- Cookie header: Sent by browsers to servers with each request
- Set-Cookie header: Sent by servers to set cookies in browsers
- Size limits: Most web servers limit total header size to 8KB-16KB
- Individual cookie limit: Browsers typically limit each cookie to 4KB
- Cookie attributes: Domain, Path, Expires/Max-Age, Secure, HttpOnly, SameSite
- Performance: Larger headers increase request size and latency
- Common limits: Nginx: 8KB (default), Apache: 8KB, IIS: 16KB
How to check cookie and header size
- Pick an input mode: Cookie String for a Cookie or Set-Cookie value, Raw Headers for request headers copied from browser DevTools (Network tab, select the request), or cURL Output for the output of curl -v.
- Paste the text into the input box.
- Compare the total with the size warning limit. The default is 8192 bytes; change it to match your server.
- Look through the cookie list for the largest items, then shorten or remove them where they are set.
Example: a Cookie header with three cookies
Paste this into Cookie String mode:
sessionId=abc123; userId=42; theme=darkThe tool lists three cookies: sessionId=abc123 (16 bytes), userId=42 (9 bytes) and theme=dark (10 bytes), 35 bytes in total. Sizes are UTF-8 bytes, so a value with é or other non-ASCII characters takes more bytes than it has characters.
The total leaves out the "; " separators and the request line, so the real header is slightly bigger than the number shown.
Frequently asked questions
What causes "400 Request Header Or Cookie Too Large"?
That's Nginx's error page when one request header line is bigger than its buffer. The default large_client_header_buffers is 4 8k, so a Cookie header over 8KB triggers it. The usual cause is too many or too large cookies on the domain.
What are the header size limits for common servers?
Nginx allows 8KB per header line by default (large_client_header_buffers 4 8k). Apache's LimitRequestFieldSize defaults to 8190 bytes per header. Node.js rejects requests whose headers total more than 16KB (--max-http-header-size). All three can be changed, so check your own config.
How big can a single cookie be?
Browsers support at least 4096 bytes per cookie, the minimum RFC 6265 requires. A Set-Cookie larger than the browser's limit is ignored without an error.
How do I fix a header that is too large?
Clearing the site's cookies confirms the cause. Then find the large cookies here. Common culprits are session data stored in a cookie instead of on the server, cookies from several analytics tools, and cookies set on a parent domain that every subdomain receives. Raising the server limit also works, but every proxy and CDN in front of the server has its own limit.
Is my data sent anywhere?
No. Parsing runs in your browser. Cookies often hold session tokens, though, so remove real session values before pasting them into any online tool.