CoreCited
Technical

302 status code: what a 302 Found response means, and when it is the right redirect

The 302 status code explained: what 302 Found means, how browsers, Google and AI crawlers treat it, when to use it, and how to check a URL's redirects.

AlexFounder & Developer11 min read

A 302 status code tells whoever asked for a page that it is temporarily somewhere else, and gives the new address in a Location header. Browsers follow it without asking. Google follows it but keeps the old URL in its results, at least at first. AI crawlers very likely follow it too, but no AI company documents how, so part of this post is about what is not known. Use a 302 when the move really is temporary. To see what any URL actually sends, hop by hop, run it through the free redirect checker.

Key takeaways
1302 Found means the page is temporarily at the URL in the Location header, and the original URL is expected to come back.
2Google keeps showing the original URL for a 302. A long-lived 302 may end up treated like a 301, and Google says there is no fixed cut-off.
3For pages read with GET, 302 and 307 behave the same. 307 only matters when a POST must stay a POST.
4No AI crawler vendor documents redirect handling. A server-side 302 is very likely followed; a JavaScript redirect is not, because those crawlers do not run JavaScript.
5If a move is permanent, send a 301 or 308. Apache and nginx can send a 302 when you leave the code out.
20
redirects in a row a browser follows before it stops with an error
Fetch Standard, Sept 2026
10
redirect hops Google's crawlers follow by default
Google, Feb 2026
5
redirects an earlier HTTP spec recommended as a maximum; some clients may still stop there
RFC 9110, 2022
0
of the 3 AI crawler docs we read (OpenAI, Anthropic, Perplexity) that mention redirects
Read 2 Oct 2026

Sources: the Fetch Standard[5]; Google[7]; RFC 9110, which notes that an earlier version “recommended a maximum of five redirections”[1]. The last figure is our own reading of each vendor’s crawler documentation[12][13][14].

What a 302 status code means

The HTTP specification defines it in one sentence: the 302 (Found) status code “indicates that the target resource resides temporarily under a different URI”. It goes on: “Since the redirection might be altered on occasion, the client ought to continue to use the target URI for future requests”[1]. In plain words: go to the other address this time, but keep asking at the original one.

The server is expected to say where to go in a Location header, and the client may follow it automatically[1]. An HTTP 302 response can be as short as this:

An HTTP 302 response
HTTP/1.1 302 Found
Location: https://www.example.com/autumn-sale
Content-Length: 0

The words after the number are the reason phrase. HTTP/1.0 called a 302 “Moved Temporarily”[2], and some servers still send that phrase; nginx’s source code does[20]. It carries no meaning. RFC 9110 says reason phrases “can be replaced by local equivalents or left out altogether without affecting the protocol”[1]. Clients act on the number.

A real one: when we checked on 2 October 2026, the address of the HTTP specification itself, rfc-editor.org/rfc/rfc9110, answered 302 Found with a Location of https://www.rfc-editor.org/info/rfc9110/. Your browser lands on the info page, and the address you typed stays the one to use next time. That is exactly what a 302 promises.

302 vs 301, 303, 307 and 308

Five status codes redirect a page. They differ on two questions: is the move permanent, and may the client change the request method when it follows?[1][3]

The five redirect codes
Meaning from RFC 9110 and MDN; Google's treatment from Google Search Central. Toggle columns.
Permanent?Request method when followedHow Google treats itTypical use
301 Moved Permanently✓YesGET stays GET; a POST may become GETStrong signal: the target becomes canonicalMoved pages, domain moves, http to https
302 Found✕NoGET stays GET; a POST may become GETWeak signal: the original URL stays in resultsShort-lived moves, A/B tests, maintenance
303 See Other✕NoBecomes GET (or HEAD)TemporaryAfter a form submission, to a result page
307 Temporary Redirect✕NoAlways keptEquivalent to 302Temporary moves where a POST must stay a POST
308 Permanent Redirect✓YesAlways keptEquivalent to 301Permanent moves for forms and APIs

For pages that people and crawlers read with GET, the method column changes nothing. GET stays GET under every one of these codes. The difference shows up with forms and APIs. The Fetch Standard, which browsers implement, turns a POST into a GET when it follows a 301 or a 302[5]. RFC 9110 explains the history: early browsers split on the question, “prevailing practice eventually converged on changing the method to GET”, and 307 and 308 were added later “to unambiguously indicate method-preserving redirects”[1]. MDN puts it plainly: “The difference between 307 and 302 is that 307 guarantees that the client will not change the request method and body when the redirected request is made”[4].

Google does not care about that difference. Its crawler documentation lists 307 as “Equivalent to 302” and 308 as “Equivalent to 301”. It still asks you to pick the right one: “Use the status code that’s appropriate for the redirect so other clients (for example, e-readers, other search engines) may benefit from it”[7]. The full permanent-or-temporary decision is in 301 vs 302, and what a permanent move does for search is in 301 Moved Permanently.

