431 Request Header Fields Too Large: the cookie problem
Why request headers grow until servers refuse them, how visitors can fix it in seconds, and how site owners can keep cookies and sessions small.
· 3 min read · By the Spot Downtime team
431 Request Header Fields Too Large means the headers on a request, not the body, are bigger than the server will read. In practice that almost always means cookies. nginx reports the same problem differently, as 400 Bad Request: Request Header Or Cookie Too Large.
Why headers grow
Browsers send every cookie for a domain with every request. Cookies pile up: analytics tools, A/B testing, chat widgets, consent banners and your own session, each adding a few hundred bytes. Cookies set on .example.com are also sent to every subdomain, so cookies from your marketing site ride along to your app and your API.
- A session stored in the cookie that grows with every item a user adds, or with a long list of permissions in a JWT.
- A redirect loop that sets a new cookie on every hop.
- Long referer URLs with huge tracking parameters.
Fix it as a visitor
Clear cookies for that site only. In Chrome: click the icon left of the address, then Cookies and site data, and remove them. If the site works in a private window, this is the problem.
Fix it as the site owner
Find the big cookies
In your browser's dev tools, open Application → Cookies and sort by size. Anything over a kilobyte is suspicious. Then decide whether it needs to exist, whether it needs to be on the parent domain, and whether it could live server-side instead.
Keep sessions small
Store a session ID in the cookie and the session data on the server. Keep JWTs to the claims you actually check.
Raise the limit, carefully
Server limits are there for good reasons, but defaults can be tight:
# nginx: up to 4 buffers of 16 KB for long headers
large_client_header_buffers 4 16k;# Node.js: default is 16 KB
node --max-http-header-size=32768 server.jsRaise limits on every layer: the CDN, the load balancer, nginx and your application. And treat it as a temporary fix, since cookies that keep growing will hit the new limit too.
Why this one is hard to catch
Keep reading
- HTTP errors · Troubleshooting500 Internal Server Error: how to find the cause and fix itA 500 hides its reason on purpose. Where to look first, the usual causes from unhandled exceptions to full disks, and the extra checks for WordPress and PHP sites.October 5, 2026 · 5 min read
- HTTP errors · Troubleshooting404 Not Found: fix broken pages, missing routes and soft 404sWhich 404s you can ignore, which ones cost you visitors and rankings, and how to fix a whole site or section that suddenly returns Not Found.October 5, 2026 · 4 min read