413 Request Entity Too Large: raise upload limits in nginx, PHP and more

Uploads fail with 413 when any layer's size limit is hit. The defaults for nginx, Apache, PHP, Node and Cloudflare, and how to raise them safely.

· 3 min read · By the Spot Downtime team

413 Request Entity Too Large (now officially called Content Too Large) means the request body is bigger than the server agreed to accept. It nearly always shows up as a failed file upload. The fix is simple once you find which limit you hit, because a typical request passes through three or four of them.

Every layer has its own limit

LayerSettingDefault
nginxclient_max_body_size1 MB
ApacheLimitRequestBody1 GB (since 2.4.54)
PHPupload_max_filesize2 MB
PHPpost_max_size8 MB
CloudflarePlan limit100 MB on Free and Pro
Express (body-parser)limit100 KB for JSON

The smallest limit in the chain wins. Raising PHP's limit to 100 MB does nothing while nginx in front of it still stops at 1 MB.

Find which layer said no

Look at the error page. nginx shows a bare 413 Request Entity Too Large nginx page; Cloudflare shows its own branded page; PHP often doesn't return 413 at all, it just hands your code an empty upload. Then fix from the outside in.

HTTP headers checkerThe server response header shows what sits in front of your app: nginx, Apache or a CDN like Cloudflare.

Raising the limits

nginx

nginx
server {
    client_max_body_size 50m;   # or inside a single location block
}
bash
sudo nginx -t && sudo systemctl reload nginx

PHP (including WordPress)

ini
upload_max_filesize = 50M
post_max_size = 55M        ; slightly bigger: the form has other fields too
memory_limit = 256M

Restart PHP-FPM after the change, and check phpinfo() to confirm the values loaded from the file you edited.

Node.js

js
app.use(express.json({ limit: "5mb" }));

Raise limits per route, not everywhere

A large body limit on every URL makes it cheaper for someone to tie up your server. Allow big bodies only on the upload endpoint. For really large files, have the browser upload straight to object storage with a pre-signed URL, so the file never passes through your server.

If you're a visitor

Compress the file, export the image at a lower resolution, or split the upload. There's nothing to change on your side; the limit is the site's setting.

Keep reading