# Cloudflare Upload Limits: Plan Caps, Error 413, and Workarounds

Cloudflare restricts client request bodies passing through its edge proxy to 100 MB on Free and Pro tiers, 200 MB on Business, and 500 MB by default on Enterprise. Uploads exceeding these limits trigger an HTTP 413 Payload Too Large error before reaching the origin server. Resolving these caps requires chunked uploads, unproxied DNS subdomains, direct object storage uploads, or connecting persistent workspaces where AI agents and teams access large files without hitting proxy bottlenecks.

Source: https://fast.io/resources/cloudflare-upload-limit/
Author: [Derek Labian](https://fast.io/authors/derek-labian/)
Last reviewed: 2026-10-04

## What Are the Cloudflare Upload Limits Across Plan Tiers?

The Cloudflare upload limit restricts the maximum client request body size that passes through Cloudflare proxy network: 100 MB for Free and Pro tiers, 200 MB for Business, and 500 MB by default on Enterprise. According to official Cloudflare documentation, any incoming HTTP request that exceeds the plan threshold is rejected at the network edge with an HTTP 413 status code before traversing to the origin server.

Cloudflare enforces these limits on the raw HTTP request body. When a browser, mobile application, or automated client issues an HTTP POST, PUT, or PATCH request containing file data or JSON payloads, Cloudflare edge servers inspect the `Content-Length` header and incoming byte stream. If the payload surpasses the plan ceiling, Cloudflare drops the connection immediately.

| Cloudflare Plan Tier | Default Maximum Upload Size | Maximum Configurable Limit | Triggered HTTP Error Status | Configuration Location |
| :--- | :--- | :--- | :--- | :--- |
| Free | 100 MB | 100 MB (Fixed) | HTTP 413 (Payload Too Large) | Locked to plan tier |
| Pro | 100 MB | 100 MB (Fixed) | HTTP 413 (Payload Too Large) | Locked to plan tier |
| Business | 200 MB | 200 MB (Fixed) | HTTP 413 (Payload Too Large) | Locked to plan tier |
| Enterprise | 500 MB | Up to 5 GB (Dashboard) / Custom (Support) | HTTP 413 (Payload Too Large) | Zone Network settings |

Understanding these boundaries is essential when designing web ingestion pipelines, media platforms, and data synchronization services. While standard file attachments fit easily within default proxy thresholds, workflows break down quickly when users upload raw video footage, database dumps, software installers, or machine learning datasets.

### Request Body Versus Response Body Boundaries

A common misconception among developers is that Cloudflare limits the size of files that can be downloaded from an origin server. The upload limit applies strictly to the client request body, meaning Cloudflare does not restrict the size of HTTP response bodies streamed back from your origin application.

An application can stream multi-gigabyte files back to a user through Cloudflare proxy without triggering an upload size error. However, edge caching rules introduce separate boundaries. Assets exceeding Cloudflare edge caching thresholds pass through the network as uncached streams directly from the origin, consuming origin bandwidth rather than serving from edge cache points of presence.

### Cloudflare Workers and Cloudflare Pages File Size Ceilings

Developers deploying serverless applications on Cloudflare must also account for product-specific upload boundaries:

* **Cloudflare Workers:** When an incoming request targets a Cloudflare Worker, the maximum request body size matches the zone's account plan: 100 MB on Free and Pro, 200 MB on Business, and 500 MB by default on Enterprise. Attempting to post a larger payload to a Worker route returns HTTP 413 before the Worker script executes.
* **Cloudflare Pages:** Cloudflare Pages enforces a strict maximum file size of 25 MiB for any individual static site asset. If a deployment contains a static asset larger than the platform limit, the Pages build pipeline rejects the asset. Cloudflare recommends hosting assets larger than 25 MiB in external object storage rather than within the static Pages repository.

