HTTP status codes · Quick reference

HTTP status code reference for redirects and endpoints

A redirect trace combines response codes, Location values and the last reachable endpoint. Use the code to understand the response, then confirm that the destination preserves the intended resource. RedirectPath follows GET requests and does not test POST behavior.

Redirect status codes

Choose permanence according to the actual move. For operations that submit data, verify method handling in a controlled client test.

Redirect status codes
CodeMeaningMethod handlingTypical decision
301 Permanent move Clients may change POST to GET. A lasting URL move where this behavior is acceptable.
302 Temporary destination Clients may change POST to GET. A temporary GET journey.
303 See another resource Retrieve the destination with GET or HEAD. Show a result page after a submission.
307 Temporary redirect Preserves method and body. Temporary routing that must preserve an operation.
308 Permanent redirect Preserves method and body. Lasting routing that must preserve an operation.

Reference: RFC 9110: Redirection

Common endpoint responses

An endpoint can be reached successfully by the scanner while returning an application error. Diagnose that status before calling the journey complete.

Common endpoint responses
CodeInterpretationNext check
200 / 204 Successful response; 204 has no content. Confirm the resource and intended response type.
304 Conditional request can reuse a stored response. Inspect cache validators; it is not a Location redirect.
401 / 403 Authentication required or access refused. Check access rules and edge restrictions.
404 / 410 Resource missing or intentionally gone. Confirm whether the URL should have a replacement.
429 Request rate limited. Check Retry-After and relevant rate limits.
500 Server encountered an internal error. Inspect application logs at the request time.
502 / 504 Gateway upstream failure or timeout. Check the proxy and upstream service.
503 Service temporarily unavailable. Check maintenance state and service health.

Reference: RFC 9110: Status codes

Read chains and stop reasons

A repeated URL is evidence of a loop. A time, download or redirect limit is a different stop condition: the complete journey remains unknown. Review the last Location and the owner of that response before changing rules.

Temporary redirects and host changes can be intentional. Preserve meaningful paths and parameters, and avoid routing unrelated old pages to the homepage.

http://example.com/docs → 301 https://example.com/docs
https://example.com/docs → 200

Loop example:
https://example.com/docs → https://www.example.com/docs
https://www.example.com/docs → https://example.com/docs

Verify with an independent GET trace

Use harmless test URLs and parameters. This command prints each response header block while following at most ten redirects. A stopped command needs investigation; it does not establish the final page status.

curl --silent --show-error --location --max-redirs 10 --dump-header - --output /dev/null http://example.com/docs
  1. Test HTTP, HTTPS, both hostname variants and an existing deep link.
  2. Read each Location and compare the final path and required parameters.
  3. Test forms and APIs separately; this trace uses GET.

Reference: curl: redirects and headers

From scan to solution

Make every redirect lead somewhere useful

A redirect check shows the journey between a link and its destination. RedirectPath follows HTTP redirects and records each hop so you can spot detours, loops and unexpected status codes. These guides explain which redirect to choose, how to debug a broken chain and what to check when moving a site to HTTPS.