When a 302 is the right redirect

Google gives the test. Choose a redirect by “how long you expect the redirect will be in place and what page you want Google Search to show in search results”[6]. A 302 is right when the answers are “not long” and “the original page”.

  • A short outage or maintenance. Google’s own example is a service that is temporarily unavailable: a temporary redirect sends users to a page that explains what is happening “without compromising the original URL in search results”[6].
  • A/B tests. When a test sends users from the original URL to a variation, Google says to “use a 302 (temporary) redirect, not a 301 (permanent) redirect”, so search engines “keep the original URL in their index”[8].
  • A campaign or a season. /sale points at this month’s sale page and will point somewhere else next month. The short URL is the one people share, so it is the one that should stay.
  • A detour for one visit. A sign-in page before an account page, or a notice while a product is out of stock, where the original URL is the one that matters.

It is the wrong code for anything you will not undo: a page moved for good, a deleted page pointed at its replacement, a domain move, and the http to https, www and trailing-slash rules every site has. Those are permanent by nature. Google’s advice is to use permanent redirects “when you’re sure that the redirect won’t be reverted”[6].

The 302 you did not ask for
Some servers send a 302 when you leave the code out. Apache’s Redirect: “If no status argument is given, the redirect will be ‘temporary’ (HTTP status 302)”[18]. In nginx, the redirect flag on rewrite “returns a temporary redirect with the 302 code”, and return given only a URL sends 302 as well[19]. If you meant permanent, write 301.

How Google treats a 302

Google describes it in two documents, in slightly different words. Its redirects guide says that for a temporary redirect, “Googlebot follows the redirect, but the indexing pipeline doesn’t use the redirect as a signal that the redirect target should be canonical”. It adds that “the target page might still be indexed if other canonicalization signals are present”[6]. Its status-code reference calls a 302 a “weak signal that the redirect target should be processed”, where a 301 is a “strong signal”[7]. The short version, from the same guide: temporary redirects “show the source page in search results”[6].

Two more details matter. Google ignores any content on the redirecting URL and processes the final target’s content instead. And its crawlers follow “up to 10 redirect hops” by default[7], so a 302 at the end of a long chain may never be reached. Chains that loop back on themselves are covered in ERR_TOO_MANY_REDIRECTS.

What happens when a 302 stays up for months

Google’s documentation does not say. What exists is what Google’s John Mueller has said in public, as reported by Search Engine Roundtable. In 2015: “when we recognize it is actually more like a permanent redirect and 302 is something that you may have accidentally set up, then we do treat that as a 301”[9]. In 2021 he described the mechanism: “with redirects, we tend to put URLs into the same bucket, and then use canonicalization to pick which one to show”. A 302 suggests the source is preferred, but Google weighs more than the redirect: “if all internal & external links point to the destination, probably we should pick the destination too. There’s no fixed cut-off time for that.”[10]

So a forgotten 302 is usually not a disaster in Google. It is also not under your control: you do not know when, or whether, the switch happens. If the move is permanent, say so with a 301. If it is temporary, keep your own links pointing at the original URL, because links to the destination are one of the signals that tip Google the other way.

By Google’s account, a 302 decides which address it shows, not whether your links count. Pick the code that matches the move, and you never have to wait for Google to guess.

302 SEO myths

Myth
A 302 throws away your links.
What is true
Google's John Mueller, in 2015: "both of these redirects pass PageRank, it is just a matter of which of these URLs we actually show in the search results." With a 302, that is the original URL, at first.
Myth
Google never indexes the target of a 302.
What is true
Google says the target "might still be indexed if other canonicalization signals are present", and a long-lived 302 can drift towards being treated as permanent.
Myth
A 307 is better for SEO than a 302.
What is true
Google lists 307 as equivalent to 302. The only difference is the request method, which matters for forms and APIs, not for pages.
Myth
Google will work it out, so the code does not matter.
What is true
Google may, eventually, with no fixed timing. Browsers, other search engines and AI crawlers do not run Google's canonicalization, and Google itself asks for the code that matches the move.

Sources: Search Engine Roundtable, reporting John Mueller[9][10]; Google[6][7].

MDN states the cautious version: search engines receiving a 302 “will not attribute links to the original URL to the new resource, meaning no SEO value is transferred to the new URL”[3]. That fits Google’s account if you read it as “the original URL keeps the credit while the redirect is treated as temporary”, not “the credit disappears”.

How browsers, Google and AI crawlers handle a 302

The same response reaches very different readers. Here is what each one is documented to do, and where the documentation stops.