## Why Cloudflare Returns HTTP Error 413 Payload Too Large

HTTP status code 413, defined in RFC 9110 as "Payload Too Large" and historically labeled "Request Entity Too Large", indicates that the receiving web server refuses to process a request because the request payload exceeds configured limits. When operating behind Cloudflare, an HTTP 413 error can originate from two completely different infrastructure layers: the Cloudflare edge proxy or your origin web server.

Diagnosing the exact origin of an HTTP 413 error determines how you resolve it.

### Edge Rejection Versus Origin Rejection

When Cloudflare edge drops an oversized upload, the rejection occurs entirely within Cloudflare global network:

1. **Edge Rejection:** The client initiates an upload exceeding the zone threshold (for example, a 120 MB file on a Free plan). Cloudflare edge proxy reads the incoming headers, identifies that the payload exceeds 100 MB, and immediately sends an HTTP 413 response. The connection closes, and zero bytes reach your origin server. Your origin access logs will not record any entry for this request. The response headers include `Server: cloudflare` and a unique `cf-ray` identifier.
2. **Origin Rejection:** If your Cloudflare plan allows the upload (for example, a 150 MB file on a Business plan) or if traffic bypasses the proxy, Cloudflare forwards the stream to your origin server. If your origin web server (such as Nginx, Apache, or Caddy) has a lower request body ceiling, the origin rejects the upload and returns an HTTP 413 error back through Cloudflare to the client.

To verify whether Cloudflare or your origin server generates the 413 error, inspect the response headers using a command-line client:

```bash
curl -v -X POST https://example.com/api/upload         -H "Content-Type: application/octet-stream"         --data-binary "@dataset-archive.zip"
```

If the response body displays the default Cloudflare error page with text reading "Error 413: Request Entity Too Large" and includes a Cloudflare Ray ID, the proxy edge terminated the transfer. If the response displays a raw Nginx or Apache error page, your origin server rejected the payload.

### Connection Timeouts and Latency Failures

In addition to hard file size limits, very large uploads introduce connection timeout risks. Cloudflare enforces standard HTTP request timeouts between the edge and the origin. If an upload connection stalls or if the origin takes longer than 100 seconds to respond after receiving headers, Cloudflare terminates the connection with an HTTP 524 Gateway Timeout error.

On slower network connections, uploading a large archive can take several minutes. Even when an upload remains strictly under the plan tier cap, TCP connection drops or origin read timeouts can abort the transfer mid-stream. Applications handling substantial uploads require fault-tolerant transfer mechanics.

## How to Bypass and Resolve the Cloudflare 100MB Upload Limit

When application requirements dictate transferring files that exceed Cloudflare upload limits, engineering teams use three proven architectural strategies: client-side chunked uploads, unproxied DNS subdomains, or direct-to-storage presigned uploads. Upgrading to an Enterprise plan is also an option, but technical workarounds allow teams to transfer large payloads reliably on any plan.

### 1. Slicing Files with Client-Side Chunked Uploads

Client-side chunking is the most resilient approach for uploading large files through Cloudflare proxy. Instead of sending a multi-gigabyte file in a single monolithic HTTP request, the client application divides the file into smaller byte chunks, uploads each chunk sequentially or in parallel, and reassembles the complete file on the server.

Because each individual chunk measures between 5 MB and 20 MB, every HTTP request stays well below the 100 MB Cloudflare ceiling.

Here is an implementation using the browser standard HTML5 File API and `Blob.slice()`:

```javascript
async function uploadLargeFileInChunks(file, targetUrl) {
  const CHUNK_SIZE = 10 * 1024 * 1024; // 10 MB per chunk
  const totalChunks = Math.ceil(file.size / CHUNK_SIZE);
  const fileId = `${Date.now()}-${file.name.replace(/[^a-zA-Z0-9.-]/g, "_")}`;
  for (let chunkIndex = 0; chunkIndex < totalChunks; chunkIndex++) {
    const start = chunkIndex * CHUNK_SIZE;
    const end = Math.min(start + CHUNK_SIZE, file.size);
    const chunkBlob = file.slice(start, end);
    const response = await fetch(targetUrl, {
      method: "POST",
      headers: {
        "Content-Type": "application/octet-stream",
        "X-Upload-File-Id": fileId,
        "X-Upload-Chunk-Index": chunkIndex.toString(),
        "X-Upload-Total-Chunks": totalChunks.toString(),
        "X-Upload-File-Name": encodeURIComponent(file.name),
      },
      body: chunkBlob,
    });
    if (!response.ok) {
      throw new Error(`Chunk ${chunkIndex + 1}/${totalChunks} failed with status ${response.status}`);
    }
  }
  return { fileId, status: "completed" };
}
```

