
Vercel CDN no longer caches origin responses when the Vary header includes Cookie. Responses still reach visitors normally, but Vercel does not store them for future requests.
The change prevents cookies from generating large numbers of cache entries that are rarely reused. Cookies often contain visitor-specific values, so two requests for the same route may carry different cookie headers and produce separate cache variants.
According to the Vercel changelog, caching behaviour for other supported Vary headers is unchanged.
How Vary Cookie responses behave now
Vary tells a cache which request headers may alter a response. When that header contains Cookie, Vercel now serves the response without adding it to the shared CDN cache.
| Check | Response with Vary: Cookie |
|---|---|
| Response delivery | Served normally |
| CDN storage | Not stored for later requests |
x-vercel-cache header | MISS |
| Runtime Logs reason | vary_key_denied:cookie |
The x-vercel-cache header and Runtime Logs provide two ways to identify affected routes. A response shows MISS in the header, while its log entry records vary_key_denied:cookie as the cache reason.
This can also explain a persistent cache miss on a route that was expected to use the CDN. The next check is the Vary header returned by the origin, rather than the route path alone.
Choosing the right header for each response
There are two paths, based on whether cookies actually change the returned content.
If every visitor receives the same response regardless of their cookies, remove Cookie from Vary. Vercel CDN can then cache the response when it meets the platform’s other caching requirements.
If the response is personalised using cookies, keep Cookie in Vary and set Cache-Control: private. This prevents personalised content from being stored in the shared CDN cache.
- 1
Inspect the response
check whether the origin returns Vary with Cookie
- 2
Read the cache result
look for MISS in the x-vercel-cache header
- 3
Check Runtime Logs
find vary_key_denied:cookie as the cache reason
- 4
Match the headers to the content
remove Cookie for identical responses or use Cache-Control private for personalised ones
Frequently asked questions
What is Vercel’s Vary Cookie caching change?
Vercel CDN no longer stores origin responses when the Vary header includes Cookie. It still serves the response, but marks the cache result as MISS.
How can I find responses affected by Vary Cookie?
Check the x-vercel-cache response header for MISS. Runtime Logs show vary_key_denied:cookie when Cookie in the Vary header caused the response not to be cached.
Should personalised responses use Cache-Control private?
Yes. When a response depends on cookies, keep Cookie in Vary and use Cache-Control: private to stop it being stored in the shared CDN cache.
Sources
3 checkedHow we cover tool news: Create With's tool desk drafts these reports with AI from the sources listed above and checks them against those sources before publishing.







