Skip to content

Redirects 301–308 Explained

The 3xx redirect status codes as decision rows: which code to pick, what each preserves about the request, and how browsers and search engines cache the hop.

A 3xx redirect answers two questions: where does this request go next, and for how long. The permanent codes (301, 308) are cached aggressively and are hard to undo; the temporary codes (302, 303, 307) get re-checked on every load. Pick along two axes — permanence, and whether the method and body must survive the hop.

Reference table · 22 entriesOpen the http-status-codes tool →
22 of 22 rows
Permanent
301Moved PermanentlyMethod not guaranteedThe URL moved for good — domain migration, trailing-slash normalization, http to https. Search engines merge ranking signals into the target.
308Permanent RedirectMethod and bodyA permanently relocated endpoint that receives POST, PUT, or PATCH calls — the request replays verbatim at the new URL, forever.
Temporary
302FoundMethod not guaranteedThe default temporary move — maintenance pages, A/B routes, short-term rebrands. Browsers re-check it instead of caching it.
303See OtherAlways GET on follow-upAfter a POST form submit — redirect to a result page so refresh and the back button never re-submit the form (the Post/Redirect/Get pattern).
307Temporary RedirectMethod and bodyA temporarily moved endpoint that must still receive the original POST or PUT body intact — for example re-authentication flows that replay the request after login.
Method preservation
301 + POSTHistoric rewritePOST may become GETPre-RFC 7231 browsers rewrote POST to GET on 301, and many still do for compatibility. Never point a 301 at an endpoint that expects a body.
302 + POSTAmbiguous by designGET in practiceRFC 1945 left 302 undefined for POST, and de-facto browser behavior became rewrite-to-GET. Codes 303 and 307 exist to close exactly this gap.
303 + POSTGuaranteed GETGET or HEAD onlyThe only code that mandates the follow-up method. Use it when the client must never replay a body — payment callbacks, form result pages.
307 + POSTNever rewrittenRe-sends body verbatimThe client re-issues the identical method, headers, and body to the Location URL. The target must be ready to accept the full request again.
308 + POSTNever rewrittenRe-sends body verbatimThe same guarantee as 307 with permanent semantics — safe for relocated API endpoints and webhook receivers.
AuthorizationDropped cross-originCredentials strippedfetch and browsers remove the Authorization header when a redirect crosses origins. Serve the hop same-origin, or re-authenticate at the target.
Large bodiesRe-upload costFull re-transmissionA 307 or 308 on a PUT upload makes the client send the entire body twice. Prefer a direct signed URL over a redirect for large transfers.
Caching & SEO
301 cacheSticky by defaultCached indefinitelyBrowsers remember a 301 across restarts with no built-in expiry. Ship one only for moves that are truly forever — undoing it takes a cache purge.
302/307 cacheRe-checked each loadNot cached by defaultTemporary codes are revalidated on every navigation unless Cache-Control extends them. Safe for experiments and staged rollouts.
308 cacheSticky like 301Cached indefinitelyTreat 308 with the same permanence caution as 301 — browsers keep following it long after you change your mind.
HSTSInternal upgradeNo network redirectOnce Strict-Transport-Security is set, the browser rewrites http to https internally before any request leaves — your server-side 301 to https stops being observed.
upgrade-insecure-requestsCSP-driven upgradeInternal, one-wayThis CSP directive upgrades subresource http links to https with an internal redirect. Add it to retire mixed-content warnings without touching markup.
rel=canonicalAlign with the redirectIndexation signalPoint the canonical tag at the same final URL the redirect lands on. A canonical that disagrees with Location confuses crawlers and splits signals.
ChainsOne hop onlyLatency per hopEach extra hop adds a round-trip and dilutes link equity. Flatten old to middle to new chains into a single old to new redirect.
Search enginesSignal handling301 merges, 302 defersGoogle treats a 301 as a permanent move and consolidates ranking into the target; a 302 keeps the origin indexed, which is correct for geo or device variants.
Cache-ControlExplicit redirect cachingYou set the TTLCDNs and proxies may cache redirect responses. Set Cache-Control max-age explicitly on the 3xx so intermediaries hold it only as long as you intend.
LocationRequired targetAbsolute or relativeEvery 3xx needs a syntactically valid Location URI; relative values resolve against the original request URL. Keep it final — never point it at another redirect.