Chunked uploads offer multiple advantages beyond bypassing proxy limits:

* **Pause and Resume:** If a network connection drops during a multi-gigabyte transfer, the client only re-transmits the failed chunk rather than restarting the entire file.
* **Progress Tracking:** Applications can calculate precise upload percentages based on confirmed chunk responses.
* **Edge Compatibility:** Every request conforms to standard Cloudflare proxy thresholds, preserving DDoS protection and Web Application Firewall (WAF) filtering.

Open-source upload protocols such as Tus (tus.io) and Uppy implement standardized chunking, pause, and resume mechanics across web and mobile clients.

### 2. The DNS-Only Subdomain Pattern

If rewriting client code to support chunked uploads is impractical, teams can bypass the Cloudflare proxy entirely using a dedicated subdomain.

In the Cloudflare dashboard under **DNS** > **Records**, create a new `A` or `CNAME` record specifically for file ingestion (for example, `upload.example.com` or `direct.example.com`). Set the proxy status toggle to **DNS only** (represented by a grey cloud icon) rather than **Proxied** (orange cloud).

When users or client applications upload files to `https://upload.example.com/api/upload`, traffic routes directly to the origin server IP address. Because traffic never traverses the Cloudflare proxy edge, the 100 MB upload limit does not apply.

| Architectural Tradeoff | Proxied Record (Orange Cloud) | DNS-Only Record (Grey Cloud) |
| :--- | :--- | :--- |
| Maximum Upload Size | Capped at 100 MB, 200 MB, or 500 MB | Unlimited by Cloudflare (origin limits apply) |
| DDoS and Flood Protection | Cloudflare global Anycast scrubbing | None (traffic hits origin IP directly) |
| Web Application Firewall (WAF) | Active on incoming HTTP requests | Inactive (origin must filter attacks) |
| Origin IP Visibility | Hidden behind Cloudflare Anycast IPs | Exposed in public DNS lookups |
| Edge SSL / TLS Termination | Handled automatically by Cloudflare | Managed directly on origin server |

To mitigate the security risks of an unproxied subdomain, configure origin firewall rules (such as `iptables` or cloud security groups) to restrict the DNS-only hostname to authenticated API clients or specific internal network ranges.

### 3. Direct-to-Storage Architecture with Presigned URLs

The recommended architectural pattern for modern web applications decouples file storage from application servers. Instead of routing multi-gigabyte files through web servers and edge proxies, clients upload directly to cloud object storage using temporary presigned URLs.

The workflow executes in three steps:

1. **Request Presigned URL:** The client sends a lightweight JSON request to your API (`POST /api/uploads/request-url`) describing the file name, size, and MIME type.
2. **Generate Signed Target:** Your backend application validates authentication and calls the storage provider API to generate a temporary presigned upload URL with an expiration window (such as 15 minutes).
3. **Direct Upload:** The client uploads the binary payload directly to the storage bucket endpoint using HTTP PUT.

Because the upload target is an object storage bucket (such as AWS S3, Cloudflare R2, or Google Cloud Storage), the upload completely bypasses your application server and the 100 MB proxy limit. Cloudflare R2 supports massive multi-terabyte objects via S3-compatible multipart uploads, and charges zero egress fees.

