Nginx 400 "Request Header or Cookie Too Large"

Nginx rejects requests whose headers overflow its default buffers — usually a fat cookie. The fix is one directive, but check which cookie is ballooning or it comes back.

What you'll see

Root causes

A single bloated cookie (often third-party)

Old analytics scripts or abandoned frameworks park 8KB+ of cookies on your domain. Nginx's client_header_buffer_size default (1k) can't hold it. Devtools → Application → Cookies, sort by size, tells you which one.

Header buffers undersized for legitimate use

SSO/JWT setups with long authorization headers legitimately exceed defaults. Here raising the buffer is the correct fix, not cookie hygiene.

Fix it

  1. Confirm it's header overflow in the log
    sudo tail -20 /var/log/nginx/error.log | grep -i 'large'   # 'client sent too long header line' or cookie message
  2. Raise the header buffer (server or http level)
    # client_header_buffer_size 16k; large_client_header_buffers 4 16k;
  3. Validate and reload
    sudo nginx -t && sudo systemctl reload nginx
  4. Hunt the fat cookie before it returns
    # devtools → Application → Cookies → sort by Size: delete/expire abandoned mega-cookies; long-term fix is scoping your own cookies tightly

Field note

This 400 arrives before your app sees the request — nothing in application logs. That absence is the diagnostic fingerprint. Browsers cache nothing here, so the fix is instant for affected users once buffers are raised.

Common questions

Why do only some users hit this 400?

Cookie size varies per user: long session histories, third-party scripts, and stale cookies accumulate. The affected browser carries the oversized cookie; a clean profile works fine.

How large can I safely set client_header_buffer_size?

16k-32k is a sane ceiling for most sites — headers are allocated per connection. If you're tempted to go beyond that, shrink the cookies instead; many clients have their own limits.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.