302 🌐 HTTP

HTTP 302 Found (Temporary Redirect)

The resource is temporarily at another URL; clients should keep using the original URL for future requests.

Meaning

302 tells clients “go there for now”. Login redirects, A/B tests and maintenance pages use it. SEO trouble comes from using 302 for permanent moves (ranking may not transfer), and API trouble comes from clients following 302 with a GET even when the original request was a POST. 307 is the method-preserving temporary redirect.

Common causes

  • Session expired — app redirects to the login page (APIs then receive HTML instead of JSON)
  • Permanent move implemented as 302 by mistake (framework default redirect())
  • POST-redirect-GET pattern after form submission (intended)
  • Geo/language redirects

⚡ Quick fix

  1. For permanent moves use 301/308
  2. For APIs, return 401 JSON instead of redirecting to a login page
  3. Use 307 when the method and body must be preserved

Detailed fix by platform

PHP

  1. header('Location: /new', true, 301); — PHP sends 302 by default when you only set Location.

Node.js

  1. Express res.redirect('/new') is 302; use res.redirect(301, '/new') for permanent moves.

JavaScript

  1. fetch() follows redirects silently — check res.redirected and res.url to detect a login redirect.

Code examples

Detect a login redirect in fetch

javascript
const res = await fetch('/api/orders');
if (res.redirected && res.url.includes('/login')) {
  location.href = '/login?next=' + encodeURIComponent(location.pathname);
}

How to diagnose

  1. Intent — Is the move temporary or permanent?
  2. Target — Where does Location point?
  3. Method — Does the client re-send POST data correctly?
  4. API — Is an API getting an HTML login page via 302?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.