Error Reference › HTTP
HTTP
400 Bad Request
The server couldn't understand the request because it's malformed.
What it looks like
HTTP/1.1 400 Bad Request
Content-Type: application/json
{"error": "Invalid JSON in request body"}
What does "400 Bad Request" mean?
Returned by the server or a proxy in front of it when the request itself is broken, before any real work happens. Web servers such as nginx also return 400 when headers or cookies are too large to accept.
What causes "400 Bad Request"?
- Invalid JSON or malformed body.
- A missing or wrong Content-Type header.
- Bad query-string or oversized header/cookie.
How do I confirm the cause?
- Read the response body — many APIs say exactly which field or header is wrong.
- Copy the request as cURL from DevTools and replay it, changing one thing at a time until it succeeds.
- If it happens only in one browser, clear that site’s cookies: an oversized cookie header is a classic hidden cause.
- Compare the failing request with one that works (from the API’s documentation or an API client) header by header to spot the difference.
How do I fix "400 Bad Request"?
- Validate the request body (e.g. is the JSON valid?).
- Set the correct Content-Type.
- Log the raw request on the server to see what arrived.
How do I stop it happening again?
- Build request bodies with JSON.stringify or a client library, never by gluing strings together.
- Validate input on the client and return clear 400 messages from your own APIs.