400 Bad Request

Free

The server cannot process the request because of a client error.

What it means

Malformed syntax: unparseable JSON, a missing required parameter, a value of the wrong type. If the request is well-formed but semantically wrong - a valid date that is in the past when it must be future - 422 says more.

Class
4xx Client error
Defined in
RFC 9110 §15.5.1
Cached by default
No

When you receive a 400

  • Read the body first - a good API names the field, or the line and column, that it could not read.
  • Check that the JSON is valid (one trailing comma is enough), that Content-Type matches the body, and that required parameters are present.
  • A header or cookie that is too large can produce a 400 from the web server before your application ever sees the request.

When you send a 400

  • For a request you could not parse, or one missing something required.
  • Say what was wrong: the field, the position, the type you expected.
  • If the request parsed and a value is simply unacceptable, 422 is the more precise code.

On the wire

HTTP/1.1 400 Bad Request
Content-Type: application/problem+json

{"title": "Malformed JSON", "detail": "Unexpected token } at line 4, column 1"}

Often confused with