302 redirect
A temporary HTTP redirect — the correct kind for a dynamic QR code.
A 302 is an HTTP response telling the browser the resource is temporarily somewhere else. A 301 says permanently.
Why dynamic QR codes must use 302. A 301 is aggressively cached by browsers, sometimes indefinitely. If a dynamic code issued a 301 and you later edited the destination, every device that had already scanned it would keep going to the old destination — possibly forever, with no way to clear it remotely. The ability to edit would be silently broken for exactly the people who had used the code most.
The accompanying header. A correct implementation also sends
Cache-Control: no-store, so intermediaries do not cache the redirect either.
Together these mean an edit takes effect on the very next scan.
How to check. curl -I against a dynamic code's URL will show
the status and cache headers. If you see a 301, test whether editing the destination
actually propagates.
In practice
A restaurant repoints its menu code in March. Customers who scanned it in February arrive
at the new menu immediately, because the platform returned a 302 with
Cache-Control: no-store and nothing was retained.
Had the platform returned a 301, those same customers' browsers could keep going to the February menu indefinitely, with no way for the restaurant to clear it. They would see correct behaviour on a fresh phone and a stale menu on their own, which is a genuinely difficult problem to even notice, let alone diagnose.
Questions
Does 302 hurt SEO?
Irrelevant here. A QR redirect address is not a page you want indexed — ours is disallowed in robots.txt. The 301-versus-302 SEO debate concerns website migrations, not QR codes.
How can I check what a platform uses?
curl -I https://their-domain/their-slug shows the status code and the
cache headers. If you see 301, test whether editing the destination actually
propagates to a device that has already scanned it.