Cache multiple versions of a URL with Vary
Cloudflare's cache now honors the Vary response header directly in Cache Rules, allowing the same URL to hold multiple cached versions based on request headers like Accept-Language or Accept. Origins can choose to normalize equivalent headers, pass through raw values, or bypass cache for specific headers, improving cache hit ratios while maintaining correct content negotiation without requiring code changes.
Your origin can serve different responses for the same URL — different languages based on Accept-Language, or different formats based on Accept — by returning a Vary ↗ response header. Cloudflare's cache now honors that header directly in Cache Rules, so the same URL can hold multiple cached versions and each request is matched to the right one. Content that previously had to bypass cache to stay correct can now be cached, following standard HTTP caching behavior ↗.
What changed
Your origin now decides which request headers matter by listing them in its Vary response, and you control how Cloudflare treats each one. When you have enabled Vary using a cache rule and a response includes a Vary header, the request headers listed become part of the cache key.
For each header your origin varies on, choose one of three actions:
| Action | Behavior | Best for |
|---|---|---|
normalize |
Converts equivalent header values to the same cache key value before matching, collapsing redundant versions. | Most Accept, Accept-Language, and Accept-Encoding use cases. |
passthrough |
Uses the raw header value to select the cached version and forwards it to the origin unchanged. | When byte-for-byte differences in the header value should create versions. |
bypass |
Bypasses cache whenever this header name appears in the origin's Vary response. |
Per-user values, or headers with too many possible values to cache safely. |
Benefits
- Higher cache hit ratios:
normalizetreats semantically equivalent headers as one version. For example,Accept-Language: en-US, fr;q=0.8andAccept-Language: fr;q=0.8, en-GBboth resolve to the same cache key, so you serve more requests from cache instead of the origin. - Correct content negotiation: Requests always receive the cached version that matches their headers, so language and format variants stay accurate.
- No origin or Worker changes required: If your origin already sends
Vary, you configure the behavior entirely in Cache Rules. - Standards-aligned: Cache key calculation follows RFC 9111, and
Vary: *continues to bypass cache as required by RFC 9110.
Availability
Vary in Cache Rules is available on all plans (Free, Pro, Business, and Enterprise). For per-request control in Workers subrequests, use the cf.vary property.
Get started
Configure Vary in the Cloudflare dashboard ↗ under Caching > Cache Rules, or through the Rulesets API. To learn how Vary affects cache keys and how each action works, refer to Vary and the Cache Rules Vary setting.
Source: original entry ↗
More from Cloudflare
Follow Cloudflare to get its new changes in your feed and email digest.
Cloudflare One Client for macOS 2026.8.2100.0
GA release for macOS Cloudflare One Client with improved split tunnel handling that no longer briefly blocks traffic during reconnects, support for non-RFC 1918 local IPv4 networks, faster connects with lower memory use, and numerous reliability fixes across DNS, reauthentication, and client stability.
Cloudflare One Client for Windows 2026.8.2100.0
This GA release improves split tunnel reliability, adds support for non-RFC 1918 local networks, optimizes connection performance with faster reconnections and lower memory usage, and includes numerous bug fixes for DNS, registration, and network handling. The client now features a service recovery mechanism that automatically restarts on system unlock and better handles large hosts files without blocking traffic.
Cloudflare One Client for Linux 2026.8.2100.0
New GA release for Linux with improved split tunnel handling that no longer briefly blocks traffic during reconnects, support for non-RFC 1918 local IPv4 networks, faster tunnel reconnections, and lower memory usage. Includes numerous stability and reliability fixes for DNS, reconnection behavior, and crash issues.