HTTP 428 — Precondition Required
HTTP 428
Precondition Required
The server insists the request be conditional, to stop it from silently overwriting someone else's changes.
What 428 actually means
A server that cares about lost updates can require every write to carry an `If-Match` header, so that it can reject the write if the resource changed since the client last read it. A 428 is the server refusing an unconditional write and telling the client to fetch the current ETag and try again. It is the preventive counterpart to 412: 428 stops the dangerous request being made, 412 reports that the safe one lost the race.
Common causes
- A PUT or PATCH sent without an `If-Match` header to an API that requires one
- A client that fetched a resource but discarded the ETag
- An API enforcing optimistic concurrency on all writes
If you're just trying to view the page
- Nothing directly — this is a contract between the client software and the API
- Reloading and retrying usually resolves it, since the client re-reads the current version
If it's your site
- GET the resource, keep its ETag, and send it back as `If-Match` on the write
- Serve stable ETags on every resource you require preconditions for
- Say which header is missing in the response body; "Precondition Required" alone does not name it
Reference
- Status code
- 428
- Reason phrase
- Precondition Required
- Category
- 4xx — Client Error
- Defined in
- RFC 6585 §3
Common questions
- What does HTTP 428 mean?
- The server insists the request be conditional, to stop it from silently overwriting someone else's changes. A server that cares about lost updates can require every write to carry an `If-Match` header, so that it can reject the write if the resource changed since the client last read it. A 428 is the server refusing an unconditional write and telling the client to fetch the current ETag and try again.
- How do I fix a 428 error?
- Nothing directly — this is a contract between the client software and the API
- Is 428 a client error or a server error?
- 428 is in the 4xx range, which means client error. The request itself was the problem, so retrying it unchanged will usually return the same code.
Related pages
- 404 Not Found The server is reachable and working, but there is nothing at the address you ask
- 403 Forbidden The server understood the request and is refusing to allow it, and logging in wi
- 401 Unauthorized You need to authenticate, and either you did not or your credentials were reject
- 429 Too Many Requests You have sent more requests than the service allows in a given period.
- 400 Bad Request The server could not understand the request because something about it is malfor
- 413 Content Too Large The request body is bigger than the server is willing to accept.
- 422 Unprocessable Content The request is well-formed and understood, but the data in it fails the rules.
- 405 Method Not Allowed The URL exists, but it does not accept the HTTP method you used.
- 409 Conflict The request cannot be completed because it clashes with the current state of the
- 415 Unsupported Media Type The server will not accept the format of the body you sent.
- 408 Request Timeout The server gave up waiting for the client to finish sending its request.
- 410 Gone The resource was deliberately removed and is not coming back, and there is no fo