The error, verbatim
Jump to the fix ↓Error 1102
Worker exceeded resource limits
# the same request from curl:
HTTP 503
error code: 1102
# npx wrangler tail --format pretty, same request:
GET https://nk-repro-cpu.nilaykabariya12.workers.dev/hash - Exceeded CPU Limit
X [ERROR] Error: Worker exceeded CPU time limit.
Tested on
- wrangler
- 4.139.0
- better-auth
- 1.7.6
- Worker
- compatibility_date 2026-09-01, nodejs_compat
- Plan
- Workers Paid, limits.cpu_ms set to 10 (the Free plan limit)
- OS
- Windows 11 Pro
Contents
Your Worker works most of the time, then a request dies with Error 1102, “Worker exceeded resource limits”. Nothing crashed. Cloudflare stopped the request because it used more CPU than your plan allows.
The fix
1. See which request used the CPU. Stream the live logs, then trigger the error again:
npx wrangler tail --format jsonEvery request shows its cpuTime in milliseconds, and the killed one has "outcome": "exceededCpu". (--format pretty is easier to read but leaves out the CPU time.) In my test, the route that tripped it hashed one password, which is what a better-auth sign-up or sign-in does.
2. On Workers Paid, check cpu_ms. The default limit is 30 seconds, so a 1102 on Paid usually means the limit was set low somewhere. Raise it, or delete the setting to get the default back:
// wrangler.jsonc
"limits": { "cpu_ms": 30000 }3. On the Free plan, the limit is 10 ms and can’t be raised. If one request genuinely needs more (password hashing does, see below), the fix is Workers Paid, which starts at $5 a month, or doing that work somewhere other than the Worker.
Why password hashing trips it
better-auth hashes passwords with scrypt (N: 16384, r: 16). On Workers it uses the node:crypto version through nodejs_compat. I timed it on a deployed Worker with wrangler tail:
| Request | CPU time |
|---|---|
Plain ok response |
0 ms |
One hashPassword() from better-auth 1.7.6 |
73 to 170 ms |
| Free plan limit | 10 ms |
One sign-up or sign-in uses 7 to 17 times the Free plan’s budget.
Why it only fails sometimes
Cloudflare’s limits page says each isolate “has some built-in flexibility to allow for cases where your Worker infrequently runs over the configured limit”. So a Worker that goes over now and then gets away with it, and one that goes over often doesn’t.
That’s exactly what happened when I sent 30 password-hashing requests one after another with the Worker capped at 10 ms:
- the first 10 all succeeded, at 73 to 170 ms each
- then 6 of the next 20 failed with 1102
The killed requests were stopped after about 20 ms of CPU, because the earlier ones had used up the slack. That’s why it shows up in production once sign-ins keep coming, and never on your laptop. (Ten requests sent at the same moment all passed, because Cloudflare spread them over separate isolates, so a quick burst test can miss it.)
Can you use a lighter password hash instead?
Not without making it weak. I tried the obvious alternative, PBKDF2 through Web Crypto:
NotSupportedError: Pbkdf2 failed: iteration counts above 100000 are not supported (requested 600000).
Workers refuses more than 100,000 iterations, while OWASP recommends 600,000 for PBKDF2-HMAC-SHA256. And even the 100,000 that Workers allows used 23 ms of CPU, still over the Free limit. No password hash of a recommended strength fits in 10 ms, so don’t weaken it to fit. Pick one of the fixes above.
What the error looks like
In a browser, Cloudflare shows its own error page: Error 1102, Worker exceeded resource limits, with a Ray ID and a line telling the owner to check Workers Logs. From curl or an API client, the same request is a bare 503 with the body error code: 1102. Neither says which code was slow, so the logs from step 1 are the only way to find it. (If the page says Worker threw exception instead, your code crashed rather than ran out of CPU: that’s Error 1101.)
What didn’t work
How this was tested
A test Worker deployed with wrangler 4.139.0 on workers.dev, with three routes: one calling hashPassword() from better-auth 1.7.6, one burning CPU in a counted loop, and one returning ok. The account is on Workers Paid, so to match the Free plan I set limits.cpu_ms to 10, then removed it to confirm the fix. CPU times, outcomes and error messages are from wrangler tail --format json, and the PBKDF2 error is from the same Worker. Cloudflare’s limits and pricing pages were checked the same day for the 10 ms, 30 second and $5 figures.
— N.K., end of entry No.026