C# HttpClient default timeout: 100 seconds, and how to set it
HttpClient.Timeout defaults to 100 seconds per request and throws TaskCanceledException. How to set it, and why slow API jobs need polling instead.

The default timeout of HttpClient in C# is 100 seconds (100,000 milliseconds), set by the HttpClient.Timeout property and applied to every request on that instance. When it expires, the call throws a TaskCanceledException whose InnerException is a TimeoutException. Change it with new HttpClient { Timeout = TimeSpan.FromSeconds(30) } before the first request, or give one request a shorter deadline with a CancellationTokenSource; the shorter of the two applies.
HttpClient facts come from Microsoft Learn's HttpClient.Timeout and Make HTTP requests with the HttpClient class pages. The slow-API example is Sume's, from Jobs and results and Video Generation, all read on 2026-09-29.
What are the rules for HttpClient.Timeout?
The property takes a TimeSpan. Microsoft's page lists these limits and exceptions:
| Rule | Value or behavior |
|---|---|
| Default | 100,000 milliseconds (100 seconds) |
| No timeout | Set it to InfiniteTimeSpan |
Zero, negative, or over MaxValue milliseconds | ArgumentOutOfRangeException |
| Changed after a request has started | InvalidOperationException |
| Scope | Every request on this HttpClient instance |
| Per-request deadline | A CancellationTokenSource; the shorter of the two applies |
| Values under 15 seconds | A DNS lookup may take up to 15 seconds, so the timeout can fire later |
How do I set a timeout and tell it apart from a cancel?
Set Timeout once when you build the client; Microsoft recommends reusing HttpClient instances for the application's lifetime. Both a timeout and your own cancel surface as the same cancellation exception, so filter on the cause: an inner TimeoutException means HttpClient.Timeout fired, and a canceled token means your code did.
var http = new HttpClient { Timeout = TimeSpan.FromSeconds(30) }; // before any request
http.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue(
"Bearer", Environment.GetEnvironmentVariable("SUME_API_KEY"));
using var cts = new CancellationTokenSource(TimeSpan.FromSeconds(10)); // shorter wins
try
{
using var res = await http.GetAsync(
"https://api.sume.com/v1/jobs/job_123/status", cts.Token);
Console.WriteLine(await res.Content.ReadAsStringAsync());
}
catch (OperationCanceledException ex) when (ex.InnerException is TimeoutException)
{
Console.WriteLine("HttpClient.Timeout fired"); // poll again later
}
catch (OperationCanceledException) when (cts.IsCancellationRequested)
{
Console.WriteLine("Our 10-second token fired");
}Should I raise the timeout for a slow API?
Not for work that takes minutes. Raising Timeout to cover a video render just holds a connection open that something between you and the server may close first. An async job API lets you wait elsewhere. Sume's video create returns a job id and polling URL immediately, and generation runs asynchronously; you poll GET /v1/videos/{jobId} until the status is completed. Where a Sume submit endpoint offers the blocking sync mode, it waits at most 30 seconds before returning the job, so the 100-second default already covers a create call. Keep a short timeout on each HTTP call and put the long deadline in your polling loop.
What happens to the job when HttpClient times out?
It keeps going. Sume's docs say a client-side timeout does not cancel the job: it keeps running and still bills, and you have only stopped watching (video API timeouts lists every wait cap). Store the job id and pick it back up from the status URL, and don't resubmit the paid request because a local process timed out. If the create itself timed out before you saw a job id, resend it with the same Idempotency-Key; on /v1/videos a replay returns the original job. Polly retry for HttpClient wires that retry, and C# HttpClient POST JSON shows the create call.
Sources
Related posts
More in Developers
- How to delete my data from an AI tool, and what stays
Delete your data from an AI tool in two steps: delete the account, then send a deletion request for stored files. How it works on Sume, and its limits.
- Do AI companies sell your data? What to read in the policy
Some may; the privacy policy is where to check. How to read its sale and sharing sections, and what Sume's policy says it collects and shares.
- Do API keys expire? Sume keys last until revoked
Some API keys expire and many last until revoked. Sume keys have no expiry date in current code, so rotation is on you. How and when to rotate.
- fal.ai API rate limit: concurrency from 2 up to 40
fal.ai limits how many requests run at once, not requests per minute: 2 for a new account, rising with credit purchases to 40 self-serve.
Written by Sume