questions about error 526

What does error 526 invalid SSL certificate mean?

Cloudflare is set to strictly validate the origin’s certificate, and the certificate failed: expired, revoked, self-signed, wrong hostname, or incomplete chain.

Is error 526 a problem with my browser?

No. Your connection to Cloudflare is fine. The failed check is between Cloudflare and the site’s own server.

How do I fix a 526 error quickly?

Install a valid certificate on the origin, such as a free Cloudflare Origin CA certificate. Switching to Full mode removes the error but also removes certificate validation.

Which status codes are related to 526?

Sources

Last reviewed

Ship an agent that actually knows things.

Free tier, 10-minute integration, and the same API powering agents at Mintlify, daily.dev, and Propane. No credit card to start.