431 Request Header Fields Too Large: the cookie problem

Why request headers grow until servers refuse them, how visitors can fix it in seconds, and how site owners can keep cookies and sessions small.

· 3 min read · By the Spot Downtime team

431 Request Header Fields Too Large means the headers on a request, not the body, are bigger than the server will read. In practice that almost always means cookies. nginx reports the same problem differently, as 400 Bad Request: Request Header Or Cookie Too Large.

Why headers grow

Browsers send every cookie for a domain with every request. Cookies pile up: analytics tools, A/B testing, chat widgets, consent banners and your own session, each adding a few hundred bytes. Cookies set on .example.com are also sent to every subdomain, so cookies from your marketing site ride along to your app and your API.

  • A session stored in the cookie that grows with every item a user adds, or with a long list of permissions in a JWT.
  • A redirect loop that sets a new cookie on every hop.
  • Long referer URLs with huge tracking parameters.

Fix it as a visitor

Clear cookies for that site only. In Chrome: click the icon left of the address, then Cookies and site data, and remove them. If the site works in a private window, this is the problem.

Fix it as the site owner

Find the big cookies

In your browser's dev tools, open Application → Cookies and sort by size. Anything over a kilobyte is suspicious. Then decide whether it needs to exist, whether it needs to be on the parent domain, and whether it could live server-side instead.

Keep sessions small

Store a session ID in the cookie and the session data on the server. Keep JWTs to the claims you actually check.

Raise the limit, carefully

Server limits are there for good reasons, but defaults can be tight:

nginx
# nginx: up to 4 buffers of 16 KB for long headers
large_client_header_buffers 4 16k;
bash
# Node.js: default is 16 KB
node --max-http-header-size=32768 server.js

Raise limits on every layer: the CDN, the load balancer, nginx and your application. And treat it as a temporary fix, since cookies that keep growing will hit the new limit too.

Why this one is hard to catch

It only affects people with a lot of cookies: often your most engaged, longest-standing users. Fresh visitors and monitoring checks carry no cookies, so they see a perfectly healthy site.
HTTP headers checkerLook at the headers a site sends back, including every Set-Cookie it adds.

Keep reading