Developer Toolbox
4xx client errorNot retryable as isRead the response body

400 Bad Request

The server won't process the request because something in it is malformed: the syntax, the framing, or a parameter it can't make sense of. The problem is on the client side, so sending the same request again gets the same answer.

Open JSON Formatter Find the syntax error in the request body.

Common causes

  • Invalid JSON in the body: a trailing comma, single quotes, an unescaped line break inside a string.
  • A Content-Type that doesn't match the body, such as JSON sent as application/x-www-form-urlencoded.
  • A malformed URL: a raw space, or a % that doesn't start an escape sequence.
  • A header the server rejects, or cookies grown too large. Some servers answer 400 here instead of 431.
  • A required query parameter that is missing or has the wrong type.

How to fix it

  • Read the response body first. Most APIs name the field that failed, often in an application/problem+json document.
  • Validate the JSON you send. Building the body with JSON.stringify instead of string concatenation removes a whole class of these errors.
  • Compare the failing request with one that works: the headers, the encoding, and the exact bytes of the body.
  • If it only happens in one browser, clear the site's cookies: an oversized Cookie header is a common cause.

400 or 422?

Use 400 when the request can't be parsed at all (broken JSON, bad framing) and 422 when it parses but the values fail validation (an email without an @, an end date before the start). Many APIs use 400 for both, which is allowed, but the split tells the client whether to fix the syntax or the data.

Example

HTTP/1.1 400 Bad Request
Content-Type: application/problem+json

{
  "title": "Malformed JSON",
  "status": 400,
  "detail": "Unexpected token } in JSON at position 41"
}

Defined in RFC 9110, section 15.5.1.