## Configuring Web Servers and Reverse Proxies Behind Cloudflare

If an Enterprise organization raises their Cloudflare upload limit to 500 MB or 2 GB, or if a team routes uploads through a DNS-only subdomain, the origin web servers must be explicitly configured to accept larger payloads. By default, most web servers and reverse proxies enforce conservative body size caps that reject large files with their own local HTTP 413 errors.

### Nginx Configuration

In Nginx, the `client_max_body_size` directive controls the maximum allowed size of a client request body. The default value is `1m` (1 megabyte).

To support large uploads, adjust the directive inside the `http`, `server`, or specific upload `location` block in `/etc/nginx/nginx.conf`:

```nginx
http {
    client_max_body_size 500M;
    client_body_buffer_size 256k;
    client_body_timeout 300s;
    send_timeout 300s;
    server {
        listen 443 ssl http2;
        server_name upload.example.com;
        location /api/upload {
            proxy_pass http://backend_upstream;
            proxy_read_timeout 300s;
            proxy_connect_timeout 75s;
            proxy_send_timeout 300s;
            proxy_request_buffering off;
            proxy_http_version 1.1;
        }
    }
}
```

Disabling `proxy_request_buffering` instructs Nginx to stream incoming bytes directly to the upstream application as they arrive, reducing disk I/O bottlenecks and memory usage during multi-hundred-megabyte transfers.

### Apache Configuration

In Apache HTTP Server, the `LimitRequestBody` directive specifies the maximum number of bytes allowed in a request body, accepting values up to two gigabytes or zero for unlimited.

Add or adjust the directive in your VirtualHost configuration or `.htaccess` file:

```apache
<VirtualHost *:443>
    ServerName upload.example.com
    LimitRequestBody 524288000
    TimeOut 300
</VirtualHost>
```

### Application Runtime Configurations

Behind the reverse proxy, application runtimes also enforce payload limits:

* **Node.js and Express:** If an application parses JSON or URL-encoded bodies, the default body-parser limit is `100 KB`. Increase the threshold explicitly:
 

```javascript
  app.use(express.json({ limit: "100mb" }));
  app.use(express.urlencoded({ limit: "100mb", extended: true }));
 

```
  For binary multipart file uploads, avoid loading entire payloads into memory. Use streaming middleware like `busboy` or configure `multer` with disk storage and explicit file size boundaries.
* **PHP Runtime (`php.ini`):** PHP enforces upload caps through multiple interconnected directives. To allow `500 MB` uploads, adjust all four values:
 

```ini
  upload_max_filesize = 500M
  post_max_size = 512M
  memory_limit = 512M
  max_execution_time = 300
  max_input_time = 300
 

```
  The `post_max_size` setting must always be larger than `upload_max_filesize` to accommodate multipart headers and accompanying form data.

## Managing Large Datasets and AI Agent Files in Intelligent Workspaces

As development teams deploy autonomous AI agents, data engineering pipelines, and multi-modal models, file volume constraints become an operational hurdle. AI coding agents such as Claude Code, Cursor, Codex, and Gemini frequently generate, analyze, and exchange multi-gigabyte software artifacts, database exports, and technical documentation corpora.

Attempting to funnel large files through standard web proxy routes or attaching them directly to AI assistant prompts leads to immediate failure. Chat assistants impose prompt token boundaries, while Cloudflare edge proxy networks terminate file uploads that exceed plan limits.

| Architecture Feature | Edge Proxy Direct Uploads | Raw Object Storage (S3 / R2) | Fast.io Workspaces |
| :--- | :--- | :--- | :--- |
| Maximum Upload Size | 100 MB to 200 MB (500 MB+ Enterprise) | 5 TB multipart limit | 25 GB (Starter) / 50 GB (Business) / 100 GB (Enterprise) |
| Ingestion Mechanism | Monolithic HTTP POST through edge CDN | Presigned PUT / Multipart API | Direct chunked upload via browser, CLI, or MCP |
| Search Mechanism | None (Origin application must index) | Key prefix matching only | Hybrid Search (semantic vector + full-text keyword + metadata) |
| AI Assistant Access Method | Custom API endpoints | Custom SDK scripts (`boto3`, `@aws-sdk`) | Remote MCP server (`https://mcp.fast.io/mcp/tools`) |
| Document Data Extraction | External OCR or parsing pipelines | Custom event-driven workers | Native Metadata Views (typed schemas to structured tables) |
| Collaboration and Locking | Application-level database locks | Object versioning (full duplicate copies) | Built-in per-file version history and advisory leases |

