← All status codes4xx – Client Error

HTTP 425 – Too Early

The server is unwilling to risk processing a request that might be replayed.

Common use case

A safety mechanism for TLS 1.3's 0-RTT early data, protecting non-idempotent requests (like a payment) from being accidentally replayed by an attacker or a network retry.

Example

HTTP/1.1 425 Too Early

History

Standardised in RFC 8470 (2018) specifically to address a replay risk introduced by TLS 1.3's 0-RTT feature.

Did you know?

It exists purely because of a performance feature (0-RTT) that made connections faster but reintroduced an old replay-attack risk - a rare case of a security code born from a speed optimisation.