tlsv1 alert protocol version 🔌 API

SSL error: tlsv1 alert protocol version / unsupported protocol / no protocols available

The client and server couldn’t agree on a TLS version or cipher, so the HTTPS handshake failed before any HTTP was exchanged.

Seen on: REST API

Meaning

Servers now refuse old TLS 1.0/1.1, and some clients (old Java, old OpenSSL, legacy .NET) can’t speak TLS 1.2/1.3 — or the reverse: a modern client refusing a legacy server. OpenSSL reports “tlsv1 alert protocol version” or “unsupported protocol”, Java “No appropriate protocol (protocol is disabled or cipher suites are inappropriate)”, browsers ERR_SSL_VERSION_OR_CIPHER_MISMATCH, curl error 35.

Common causes

  • Client limited to TLS 1.0/1.1 (old runtime, explicit setting)
  • Server only allows TLS 1.3 / modern ciphers and the client is old
  • Java/OpenSSL security policy disables the needed version
  • Corporate proxy doing TLS interception with old settings

⚡ Quick fix

  1. Upgrade the runtime/OpenSSL or enable TLS 1.2+ in the client
  2. Test which versions the server supports
  3. Avoid hard-coding an old protocol version in code

Detailed fix by platform

curl

  1. bash
    curl -v --tlsv1.2 https://api.example.com/
    openssl s_client -connect api.example.com:443 -tls1_2

Java

  1. java
    // Java 8u261+ supports TLS 1.3; at minimum allow 1.2
    System.setProperty("https.protocols", "TLSv1.2,TLSv1.3");

.NET

  1. ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12 | SecurityProtocolType.Tls13; // legacy .NET Framework only

How to diagnose

  1. Server — Which TLS versions/ciphers does it accept (SSL Labs, openssl s_client)?
  2. Client — Runtime and OpenSSL version
  3. Proxy — Is anything intercepting TLS?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.