Nginx rejects requests whose headers overflow its default buffers — usually a fat cookie. The fix is one directive, but check which cookie is ballooning or it comes back.
Old analytics scripts or abandoned frameworks park 8KB+ of cookies on your domain. Nginx's client_header_buffer_size default (1k) can't hold it. Devtools → Application → Cookies, sort by size, tells you which one.
SSO/JWT setups with long authorization headers legitimately exceed defaults. Here raising the buffer is the correct fix, not cookie hygiene.
sudo tail -20 /var/log/nginx/error.log | grep -i 'large' # 'client sent too long header line' or cookie message
# client_header_buffer_size 16k; large_client_header_buffers 4 16k;
sudo nginx -t && sudo systemctl reload nginx
# devtools → Application → Cookies → sort by Size: delete/expire abandoned mega-cookies; long-term fix is scoping your own cookies tightly
This 400 arrives before your app sees the request — nothing in application logs. That absence is the diagnostic fingerprint. Browsers cache nothing here, so the fix is instant for affected users once buffers are raised.
Cookie size varies per user: long session histories, third-party scripts, and stale cookies accumulate. The affected browser carries the oversized cookie; a clean profile works fine.
16k-32k is a sane ceiling for most sites — headers are allocated per connection. If you're tempted to go beyond that, shrink the cookies instead; many clients have their own limits.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.