HTTP 425 – Too Early
The server is unwilling to risk processing a request that might be replayed.
Common use case
A safety mechanism for TLS 1.3's 0-RTT early data, protecting non-idempotent requests (like a payment) from being accidentally replayed by an attacker or a network retry.
Example
HTTP/1.1 425 Too Early
History
Standardised in RFC 8470 (2018) specifically to address a replay risk introduced by TLS 1.3's 0-RTT feature.
Did you know?
It exists purely because of a performance feature (0-RTT) that made connections faster but reintroduced an old replay-attack risk - a rare case of a security code born from a speed optimisation.