Who follows a 302, and how far
From each client's own documentation or specification. 'Not published' means we found nothing, not that there is no limit. Toggle columns.
Follows a 302?Redirect limitWhat it keeps afterwardsDocumented by
BrowsersYes, automatically20 in a rowNothing, unless caching headers allow itFetch Standard, RFC 9110
GooglebotYes10 hops by defaultThe original URL in results, at firstGoogle Search Central
GPTBot, ClaudeBot, PerplexityBotVery likely; not documentedNot publishedNot publishedNobody
curlOnly with -L50 by defaultn/acurl manual
Python RequestsYes, by default, except HEAD30 by defaultn/aRequests docs

Sources: Fetch Standard[5]; RFC 9110[1]; Google[7][6]; OpenAI, Anthropic and Perplexity[12][13][14]; curl[17]; Requests[15][16].

Browsers follow a 302 at once and show the destination’s address. They give up after 20 redirects in a row: the Fetch Standard returns a network error when “request’s redirect count is 20”[5]. They also do not remember a 302 by default. RFC 9110 lists 301 and 308 among the codes a cache may reuse without explicit instructions; 302 is not on that list[1]. That makes a 302 easy to undo: change the rule and visitors get the change on their next request, unless you sent caching headers with it.

AI crawlers: what is documented, and what is not

Start with the gap. We read the crawler documentation of OpenAI, Anthropic and Perplexity on 2 October 2026[12][13][14]. None of the three mentions redirects. None says whether its crawlers follow a 302, how many hops they allow, or which URL they keep, the source or the target. Anyone quoting a number for them is guessing.

What can be said with confidence is narrower. A 302 is part of the HTTP response, so a crawler meets it before any page content. Standard HTTP clients follow it by default: Python’s Requests “will perform location redirection for all verbs except HEAD”[15], and browsers follow automatically[5]. curl is the exception, and only because you have to ask: it follows with -L[17]. So it is very likely that GPTBot, ClaudeBot and PerplexityBot follow a server-side 302. That is an inference, not a documented fact.

One thing has been measured. Vercel’s study of its own network found that OpenAI’s, Anthropic’s and Perplexity’s crawlers fetch JavaScript files but do not run them[11]. A redirect done in JavaScript is invisible to them: they read the page that holds the script and stop there. The same study found that 14.36% of ChatGPT’s crawler fetches went on following redirects, against 1.49% for Googlebot[11]. That is one vendor’s data from a few months on one network, and it covers every kind of redirect, not just 302s.

There is a twist for tests. Google says JavaScript-based redirects “are also fine” for A/B tests[8]. For AI crawlers, that means they keep reading the original page, which is what a temporary test intends anyway. For a real move, a JavaScript redirect leaves them on the old page for good. Use a server-side code.

The more common problem is not the code but who gets it. Bot protection and CDN rules can treat crawler user agents differently, so a browser gets a 302 to the sale page while GPTBot gets a 403. The redirect checker runs a single URL as a browser and as GPTBot, ClaudeBot, PerplexityBot and Googlebot, and says when the chains differ. It sends their user-agent strings from our own server, so a site that verifies crawlers by IP address may treat it differently from the real bot. Confirm any difference in your server logs; the guide to AI crawler log file analysis shows how.

How to send a 302

Name the code explicitly, even where 302 is the default, so the next person to read the config knows it was intended. Pick your server.

mod_alias takes a number or the keyword temp, which “returns a temporary redirect status (302)”[18].
.htaccess
# .htaccess or the virtual host
Redirect 302 /sale https://www.example.com/autumn-sale

# The same, with the keyword
Redirect temp /sale https://www.example.com/autumn-sale

# With mod_rewrite, put the code in the R flag
RewriteEngine On
RewriteRule ^sale$ https://www.example.com/autumn-sale [R=302,L]

Why does Next.js default to 307? Its documentation says it plainly: “Traditionally a 302 was used for a temporary redirect, and a 301 for a permanent redirect, but many browsers changed the request method of the redirect to GET, regardless of the original method”[21]. A 307 keeps the method. The redirect() function in server code also sends 307, or 303 after a Server Action[22]. For pages read with GET, 307 and 302 do the same job, and Google treats them the same[7]. Only switch to an exact 302 if an older client needs it. More on what crawlers receive from Next.js is in the Next.js SEO guide.

How to check what a URL sends

A browser hides redirects; you only see where you land. Three ways to see the HTTP 302 itself.

curl. Without -L, curl does not follow redirects[17], so it prints the first response:

Terminal
$ curl -sS -o /dev/null -D - https://www.rfc-editor.org/rfc/rfc9110
HTTP/1.1 302 Found
Location: https://www.rfc-editor.org/info/rfc9110/

That is what we got on 2 October 2026, with the other headers trimmed. Add -L to follow the whole chain and print every hop. One catch: when curl follows a 302 after a POST, it switches to GET, as browsers do, unless you pass --post302[17].

