HTTP 307 Temporary Redirect
A temporary redirect that keeps the original method and body — a POST stays a POST at the new URL.
Meaning
307 is the strict version of 302: clients must repeat the same request (method and body) at the Location URL. Browsers also show an “internal” 307 when HSTS forces http→https before any request is sent.
Problems: clients that don’t resend the body, redirect loops between http/https or trailing slash, and APIs that redirect POSTs to a different host and lose the Authorization header.
Common causes
- HSTS: browser upgrading http to https (shown as 307 Internal Redirect)
- Server or load balancer redirecting to https or a canonical host
- Trailing-slash redirects in frameworks (FastAPI, Django)
- Maintenance/temporary moves
⚡ Quick fix
- Call the final URL directly (https, correct host, trailing slash)
- Check for redirect loops with curl -IL
- Re-add auth headers if the client drops them on cross-host redirects
Detailed fix by platform
curl
curl -sIL https://example.com/api/items | grep -iE '^(HTTP|location)'
FastAPI
app = FastAPI(redirect_slashes=False) # or call the URL with the exact trailing slash
How to diagnose
- Chain — Every hop’s status and Location
- Cause — HSTS internal vs server redirect
- Headers — Authorization still present after the hop?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in HTTP
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Report a correction or suggest an improvement
Last updated 7 Oct 2026