Skip to content
Nilay Kabariya

Entry No.026·Deploy··4 min read

Cloudflare 1102: Worker exceeded resource limits / CPU time limit

Cloudflare Workers Error 1102. Why sign-ups with better-auth trip it, why it only fails sometimes, and what fixes it, measured on a deployed Worker.

by Nilay#cloudflare#workers#better-authDEPLOY

The error, verbatim

Jump to the fix ↓
Error 1102
Worker exceeded resource limits

# the same request from curl:
HTTP 503
error code: 1102

# npx wrangler tail --format pretty, same request:
GET https://nk-repro-cpu.nilaykabariya12.workers.dev/hash - Exceeded CPU Limit
X [ERROR] Error: Worker exceeded CPU time limit.
✓ Reproduced on Windows 11 Pro

Tested on

wrangler
4.139.0
better-auth
1.7.6
Worker
compatibility_date 2026-09-01, nodejs_compat
Plan
Workers Paid, limits.cpu_ms set to 10 (the Free plan limit)
OS
Windows 11 Pro
Contents
  1. The fix01
  2. Why password hashing trips it02
  3. Why it only fails sometimes03
  4. Can you use a lighter password hash instead?04
  5. What the error looks like05
  6. What didn’t work06
  7. How this was tested07

Your Worker works most of the time, then a request dies with Error 1102, “Worker exceeded resource limits”. Nothing crashed. Cloudflare stopped the request because it used more CPU than your plan allows.

The fix

1. See which request used the CPU. Stream the live logs, then trigger the error again:

npx wrangler tail --format json

Every request shows its cpuTime in milliseconds, and the killed one has "outcome": "exceededCpu". (--format pretty is easier to read but leaves out the CPU time.) In my test, the route that tripped it hashed one password, which is what a better-auth sign-up or sign-in does.

2. On Workers Paid, check cpu_ms. The default limit is 30 seconds, so a 1102 on Paid usually means the limit was set low somewhere. Raise it, or delete the setting to get the default back:

// wrangler.jsonc
"limits": { "cpu_ms": 30000 }

3. On the Free plan, the limit is 10 ms and can’t be raised. If one request genuinely needs more (password hashing does, see below), the fix is Workers Paid, which starts at $5 a month, or doing that work somewhere other than the Worker.

Why password hashing trips it

better-auth hashes passwords with scrypt (N: 16384, r: 16). On Workers it uses the node:crypto version through nodejs_compat. I timed it on a deployed Worker with wrangler tail:

Request CPU time
Plain ok response 0 ms
One hashPassword() from better-auth 1.7.6 73 to 170 ms
Free plan limit 10 ms

One sign-up or sign-in uses 7 to 17 times the Free plan’s budget.

Why it only fails sometimes

Cloudflare’s limits page says each isolate “has some built-in flexibility to allow for cases where your Worker infrequently runs over the configured limit”. So a Worker that goes over now and then gets away with it, and one that goes over often doesn’t.

That’s exactly what happened when I sent 30 password-hashing requests one after another with the Worker capped at 10 ms:

  • the first 10 all succeeded, at 73 to 170 ms each
  • then 6 of the next 20 failed with 1102

The killed requests were stopped after about 20 ms of CPU, because the earlier ones had used up the slack. That’s why it shows up in production once sign-ins keep coming, and never on your laptop. (Ten requests sent at the same moment all passed, because Cloudflare spread them over separate isolates, so a quick burst test can miss it.)

Can you use a lighter password hash instead?

Not without making it weak. I tried the obvious alternative, PBKDF2 through Web Crypto:

NotSupportedError: Pbkdf2 failed: iteration counts above 100000 are not supported (requested 600000).

Workers refuses more than 100,000 iterations, while OWASP recommends 600,000 for PBKDF2-HMAC-SHA256. And even the 100,000 that Workers allows used 23 ms of CPU, still over the Free limit. No password hash of a recommended strength fits in 10 ms, so don’t weaken it to fit. Pick one of the fixes above.

What the error looks like

In a browser, Cloudflare shows its own error page: Error 1102, Worker exceeded resource limits, with a Ray ID and a line telling the owner to check Workers Logs. From curl or an API client, the same request is a bare 503 with the body error code: 1102. Neither says which code was slow, so the logs from step 1 are the only way to find it. (If the page says Worker threw exception instead, your code crashed rather than ran out of CPU: that’s Error 1101.)

What didn’t work

How this was tested

A test Worker deployed with wrangler 4.139.0 on workers.dev, with three routes: one calling hashPassword() from better-auth 1.7.6, one burning CPU in a counted loop, and one returning ok. The account is on Workers Paid, so to match the Free plan I set limits.cpu_ms to 10, then removed it to confirm the fix. CPU times, outcomes and error messages are from wrangler tail --format json, and the PBKDF2 error is from the same Worker. Cloudflare’s limits and pricing pages were checked the same day for the 10 ms, 30 second and $5 figures.

— N.K., end of entry No.026

Useful? Pass it on:Post on XFollow @EmotionalMatter

Related entries

  1. No.035

    Fix: Script startup exceeded CPU time limit (Workers 10021)

    Cloudflare rejects your Worker deploy with Script startup exceeded CPU time limit. How to see which code is slow, and the fix that removes it, measured.

    > X [ERROR] Your Worker failed validation because it exceeded startup limits.

    DEPLOY2 min
  2. No.034

    Fix: The uploaded script has no registered event handlers

    Cloudflare rejects your Worker with no registered event handlers (code 10068), or accepts it and serves a 404. Three ways it happens, tested on a deploy.

    > X [ERROR] A request to the Cloudflare API (/accounts/.../workers/scripts/nk-repro-cpu) failed.

    DEPLOY2 min
  3. No.027

    Fix: Error 1101 Worker threw exception (Cloudflare Workers)

    Cloudflare's 1101 page hides the real error. See it with one command, plus six causes reproduced on a deployed Worker, each with its exact log message.

    > Error 1101

    DEPLOY3 min

Post card · Newsletter

Get the next fix in your inbox.

One short email when a new entry is published. No spam, never shared, and you can leave any time.

— Nilay

or follow by RSSor on X

By subscribing you agree to the privacy note. One click to leave.

tip: paste the exact error text