What it means
The server refuses to process a request sent in TLS 1.3 early data (0-RTT) because it could be replayed.
Common causes
- Non-idempotent request sent as 0-RTT early data
- CDN protection against replay attacks
How to fix it
As a client or visitor
Retry after the TLS handshake completes; browsers do this automatically.
As the site or API owner
Reject early data for non-idempotent requests, or disable 0-RTT if your app cannot tell.
Example response
HTTP/1.1
HTTP/1.1 425 Too Early
Date: Tue, 07 Oct 2025 09:30:00 GMT
Server: nginx
Content-Length: 0 Specification
FAQ
› What is 0-RTT?
A TLS 1.3 feature that sends data with the first flight to save a round trip, at the cost of possible replay.
› Do I need to handle 425 in my app?
Rarely; browsers retry automatically. It matters mostly to CDNs and custom clients.