Simon Willison1 min readintermediate
We just shipped support for the ugliest part of HTTP: Vary
Summary
Cloudflare now respects the Vary header for non‑image resources, allowing caches to serve different representations (HTML vs JSON) safely. The author still prefers explicit URL suffixes like .json for clarity.
- Cloudflare's new feature stops ignoring Vary on anything other than images, preventing cache‑poisoning when using content negotiation.
- You can now safely cache responses that vary by Accept header (e.g., HTML vs JSON) behind Cloudflare.
- The author recommends using distinct URLs (e.g., .json) instead of relying on Vary for clearer API design.
Anyone serving dynamic content through Cloudflare should know they can now use Vary safely, or reconsider their URL design.
4/10




