What Is a 526 Status Code?
A 526 status code is a Cloudflare error, "Invalid SSL certificate", returned when Cloudflare cannot validate the origin server’s certificate while the SSL mode is Full (strict). The certificate may be expired, revoked, self-signed, missing the hostname, or served without its intermediate chain. Only the site owner can fix it.
- Code
- 526
- Name
- Invalid SSL Certificate
- Class
- Cloudflare extension
- Retry?
- No, fix the cause first
What causes error 526?
- →An expired or revoked certificate on the origin.
- →A self-signed certificate rather than one issued by a certificate authority.
- →The hostname missing from the certificate’s Common Name or Subject Alternative Names.
- →An incomplete chain, or an origin that does not accept connections on port 443.
How do you fix error 526 when web scraping?
- →Do not retry in a loop. Nothing changes until the certificate is fixed.
- →Use a cached copy of the page, or check back later.
How do you fix error 526 on your own server?
- →Renew or replace the certificate, or install a Cloudflare Origin CA certificate.
- →Make sure the certificate covers the hostname and is served with its full chain on port 443.
- →As a short-term fix, switch the zone from Full (strict) to Full while you repair the certificate.
How do you handle error 526 in a retry loop?
526 is not in RETRYABLE, so raise_for_status() raises on the first response instead of spending retries on a request that will fail the same way. Fix the cause, then send the request again.
import random
import time
import requests
RETRYABLE = {408, 429, 500, 502, 503, 504, 520, 521, 522, 523, 524}
def fetch(url: str, max_attempts: int = 5) -> requests.Response:
for attempt in range(max_attempts):
try:
response = requests.get(url, timeout=(10, 60))
except requests.Timeout:
time.sleep(2**attempt + random.uniform(0, 1))
continue
if response.status_code not in RETRYABLE:
response.raise_for_status()
return response
retry_after = response.headers.get("Retry-After", "")
backoff = 2**attempt + random.uniform(0, 1)
time.sleep(min(int(retry_after) if retry_after.isdigit() else backoff, 60))
raise RuntimeError(f"Gave up on {url} after {max_attempts} attempts")
How does Context.dev handle error 526?
Context.dev retries the fetch for you, and by default Scrape can reuse a capture made in the last 3 days (maxAgeMs), so a page that is briefly down may still come back from cache. If no capture is available, the failed output carries an error_code and message inside an HTTP 200 response, and a request where every output fails is not charged.
See what the web scraping API does on every request, or read how to fix HTTP errors in web scraping for a longer walkthrough.
Frequently asked questions about error 526
What does error 526 invalid SSL certificate mean?
Cloudflare is set to strictly validate the origin’s certificate, and the certificate failed: expired, revoked, self-signed, wrong hostname, or incomplete chain.
Is error 526 a problem with my browser?
No. Your connection to Cloudflare is fine. The failed check is between Cloudflare and the site’s own server.
How do I fix a 526 error quickly?
Install a valid certificate on the origin, such as a free Cloudflare Origin CA certificate. Switching to Full mode removes the error but also removes certificate validation.
Which status codes are related to 526?
Sources
Last reviewed