Skip to content
All tool news

Tool desk · Updated daily

Tool news·Vercel·

Vercel Stops Caching Responses That Vary by Cookie.

Vercel CDN now skips caching responses with Vary: Cookie, preventing visitor-specific cookies from creating low-use cache entries.

CW

Create With tool desk

3 sources checked · 2 min read · 3 sections

ShareLinkedIn
Vercel Stops Caching Responses That Vary by Cookie

Vercel CDN no longer caches origin responses when the Vary header includes Cookie. Responses still reach visitors normally, but Vercel does not store them for future requests.

The change prevents cookies from generating large numbers of cache entries that are rarely reused. Cookies often contain visitor-specific values, so two requests for the same route may carry different cookie headers and produce separate cache variants.

According to the Vercel changelog, caching behaviour for other supported Vary headers is unchanged.

Vary tells a cache which request headers may alter a response. When that header contains Cookie, Vercel now serves the response without adding it to the shared CDN cache.

CheckResponse with Vary: Cookie
Response deliveryServed normally
CDN storageNot stored for later requests
x-vercel-cache headerMISS
Runtime Logs reasonvary_key_denied:cookie

The x-vercel-cache header and Runtime Logs provide two ways to identify affected routes. A response shows MISS in the header, while its log entry records vary_key_denied:cookie as the cache reason.

This can also explain a persistent cache miss on a route that was expected to use the CDN. The next check is the Vary header returned by the origin, rather than the route path alone.

Choosing the right header for each response

There are two paths, based on whether cookies actually change the returned content.

If every visitor receives the same response regardless of their cookies, remove Cookie from Vary. Vercel CDN can then cache the response when it meets the platform’s other caching requirements.

If the response is personalised using cookies, keep Cookie in Vary and set Cache-Control: private. This prevents personalised content from being stored in the shared CDN cache.

  1. 1

    Inspect the response

    check whether the origin returns Vary with Cookie

  2. 2

    Read the cache result

    look for MISS in the x-vercel-cache header

  3. 3

    Check Runtime Logs

    find vary_key_denied:cookie as the cache reason

  4. 4

    Match the headers to the content

    remove Cookie for identical responses or use Cache-Control private for personalised ones

Frequently asked questions

What is Vercel’s Vary Cookie caching change? Vercel CDN no longer stores origin responses when the Vary header includes Cookie. It still serves the response, but marks the cache result as MISS.

How can I find responses affected by Vary Cookie? Check the x-vercel-cache response header for MISS. Runtime Logs show vary_key_denied:cookie when Cookie in the Vary header caused the response not to be cached.

Should personalised responses use Cache-Control private? Yes. When a response depends on cookies, keep Cookie in Vary and use Cache-Control: private to stop it being stored in the shared CDN cache.

Sources

3 checked

How we cover tool news: Create With's tool desk drafts these reports with AI from the sources listed above and checks them against those sources before publishing.

Worth passing on?

ShareLinkedIn

Go deeper on Vercel

Related reading, watching and going.

Everything on Vercel →

The briefing

19 May 2026

How to Migrate Your App from Lovable to Claude Code in 2025

Step-by-step guide to migrating your Lovable app to Claude Code. Learn how to move from Lovable's managed platform to a stack you own and control.

Read →

The briefing

10 Feb 2026

OpenClaw Review: 2 Weeks With This AI Agent

Honest 2-week review of OpenClaw — an autonomous AI agent powered by Claude. We test setup, safety, autonomy, and real value to see if it's worth using.

Read →
34 min

Podcast

My Daughter Built a Website Business, Claude Design First Look & Going All-In on Cloudflare

James and Kieran discuss practical AI-powered development through real-world examples, including a seven-year-old building a website business with Claude Code voice mode, Anthropic's new Claude Design tool, API security challenges in the AI agent era, and Cloudflare's expanding AI infrastructure offerings. The episode covers hands-on experiences with vibe coding, emerging design tools, and the evolving landscape of AI-assisted development.

Watch now ↗

Podcast

53. Why Your Vibe Code Needs Tests, Ditching SaaS & AI Agents That Work While You Sleep

James and Kieran discuss the practical realities of building AI-powered software, emphasizing the importance of testing in vibe-coded applications, exploring alternatives to traditional SaaS tools, and implementing autonomous AI agents for business operations. The episode covers technical topics like Convex databases, app store bottlenecks from AI-generated submissions, and using OpenClaw as a marketing automation agent.

Watch now ↗
38 min

Podcast

52. Your AI Co-Founder: OpenClaw, Manus & the Zero-Person Business

In this Create With podcast episode, James and Kieran are joined by Matt Roberts from Happy Operators for an in-depth discussion on using autonomous AI agents in production. The conversation covers practical experiences with OpenClaw, security considerations, comparison with emerging tools like Manus, and the broader shift toward AI-assisted development. They also discuss the VibeCoding Olympics results, Bubble's new AI capabilities, and research on Claude.MD file effectiveness.

Watch now ↗

Latest tool news

What else changed this week.

All tool news
MakeDigest

What Make Shipped in Early October

Make shipped a small but useful reliability update for people building automations in the editor. This one is about protecting work in progress, following broader recent changes…

The Create With Briefing

Don't watch forty changelogs. Read one email.

Every Tuesday: the tool changes worth knowing, real business use cases, and what's on near you. Free, unsubscribe any time.