The server will not process a request sent in TLS early data (0-RTT), because it could be replayed by an attacker.
Defined in RFC 8470 §5.2 — 425 Too Early · MDN reference
CDNs and servers that support TLS 1.3 0-RTT but refuse non-idempotent requests in early data — a replayed POST could charge a card twice.
Only reachable with TLS 1.3 early data enabled. The test is that the client retries after the full handshake, which most do automatically.
Retry the same request after the TLS handshake completes, outside early data. Browsers and well-behaved clients do this transparently; a custom client has to do it itself.
1 endpoint in this playground answers with 425. Every one is free, needs no signup, and can be called from the browser or with curl.
GET https://funapi.dev/api/faults/v1/status/{code} — Returned on request (Fault Injection API) Open & run this endpointAll HTTP status codes · All 39 mock REST APIs · Getting started guide
Last updated