Lifestyle

Cloudflare Adds HTTP Vary Header Support to Cache Rules for Websites on All Plans

On September 22, 2026, Cloudflare announced that its Cache Rules now support the HTTP Vary header on all plans. Websites that use Cloudflare's caching can decide how each request header affects which stored copy visitors get, which Cloudflare says helps avoid serving the wrong content while keeping the cache useful.

About 6 min read

Cloudflare Adds HTTP Vary Header Support to Cache Rules for Websites on All Plans
Image: Mokaair (Original editorial artwork)

What happened

On September 22, 2026, Cloudflare published a blog post by Alex Krivit and Zaidoon Abd Al Hadi announcing support for the HTTP Vary response header. Cloudflare said the feature is now available in Cache Rules on all plans. The post also quotes a description of Vary as "the ugliest part of HTTP that we haven't yet improved.", showing how awkward this header has long been to handle.

Some background helps. A cache is a store of ready-made copies of web pages and files. A CDN (content delivery network) such as Cloudflare keeps these copies so visitors can be answered quickly without asking the website's own server, called the origin, every time. When a browser asks for a page, it sends request headers: short notes such as its preferred language or the file formats it accepts. According to Cloudflare, Vary is a standard HTTP response header that tells intermediary caches like a CDN which of those request fields may affect the origin's response. Sites commonly use it to serve different languages, image formats, compression methods or regional content at the same URL.

Cloudflare Adds HTTP Vary Header Support to Cache Rules for Websites on All Plans
Mokaair editorial verification flow · Image: Mokaair (Original editorial artwork)
Read the full description

Sources are collected, independently checked, then reviewed by Jev.

Why Vary is hard to handle

Cloudflare uses examples to describe the dilemma. If a cache ignores Vary, the HTML and JSON versions of the same URL may go to the wrong clients. For example, an app expecting data could receive web page markup it cannot parse. If instead a cache treats every raw header value as distinct, a handful of similar requests can scatter into thousands of stored copies that are almost never reused. In one example, two Accept-Language values (the header that states language preferences) differ in order and language tags. According to Cloudflare, both effectively prefer English, so the origin may return the same English response, but the cache stores them separately because the raw values differ.

Cloudflare notes that one field with 10 values produces 10 variants, while three fields with 10 values each can produce 1,000 combinations. These scattered variants take up storage space, push one another out of the cache and lower the cache hit ratio, which is the share of requests answered from stored copies. They also send more requests back to the origin. An analysis cited by Cloudflare examined more than 120 million responses from nearly 50,000 popular websites. It found that nearly 3,000 sites vary on four or more fields, some on 10, 23 or even 47.

How Cache Rules handle Vary

Cloudflare says the new design splits the decision in two. The origin uses Vary to indicate which request headers may affect the response, and the Cache Rule decides how Cloudflare treats each header's values. If the origin does not return Vary, Cloudflare caches as usual. Headers without an individual setting fall back to the rule's default action.

The three actions for handling Vary in Cloudflare Cache Rules, as described by Cloudflare
ActionBehavior as described by CloudflareUse case recommended by Cloudflare
normalizeTidies the request header into a standard form before picking a stored copy, so equivalent requests share one cache entry; applies dedicated rules to Accept, Accept-Language and Accept-EncodingRecommended starting point for negotiation headers (those where browser and server agree on language, format or compression), where many request values map to a few responses
passthroughMatches the cache on the request header's exact raw bytes, preserving case, whitespace, order and duplicate valuesHeaders whose values are controlled and whose exact value changes the response
bypassDoes not store the response when the origin lists the header in Vary; existing cache entries are not removedPersonalized headers, headers with a very large number of possible values (high-cardinality) or unexpected headers

What it means for readers and site administrators

For everyday internet users, changes like this happen behind the scenes. Cloudflare says Vary exists to stop a cache from handing a visitor the wrong version of a page, such as the wrong language or format. For site administrators, Cloudflare says earlier approaches to such content each had a limitation. Bypassing the cache gives up caching, and custom cache keys duplicate application logic. Workers require extra code, while Vary for images covers only a narrower use case. Cloudflare says the new feature is meant to fill the gaps between them.

The feature details and benefits above are Cloudflare's own description in its announcement. Actual results depend on each site's configuration and traffic. This article only summarizes the announcement and does not constitute a recommendation to buy any product or service.

Frequently asked questions

What is the HTTP Vary header?

According to Cloudflare, Vary is a standard HTTP response header that tells intermediary caches which request fields may affect the origin server's response. It is commonly used to serve different languages, image formats, compression methods or regional content at the same URL.

Which Cloudflare plans can use this feature?

Cloudflare says Vary support in Cache Rules is available on all plans.

What happens if my site does not send Vary?

Cloudflare says that if the origin server does not return Vary, Cloudflare caches the response as usual.

Which of the three actions should I start with?

Cloudflare recommends normalize as the starting point for negotiation headers. It recommends passthrough when values are controlled and the exact value affects the response, and bypass for personalized, high-cardinality or unexpected headers.

Where does this information come from?

All information in this article comes from Cloudflare's official blog post announcing the feature, so it reflects the company's own description.

Browse the latest news in this topic

Latest travel guides

Sources

Lifestyle