Lifestyle
Cloudflare Adds HTTP Vary Header Support to Cache Rules for Websites on All Plans
On September 22, 2026, Cloudflare announced that its Cache Rules now support the HTTP Vary header on all plans. Websites that use Cloudflare's caching can decide how each request header affects which stored copy visitors get, which Cloudflare says helps avoid serving the wrong content while keeping the cache useful.
About 6 min read

What happened
On September 22, 2026, Cloudflare published a blog post by Alex Krivit and Zaidoon Abd Al Hadi announcing support for the HTTP Vary response header. Cloudflare said the feature is now available in Cache Rules on all plans. The post also quotes a description of Vary as "the ugliest part of HTTP that we haven't yet improved.", showing how awkward this header has long been to handle.
Some background helps. A cache is a store of ready-made copies of web pages and files. A CDN (content delivery network) such as Cloudflare keeps these copies so visitors can be answered quickly without asking the website's own server, called the origin, every time. When a browser asks for a page, it sends request headers: short notes such as its preferred language or the file formats it accepts. According to Cloudflare, Vary is a standard HTTP response header that tells intermediary caches like a CDN which of those request fields may affect the origin's response. Sites commonly use it to serve different languages, image formats, compression methods or regional content at the same URL.
Read the full description
Sources are collected, independently checked, then reviewed by Jev.
Why Vary is hard to handle
Cloudflare uses examples to describe the dilemma. If a cache ignores Vary, the HTML and JSON versions of the same URL may go to the wrong clients. For example, an app expecting data could receive web page markup it cannot parse. If instead a cache treats every raw header value as distinct, a handful of similar requests can scatter into thousands of stored copies that are almost never reused. In one example, two Accept-Language values (the header that states language preferences) differ in order and language tags. According to Cloudflare, both effectively prefer English, so the origin may return the same English response, but the cache stores them separately because the raw values differ.
Cloudflare notes that one field with 10 values produces 10 variants, while three fields with 10 values each can produce 1,000 combinations. These scattered variants take up storage space, push one another out of the cache and lower the cache hit ratio, which is the share of requests answered from stored copies. They also send more requests back to the origin. An analysis cited by Cloudflare examined more than 120 million responses from nearly 50,000 popular websites. It found that nearly 3,000 sites vary on four or more fields, some on 10, 23 or even 47.
How Cache Rules handle Vary
Cloudflare says the new design splits the decision in two. The origin uses Vary to indicate which request headers may affect the response, and the Cache Rule decides how Cloudflare treats each header's values. If the origin does not return Vary, Cloudflare caches as usual. Headers without an individual setting fall back to the rule's default action.
| Action | Behavior as described by Cloudflare | Use case recommended by Cloudflare |
|---|---|---|
| normalize | Tidies the request header into a standard form before picking a stored copy, so equivalent requests share one cache entry; applies dedicated rules to Accept, Accept-Language and Accept-Encoding | Recommended starting point for negotiation headers (those where browser and server agree on language, format or compression), where many request values map to a few responses |
| passthrough | Matches the cache on the request header's exact raw bytes, preserving case, whitespace, order and duplicate values | Headers whose values are controlled and whose exact value changes the response |
| bypass | Does not store the response when the origin lists the header in Vary; existing cache entries are not removed | Personalized headers, headers with a very large number of possible values (high-cardinality) or unexpected headers |
What it means for readers and site administrators
For everyday internet users, changes like this happen behind the scenes. Cloudflare says Vary exists to stop a cache from handing a visitor the wrong version of a page, such as the wrong language or format. For site administrators, Cloudflare says earlier approaches to such content each had a limitation. Bypassing the cache gives up caching, and custom cache keys duplicate application logic. Workers require extra code, while Vary for images covers only a narrower use case. Cloudflare says the new feature is meant to fill the gaps between them.
The feature details and benefits above are Cloudflare's own description in its announcement. Actual results depend on each site's configuration and traffic. This article only summarizes the announcement and does not constitute a recommendation to buy any product or service.
Frequently asked questions
What is the HTTP Vary header?
According to Cloudflare, Vary is a standard HTTP response header that tells intermediary caches which request fields may affect the origin server's response. It is commonly used to serve different languages, image formats, compression methods or regional content at the same URL.
Which Cloudflare plans can use this feature?
Cloudflare says Vary support in Cache Rules is available on all plans.
What happens if my site does not send Vary?
Cloudflare says that if the origin server does not return Vary, Cloudflare caches the response as usual.
Which of the three actions should I start with?
Cloudflare recommends normalize as the starting point for negotiation headers. It recommends passthrough when values are controlled and the exact value affects the response, and bypass for personalized, high-cardinality or unexpected headers.
Where does this information come from?
All information in this article comes from Cloudflare's official blog post announcing the feature, so it reflects the company's own description.
Browse the latest news in this topic
Lifestyle
Cloudflare launches Traces in public beta: site operators can follow every step a request takes through the platform on one timeline
On October 2, 2026, Cloudflare announced the public beta of Cloudflare Traces. Website operators and developers using Cloudflare can see a request pass through security rules, caching, routing and the origin server on a single timeline, making it easier to find why a request was blocked or slowed. New pricing takes effect on December 1, 2026. Information comes from the official Cloudflare blog.
Lifestyle
Cloudflare launches Web Search API via AI Gateway, requiring search partners to follow its crawler rules
On October 2, 2026, Cloudflare announced a Web Search API that lets AI agents query live web information through AI Gateway. The first partners are Ceramic.ai, Exa and Linkup. Cloudflare says these partners' crawlers must meet its Verified bots requirements and cite sources. This matters both to developers building AI applications and to website owners whose content may be crawled.
Lifestyle
Cloudflare open-sources Streamline: a demo of using its cloud services to add graphics to live streams and burn subtitles into videos
On October 2, 2026, Cloudflare launched and open-sourced Streamline, a developer playground showing how developers can combine Stream, Workers, Containers and Durable Objects to build their own video processing pipelines, such as adding graphics to live streams in real time or adding subtitles to videos. This article explains what it is, how it works, its limitations, and what it means for viewers and developers.
Lifestyle
Google unveils Gemini 4 Argon: cyber defenders get it first, everyone else still has to wait
On September 30, 2026, Google announced Gemini 4 Argon, which it calls its new frontier (most advanced) AI model. For now it is available only to trusted cyber defenders through the Fairwind Program. Here is what Google says the model can do, what it will cost developers, how Google says it is managing the risks, and what it means for everyday users. All figures come from Google itself.
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family