497 🌐 HTTP

400 Bad Request: The plain HTTP request was sent to HTTPS port (Nginx 497)

Plain http:// traffic arrived on a port Nginx expects to be TLS (443 or a custom SSL port).

Seen on: REST API

Meaning

Nginx returns “400 Bad Request — The plain HTTP request was sent to HTTPS port” and logs it internally as 497. It happens when someone types http://example.com:443, when a load balancer terminates TLS and forwards plain HTTP to an Nginx listen 443 ssl, or when an app builds URLs with the wrong scheme/port.

Common causes

  • URL uses http:// with port 443 or the SSL port
  • Load balancer/Cloudflare forwarding plain HTTP to a TLS listener
  • App behind a proxy generating http://host:443 links
  • listen directive has ssl on a port that also receives HTTP

⚡ Quick fix

  1. Use https:// for that port
  2. Match proxy → origin protocol (Cloudflare Full mode, LB target protocol HTTPS)
  3. Redirect 497 to https in Nginx

Detailed fix by platform

Nginx

  1. nginx
    server {
        listen 443 ssl;
        error_page 497 =301 https://$host$request_uri;
    }

How to diagnose

  1. URL — Scheme and port being used
  2. Proxy — What protocol does the LB/CDN send to the origin?
  3. Listen — Which ports have ssl?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.