307 🌐 HTTP

HTTP 307 Temporary Redirect

A temporary redirect that keeps the original method and body — a POST stays a POST at the new URL.

Seen on: REST API

Meaning

307 is the strict version of 302: clients must repeat the same request (method and body) at the Location URL. Browsers also show an “internal” 307 when HSTS forces http→https before any request is sent.

Problems: clients that don’t resend the body, redirect loops between http/https or trailing slash, and APIs that redirect POSTs to a different host and lose the Authorization header.

Common causes

  • HSTS: browser upgrading http to https (shown as 307 Internal Redirect)
  • Server or load balancer redirecting to https or a canonical host
  • Trailing-slash redirects in frameworks (FastAPI, Django)
  • Maintenance/temporary moves

⚡ Quick fix

  1. Call the final URL directly (https, correct host, trailing slash)
  2. Check for redirect loops with curl -IL
  3. Re-add auth headers if the client drops them on cross-host redirects

Detailed fix by platform

curl

  1. curl -sIL https://example.com/api/items | grep -iE '^(HTTP|location)'

FastAPI

  1. app = FastAPI(redirect_slashes=False) # or call the URL with the exact trailing slash

How to diagnose

  1. Chain — Every hop’s status and Location
  2. Cause — HSTS internal vs server redirect
  3. Headers — Authorization still present after the hop?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.