### Fast.io Capabilities for Modern Project Workspaces

Fast.io provides an intelligent workspace platform where engineering teams and autonomous AI agents share persistent file storage without hitting proxy bottlenecks:

* **Large File Uploads Without Proxy Caps:** Workspaces support direct chunked uploads for files up to 25 GB on Starter, 50 GB on Business, and 100 GB on Enterprise plans. Files upload reliably through browser interfaces, automated scripts, or the command-line tool `@vividengine/fastio-cli`.
* **Intelligence Mode and Built-in RAG:** Once Intelligence is enabled on a workspace, uploaded documents, spreadsheets, code files, and PDFs are automatically indexed for hybrid search. Rather than uploading large document corpora into a chat window, AI assistants query the remote Model Context Protocol (MCP) server at `https://mcp.fast.io/mcp/tools`. The assistant retrieves relevant passages backed by precise source citations.
* **Structured Data Extraction with Metadata Views:** Fast.io [Metadata Views](/product/document-data-extraction/) convert unstructured documents into queryable tables. Users specify desired fields in natural language, and the platform generates a typed schema (Text, Integer, Decimal, Boolean, URL, JSON, Date & Time), populating sortable columns across scanned pages, PDFs, and spreadsheets without manual template configuration.
* **Advisory File Locks for Agent Coordination:** When multiple autonomous agents collaborate in the same workspace, concurrent write collisions are managed through advisory per-file leases. Agents acquire, heartbeat, and release locks using the MCP `storage_manage` tool actions `lock-acquire` and `lock-release`, checking status via `lock-status` on `storage`. Because locks are advisory, concurrent writes are preserved, and per-file version history maintains an auditable trail of every revision.
* **Cloud Import and Sync:** Organizations connect external storage repositories directly. Fast.io provides Cloud Sync for Dropbox, Box, and OneDrive (including SharePoint libraries via the OneDrive connector). Cloud Sync operates one-way or two-way, on a schedule or on demand. Google Drive supports cloud import today, with sync coming soon.
* **Append-Only Audit Log:** Workspaces record all team and agent activity in an append-only audit log, ensuring complete visibility into file modifications, permission updates, and data access.

### Transparent Pricing and Trial Structure

Fast.io plans are structured around organizational workspaces with predictable billing. Monthly plans start with a 30-day free trial, which requires a credit card. Subscription tiers are Starter at `$9.99/mo`, Business at `$49.99/mo`, and Enterprise at `$199.99/mo` on [Fast.io pricing](/pricing/).

| Plan Tier | Monthly Price | Included Storage | Included Workspaces | AI Credits per Month | Maximum Upload Size |
| :--- | :--- | :--- | :--- | :--- | :--- |
| Starter | $9.99/mo ($99/yr) | 250 GB | 5 workspaces | 100,000 credits | 25 GB max upload |
| Business | $49.99/mo ($499/yr) | 5 TB | 50 workspaces | 600,000 credits | 50 GB max upload |
| Enterprise | $199.99/mo ($1,999/yr) | 25 TB | 200 workspaces | 3,000,000 credits | 100 GB max upload |

Additional storage beyond the plan allowance is billed at 1.5 cents per GB per month, and bandwidth beyond plan limits is billed at 4 cents per GB. Credits meter AI operations, with overage billed at `$10 per 100,000 credits`. Developers manage workspaces programmatically using the remote MCP server or the official `@vividengine/fastio-cli` command-line tool.

