< HTTP/1.1 464 Incompatible Request Protocol464 Incompatible Request Protocol (AWS ALB)
AWS ALB 464 means the incoming HTTP or gRPC request conflicts with the target group protocol version. Inspect ProtocolVersion and listener routing.
- Cacheable
- Only with explicit freshness
- Retry?
- No: align the request with the target group protocol version
- Usually sent by
- AWS ALB
- Spec
- AWS ALB HTTP 464
TL;DR: AWS ALB 464 means the incoming request protocol does not match the selected target group’s protocol version. Inspect
ProtocolVersionand the listener rule that selected the group; changing only the backend URL from HTTP to HTTPS does not resolve that mismatch.
What it means
464 is a non-standard AWS Application Load Balancer code. “Incompatible Request Protocol” is a descriptive label, not an AWS-defined reason phrase. AWS’s troubleshooting entry identifies an incompatible request and target group protocol version.
Use the target group compatibility table to check the actual combination. HTTP/1.1 requests cannot go to an HTTP/2 or gRPC group. gRPC requests cannot go to an HTTP/1.1 group. An ordinary HTTP/2 request to a gRPC group must be POST. HTTP/2 requests to an HTTP/1.1 group are supported, so do not assume both directions fail.
Confirm the selected target group
Search access logs for elb_status_code = 464. Inspect the request, target_group_arn and matched_rule_priority. target_status_code describes the target’s response, or - if none was recorded; it is distinct from the ALB-generated status.
Set ALB_ARN to your load balancer ARN and inspect its target groups:
aws elbv2 describe-target-groups \
--load-balancer-arn "$ALB_ARN" \
--query 'TargetGroups[].{Name:TargetGroupName,ARN:TargetGroupArn,Protocol:Protocol,Version:ProtocolVersion}'
Protocol and ProtocolVersion are separate fields. Check the group ARN from the failing request rather than inspecting a similarly named group in another environment.
Fix it
Route ordinary HTTP endpoints to a compatible group, and route gRPC calls to a group whose targets support gRPC. If a path-based rule sends a web page to the gRPC group, correct that rule rather than turning the page request into POST.
For an endpoint intended to use HTTP/2, confirm what protocol the caller actually negotiated. A client that reaches the ALB using HTTP/1.1 still conflicts with an HTTP/2 target group. Compare a working caller with the failing caller through the same listener and path.
After the routing or client change, repeat the original request and verify that its log entry selects the expected group. Record both the incoming protocol and target group version in the incident notes; the word “HTTPS” alone does not describe either combination fully.
Related
Frequently asked questions
What does AWS ALB 464 mean?
The incoming request protocol is incompatible with the configured protocol version of the selected target group. It is a non-standard ALB status code.
Can ALB forward HTTP/2 to an HTTP/1.1 target group?
Yes. AWS lists HTTP/2 requests to HTTP/1.1 target groups as supported. The reverse combination, HTTP/1.1 requests to HTTP/2 target groups, is not supported.
Why does a GET fail against a gRPC target group?
AWS requires an ordinary HTTP/2 request to use POST when the target group protocol version is gRPC. Check that listener routing selects the intended target group before changing the method.
Sources
- AWS: Troubleshoot ALB HTTP 464docs.aws.amazon.com
- AWS: Target group protocol versionsdocs.aws.amazon.com
- AWS: ALB access logsdocs.aws.amazon.com
- AWS CLI: describe-target-groupsdocs.aws.amazon.com
- IANA HTTP Status Code Registryiana.org
- MDN: HTTP response status codesdeveloper.mozilla.org
- RFC 9110: Status Codesrfc-editor.org
Related
400 Bad Request
400 Bad Request means the server could not parse your request. Find which layer sent it, fix bad JSON and oversized cookies or headers, and reproduce with curl.
505 HTTP Version Not Supported
Learn what 505 HTTP Version Not Supported means when servers reject protocol versions. Understand HTTP/1.1, HTTP/2 compatibility and version negotiation.
460 Client Closed Connection (AWS ALB)
An AWS ALB 460 means the client disconnected before the load balancer idle timeout. Confirm it in access logs, then compare client and target timings.
463 Too Many Forwarded IP Addresses (AWS ALB)
AWS ALB 463 rejects an X-Forwarded-For header with more than 30 IP addresses. Trace proxy appends and correct the forwarding chain at a trusted ingress.