Glossary · HTTP, edge and rendering
Cache-Control
The response header that states how long, and by whom, a response may be stored: max-age for the browser, s-maxage for shared caches, no-store to forbid storing, private to keep it out of shared caches.
What Cache-Control means
The response header that states how long, and by whom, a response may be stored: max-age for the browser, s-maxage for shared caches, no-store to forbid storing, private to keep it out of shared caches. It governs future stores only; a copy already sitting at an edge is unaffected by a header the origin starts sending later.
What Cache-Control can and cannot support
| It can support | It cannot support |
|---|---|
| The response header that states how long, and by whom, a response may be stored: max-age for the browser, s-maxage for shared caches, no-store to forbid storing, private to keep it out of shared caches. | It governs future stores only; a copy already sitting at an edge is unaffected by a header the origin starts sending later. |
Where Cache-Control comes up on this site
- Cached robots.txt and llms.txt: stale, split, or blockedNever let a challenge or maintenance page be cacheable: a Cache-Control: no-store on every interstitial response is the single setting that prevents the split case.
- Your new cache rule did not fix the object it was written forWhat worked was a response header transform rule: rewrite cache-control to public, max-age=300 on the machine-file paths.
- Your cache purge returned 200 and evicted nothingOn one of our own properties a Cache-Control: no-cache request header did not bypass the application’s page cache at all, and only a query string did.
- robots.txt returned 200 and no crawler could read it: challenge pagesIts response carried Cache-Control: private, no-store — the standard way of saying this answer is for one requester only .
Related terms in HTTP, edge and rendering
The delivery layer between an origin and a client: proxies, caches, redirects, status codes and the headers that decide what a crawler actually received.
Origin server · Reverse proxy · CDN · Edge node · WAF · Bot score · TLS handshake · DNS resolution · DNS timeout · Connection timeout · Read timeout · Redirect chain · Redirect loop · 301 redirect · 302 redirect · 307 redirect · 308 redirect · 304 response · 404 response · 410 response · 429 response · 500 response · 502 response · 503 response · 504 response · HEAD request · GET request · Content type · MIME sniffing · Content encoding · Compression · Brotli · ETag · Last-Modified · If-None-Match · Cache hit · Cache miss · Cache key · Vary header · Stale response · Stale-while-revalidate · Edge redirect · Origin bypass · Response parity · Header parity · hreflang · canonical URL · HSTS · HSTS preload list · Content-Security-Policy · CSP nonce · edge cache · cache split · cache-buster · Age header · render-blocking resource · payload text share · lazy loading · 404 and 410 status codes
Questions about Cache-Control
What is Cache-Control?
The response header that states how long, and by whom, a response may be stored: max-age for the browser, s-maxage for shared caches, no-store to forbid storing, private to keep it out of shared caches.
What does Cache-Control not show or guarantee?
It governs future stores only; a copy already sitting at an edge is unaffected by a header the origin starts sending later.
Which area of the glossary does Cache-Control belong to?
HTTP, edge and rendering: The delivery layer between an origin and a client: proxies, caches, redirects, status codes and the headers that decide what a crawler actually received.
← cache-buster · Age header →
See it in the full glossary · 668 terms across 19 areas.