400 Bad Request: Request Header Or Cookie Too Large

You see "400 Bad Request" or "400 Bad Request — Request Header Or Cookie Too Large" — the server received something from the browser it could not read, most often an oversized or corrupted cookie for that one site.

Common signs of this issue

Safe checks you can do yourself

None of these require sharing passwords with anyone.

What this usually means

A 400 means the server looked at what the browser sent and decided it was malformed or too big to process. Unlike most errors in this series, the cause is usually on the visitor's side. Every time your browser asks a site for a page, it sends along all the cookies that site has stored — logins, preferences, analytics and marketing tags. When those pile up past the server's size limit, or one of them becomes corrupted, the server refuses with "Request Header Or Cookie Too Large". That wording comes from nginx, a very common web server, and similar limits exist on Apache, Cloudflare, and others.

Sites that use many subdomains, many tracking or chat tools, or long login sessions are the most likely to hit this, because cookies set for the main domain are sent to every part of it. Clearing that one site's cookies fixes it instantly for the person affected. If many customers see it, though, something on the site is setting too many or oversized cookies — often a plugin, a marketing script, or a loop that adds a new cookie on every page — and that needs fixing at the source, or the error will keep coming back.

The other causes are narrower. A broken link with invalid characters produces a 400 on that address only. Some firewalls return 400 when they dislike the shape of a request. And a site whose server header limits were set unusually low will reject perfectly normal traffic. Those server-side cases are for your host to adjust. If you are seeing a blanket error on every page for everyone, start with 500 Internal Server Error or 403 Forbidden instead, since a true site-wide 400 is rare.

What not to do

When to get help

It is time for help when the 400 comes back for the same people after they clear cookies, when multiple customers report it, or when it hits checkout, logins, or forms that bring in business. At that point the site itself is producing oversized cookies, rejecting valid requests through a firewall rule, or running with header limits set too low, and that is a server and site configuration job rather than a browser one. Someone who can see the actual request headers and server logs can pinpoint which cookie or rule is responsible without guesswork on a live site.

Glenn at WebsiteSelfHelp tracks down stubborn 400 Bad Request and cookie-size errors for small business websites. Send the page address and what the error says, and he will give you a straight answer on whether it is a browser quirk or a site fix, and what that fix would involve — nothing to log in to just to ask.

Not sure what to do next?

Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.

Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.

Frequently asked questions

What does 400 Bad Request mean?

It means the server could not understand or accept the request your browser sent, usually because of a corrupted or oversized cookie, a malformed web address, or a request larger than the server allows.

How do I fix 400 Bad Request Request Header Or Cookie Too Large?

Clear the cookies and site data for that one website in your browser, then reload and log in again. If the error keeps returning for you or others, the site is setting too many cookies and needs fixing at the source.

Is a 400 Bad Request error my fault or the website's?

Usually it is the browser's stored data, which is nobody's fault and easy to clear. If many visitors get it, or it happens in a fresh private window, the website or server is the cause.

Why does the site work in incognito but not in my normal browser?

A private window starts without cookies. If the page loads there, your normal browser is sending cookies or cached data that the server rejects. Clearing that site's data should fix it.

Will a 400 error hurt my SEO?

Rarely, because Googlebot does not carry the cookie build-up that usually causes it. It only matters if the site returns 400 to everyone, or if broken internal links point to malformed addresses.

Can a large file upload cause a 400 Bad Request?

It can, though most servers use a 413 or a size-limit message instead. If a 400 appears only when uploading, try a smaller file and check your site's upload limits.

Related free guides

WordPress site down?

Seeing “There has been a critical error on this website”?

Our guided repair tool logs in over secure FTPS and fixes the most common WordPress failures — safely, with every change backed up and reversible. Start with a free scan, no password needed.

Fix My WordPress Site → Free scan · No download of your site · Reversible