HTTP

HTTP 405 Method Not Allowed vs 526 Invalid SSL Certificate

HTTP 405 (Method Not Allowed) is a 4xx Client Error response, while 526 (Invalid SSL Certificate) is a 5xx Server Error response. 405 indicates that the HTTP method is not allowed for the requested resource. The response includes an Allow header listing valid methods. In contrast, 526 means that cloudflare-specific. The origin's SSL certificate could not be validated.

Description

The HTTP method is not allowed for the requested resource. The response includes an Allow header listing valid methods.

When You See It

When sending POST to a read-only endpoint, or DELETE to a non-deletable resource.

How to Fix

Check the Allow response header for supported methods. Use the correct HTTP method.

Description

Cloudflare-specific. The origin's SSL certificate could not be validated.

When You See It

When using Cloudflare Full (Strict) mode with an invalid origin certificate.

How to Fix

Install a valid SSL certificate on the origin, or use Cloudflare Origin CA certificate.

Key Differences

1.

405 is a 4xx Client Error response, while 526 is a 5xx Server Error response.

2.

HTTP 405: The HTTP method is not allowed for the requested resource. The response includes an Allow header listing valid methods.

3.

HTTP 526: Cloudflare-specific. The origin's SSL certificate could not be validated.

4.

You encounter 405 when when sending POST to a read-only endpoint, or DELETE to a non-deletable resource.

5.

You encounter 526 when when using Cloudflare Full (Strict) mode with an invalid origin certificate.

When to Use Which

For 405 (Method Not Allowed): Check the Allow response header for supported methods. Use the correct HTTP method. For 526 (Invalid SSL Certificate): Install a valid SSL certificate on the origin, or use Cloudflare Origin CA certificate.

Learn More