Ffile2fix
Sign in Get started

How to fix "400 Bad Request: Request Header Or Cookie Too Large"

400 Bad Request
Request Header Or Cookie Too Large
nginx

This 400 error means the browser sent request headers, almost always cookies, that are bigger than the server accepts. It usually happens after a site or its plugins pile up many cookies for one domain, or a cookie grows too large.

Also appears as: Bad Request - Request Too Long. HTTP Error 400. The size of the request headers is too long. · Your browser sent a request that this server could not understand. Size of a request header field exceeds server limit. · 431 Request Header Fields Too Large · upstream sent too big header while reading response header from upstream

Common causes

  • Too many or very large cookies stored for the domain
  • Analytics, A/B testing or session plugins adding cookies on every visit
  • Large authentication tokens (JWT, SSO) stored in cookies or headers
  • Nginx large_client_header_buffers left at the default 4 8k
  • Apache LimitRequestFieldSize at the default 8190 bytes
  • Cookies shared across subdomains via a parent-domain cookie

How to fix it

  1. Clear cookies for the site. In the browser, open site settings for the domain and delete its cookies. If the page loads again, the cookie size was the problem. This is a quick fix for one user.
  2. Find the large cookies. Open developer tools > Application > Cookies and sort by size. Note which plugin or script sets the biggest or most numerous cookies.
  3. Raise Nginx header buffers. Add large_client_header_buffers 4 16k; in the http or server block, run sudo nginx -t, then reload. Raise it moderately; do not set huge values.
  4. Raise Apache header limits. Set LimitRequestFieldSize 16380 in the server config (not .htaccess) and restart Apache. Also check any proxy in front with its own limit.
  5. Shrink cookies at the source. Store session data on the server and keep only a session ID in the cookie. Remove unused tracking scripts and set cookies on the exact subdomain instead of the whole domain.

Increase Nginx request header buffers

http {
    large_client_header_buffers 4 16k;
}

How to stop it happening again

  • Keep cookies small and server-side sessions where possible
  • Audit third-party scripts that set cookies
  • Scope cookies to the subdomain that needs them
  • Set expiry dates on cookies so they do not pile up

File2fix tools for this error

Frequently asked questions

Why does it work in an incognito window?

Incognito starts with no cookies, so the request is small. That confirms cookies are the cause.

Can I fix this in .htaccess?

No. LimitRequestFieldSize only works in the main server or virtual host config. On shared hosting, ask the host or reduce cookie size.

What is the difference with 431?

431 Request Header Fields Too Large is the specific status code for this issue. Nginx sends 400 with the 'Request Header Or Cookie Too Large' text instead.