## Frequently asked questions

### What is the maximum upload size for Cloudflare?

Cloudflare enforces maximum upload size limits on client request bodies based on your account plan tier. Free and Pro plans are capped at 100 MB per request upload. The Cloudflare Business plan allows request uploads up to 200 MB. Enterprise accounts default to 500 MB, with self-service configuration up to 5 GB in the dashboard Network settings and custom limits available through Cloudflare Support.

### How do I bypass the 100MB limit on Cloudflare?

You can bypass the 100 MB Cloudflare upload limit using three common architectural strategies. First, implement client-side chunked uploads to slice large files into smaller parts under 100 MB before transmission. Second, route uploads through a dedicated subdomain configured as DNS-only (unproxied grey cloud in the Cloudflare dashboard). Third, use direct-to-storage uploads with presigned URLs to transfer payloads directly to object storage or cloud workspaces.

### Why does Cloudflare return Error 413?

Cloudflare returns an HTTP 413 Payload Too Large error when an incoming client request body exceeds the configured Maximum Upload Size for the zone. Cloudflare edge servers inspect the Content-Length header and incoming payload stream. If the request surpasses the tier threshold (100 MB for Free and Pro, 200 MB for Business), Cloudflare terminates the connection at the edge before sending data to the origin.

### Does Cloudflare limit download file sizes or response bodies?

Cloudflare does not enforce a file size limit on HTTP response bodies streamed back from an origin server to a client. However, Cloudflare enforces edge cache size limits. On Free, Pro, and Business plans, files exceeding edge caching thresholds pass through as uncached origin streams rather than remaining stored in edge points of presence.

### How does the 25 MiB asset limit on Cloudflare Pages differ from the proxy upload limit?

The 25 MiB limit on Cloudflare Pages applies specifically to static website deployment assets uploaded to the Pages hosting platform. If a single static file in your site repository exceeds 25 MiB, the Pages build or direct upload will fail. In contrast, Cloudflare upload limits apply to dynamic HTTP request bodies (such as file uploads sent via POST or PUT) passing through the Cloudflare proxy network.

### Can Enterprise plan customers increase the Cloudflare upload limit beyond 500 MB?

Yes. Enterprise customers can adjust the Maximum Upload Size setting directly within the Cloudflare dashboard under Network settings, selecting values up to 5 GB on a self-service basis. If an organization requires upload limits exceeding 5 GB for specific enterprise workflows, they must coordinate with their dedicated Cloudflare account team or Cloudflare Support.

### How can AI agents handle datasets larger than edge proxy limits?

Rather than transferring multi-gigabyte datasets through web proxies or stuffing them into prompt context windows, engineering teams store files in shared workspaces. When Intelligence Mode is enabled, files are automatically indexed for hybrid vector and full-text search. AI assistants connect through a remote Model Context Protocol (MCP) server, allowing them to search and retrieve relevant excerpts on demand.

## Sources

- [Cloudflare: Default Cache Behavior](https://developers.cloudflare.com/cache/concepts/default-cache-behavior/): Cloudflare upload limits restrict client request body size across Free, Pro, Business, and Enterprise plans, capping default file uploads by plan tier at 100 MB or 200 MB while allowing Enterprise customers to self-serve limits up to 5 GB on the network dashboard.
- [Cloudflare: Troubleshooting Error 413](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/4xx-client-error/error-413/): Exceeding Cloudflare maximum upload limit rules or proxy request ceilings triggers an HTTP 413 Payload Too Large error code, requiring chunked uploads, DNS-only subdomain bypass, or origin server configuration.

## About Fast.io

Fast.io provides shared workspaces where people and AI agents work on the same files, with built-in semantic search and citation-backed chat over what they hold. Agents reach it through a remote MCP server, a REST API at https://api.fast.io/current/, and a command line client published on npm as @vividengine/fastio-cli. MCP setup is at https://mcp.fast.io/docs: Claude and most MCP clients connect to https://mcp.fast.io/mcp/tools, ChatGPT to https://mcp.fast.io/mcp/operations, and coding agents to https://mcp.fast.io/mcp/code.
