400 Bad Request
The server cannot process the request because it looks malformed.
| Class | Client error (4xx) |
|---|---|
| Defined in | RFC9110, Section 15.5.1 |
| Cacheable by default | No, unless explicit freshness headers allow it |
Common causes
- Invalid JSON, malformed headers or an invalid URL.
- A request body that does not match what the endpoint expects.
- Oversized or corrupted cookies.
What to do
Check the request syntax and body against the API documentation. In a browser, clear cookies for the site. On the server, return a clear message saying which field failed.
Related codes
- 401 Unauthorized: The request lacks valid authentication credentials for the target resource.
- 403 Forbidden: The server understood the request but refuses to authorize it.
- 422 Unprocessable Content: The server understands the content type and syntax but cannot process the contained instructions.