Browser developer tools. Open the Network tab, turn on Preserve log, and load the URL. The first row shows the 302 and its Location header.

The redirect checker. It follows every hop up to 10, the same limit as Google’s crawlers, and shows each status code, Location and response time. It labels every 302 as temporary, and when a 302 does a job that is permanent by nature, such as http to https, www or a trailing slash, it says so and suggests a 301. It also runs the chain as four crawlers and reads the final page for meta refresh and JavaScript redirects.

Before you ship a 302
0/8

Checking every page

The redirect checker is free and looks at the URLs you give it, up to 10 at a time. The 302s that cause trouble are often the ones nobody remembers: an old internal link, a sitemap entry, a campaign rule that outlived the campaign. The GEO Audit crawls your site and runs 31 checks on every page, including whether each one answers with a clean 200 or only after a redirect. A free account audits 10 pages; every limit is on the pricing page.

Questions people ask

What does a 302 status code mean?

302 Found means the page you asked for is temporarily at another URL, given in the Location header. The client should follow it this time but keep using the original URL in future. Browsers follow it automatically, so visitors rarely notice it.

What is the difference between a 301 and a 302?

A 301 says the move is permanent, so Google uses the new URL as the canonical one and shows it in results. A 302 says the move is temporary, so Google keeps showing the original URL. Google's documentation calls a 301 a strong signal and a 302 a weak one.

Is a 302 redirect bad for SEO?

Not when the move is temporary. That is what it is for, and Google recommends it for A/B tests. It becomes a problem when it is used for a permanent move, such as http to https or a deleted page, because Google keeps the old URL as the one to show, for a time nobody can predict.

Does Google treat a long-lived 302 as a 301?

Often, eventually. Google's documentation does not say so, but Google's John Mueller has said a 302 can end up treated like a 301 over time, especially when links point at the destination, and that there is no fixed cut-off. If a move is permanent, send a 301 rather than wait.

What is the difference between 302 and 307?

Both are temporary. A 307 forbids the client from changing the request method, so a POST stays a POST. After a 302, browsers turn a POST into a GET. For ordinary pages read with GET there is no practical difference, and Google treats 307 as equivalent to 302.

Do AI crawlers like GPTBot follow 302 redirects?

Very likely, but it is not documented. When we read OpenAI's, Anthropic's and Perplexity's crawler documentation on 2 October 2026, none of it mentioned redirects. A server-side 302 is standard HTTP that common clients follow by default. JavaScript redirects are different: the major AI crawlers do not run JavaScript, so they never see them.

How do I check if a URL returns a 302?

Run it through a redirect checker, which shows every hop with its status code and Location header. From a terminal, curl with -D - and without -L prints the first response without following it. In a browser, the Network tab in developer tools shows the 302 if Preserve log is turned on.

Keep reading

Sources

[3]302 Found — MDN Web Docs, last modified 22 June 2026
[4]307 Temporary Redirect — MDN Web Docs, last modified 22 June 2026
[5]Fetch Standard: HTTP-redirect fetch — WHATWG, updated 21 September 2026
[6]Redirects and Google Search — Google Search Central, updated 14 April 2026
[7]How HTTP status codes, and network and DNS errors affect Google Search — Google Search Central, updated 4 February 2026
[8]A/B testing best practices for Search — Google Search Central, updated 10 December 2025
[9]Google Will Make Your 302 Temporary Redirects Into 301 Permanent Redirects When... — Search Engine Roundtable (Barry Schwartz, reporting John Mueller of Google), 16 October 2015
[10]Why 302 Redirects Often Are Treated As 301 Redirects By Google Search — Search Engine Roundtable (Barry Schwartz, reporting John Mueller of Google), 9 April 2021
[11]The rise of the AI crawler — Vercel (vendor study of its own network), 17 December 2024
[12]Overview of OpenAI Crawlers — OpenAI, read 2 October 2026
[14]Perplexity Crawlers — Perplexity docs, read 2 October 2026
[15]Quickstart: Redirection and History — Requests documentation, read 2 October 2026
[16]Developer Interface: Session.max_redirects — Requests documentation, read 2 October 2026
[17]curl man page (--location, --post302, --max-redirs) — curl.se, read 2 October 2026
[18]Apache Module mod_alias — Apache HTTP Server 2.4 documentation, read 2 October 2026
[19]Module ngx_http_rewrite_module — nginx.org, read 2 October 2026
[20]ngx_http_header_filter_module.c (status lines) — nginx source code, GitHub, read 2 October 2026
[21]next.config.js: redirects — Next.js docs, updated 30 June 2026
[22]Guides: Redirecting — Next.js docs, updated 25 August 2026
[23]File-system conventions: proxy.js — Next.js docs, updated 7 September 2026

Find out where you actually stand

One real question, real AI engines, and the answer they gave — including who was named in it. No account, no card.