4xx
425 Too Early
The server is unwilling to process a request that might be replayed.
What is HTTP 425?
This status code indicates that the server is not willing to risk processing a request that might be replayed. It is primarily used with TLS 1.3 early data (0-RTT), where the client sends data before the TLS handshake completes to reduce latency. Because early data can potentially be replayed by an attacker, servers use this code to reject requests that could have dangerous side effects if executed more than once.
Defined in RFC 8470
Common Causes
- A request was sent as TLS 1.3 early data (0-RTT) and the server considers it unsafe to process
- The server policy rejects state-changing requests in early data to prevent replay attacks
- Non-idempotent operations like payments or writes that could cause harm if replayed
How to Fix
- Retry the request after the TLS handshake is fully complete
- Ensure your client handles 425 by falling back to sending the request in the regular data phase
- Only send safe, idempotent requests as early data; keep state-changing requests for after the handshake