400 Bad Request

The server could not understand the request.

Code
400
Reason phrase
Bad Request
Class
4xx Client error
Defined in
RFC 9110 section 15.5.1
Cacheable by default
No

What it means

Client error: the problem lies with the request. Repeating it unchanged will normally fail again.

When a server should send it. When the request itself is broken and repeating it unchanged cannot work: malformed JSON, an invalid query parameter, a header the server cannot parse. For well-formed data that fails validation, 422 is more precise; either way, say what was wrong in the body.

Common causes. Malformed JSON, a missing required field, an oversized or corrupt cookie, or a bad URL.

What to do. Check the request body and parameters against the API documentation. On a website, clearing the site's cookies often fixes it.

How clients and crawlers treat it

Browsers and HTTP clients. Browsers show whatever page the server returns. HTTP libraries treat it as a client error and do not retry, because the same request would fail the same way.

Google Search. Like every 4xx except 429, it tells Google the content does not exist: an indexed URL is removed from the index, and a new one is not processed. Crawl frequency for the URL gradually drops. Source: Google Search Central, How HTTP status codes, and network and DNS errors affect Google Search.

Caching. Not cacheable by default (RFC 9110 section 15.1 does not list it). A cache stores it only when the response says so with Cache-Control or Expires.

Example response

HTTP/1.1 400 Bad Request
Content-Type: application/problem+json

{"status": 400, "title": "Bad Request"}

How to send 400

nginx
location /example {
    return 400;
}
Apache (.htaccess)
RewriteEngine On
RewriteRule ^example$ - [R=400,L]
PHP
http_response_code(400);
echo 'Bad Request';
exit;
Node.js
res.writeHead(400, { 'Content-Type': 'text/plain' });
res.end('Bad Request');
Python (Flask)
# in a view function
return 'Bad Request', 400

Change the paths to suit. In nginx, add_header needs always to apply to error responses.

Related codes

All status codes · All 4xx codes

Names and numbers from the IANA HTTP Status Code Registry. Google Search behaviour as documented by Google Search Central.