[{"data":1,"prerenderedAt":1043},["ShallowReactive",2],{"content:\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fno-cache-vs-no-store-vs-max-age-0":3,"surroundings:\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fno-cache-vs-no-store-vs-max-age-0":1035},{"id":4,"title":5,"body":6,"description":1015,"extension":1016,"meta":1017,"navigation":1028,"path":1029,"seo":1030,"stem":1033,"__hash__":1034},"content\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fno-cache-vs-no-store-vs-max-age-0\u002Findex.md","no-cache vs no-store vs max-age=0",{"type":7,"value":8,"toc":998},"minimark",[9,14,34,55,225,230,290,294,303,312,329,343,456,460,465,468,472,494,497,501,537,540,544,557,681,685,697,701,714,718,740,744,789,793,804,816,822,835,839,857,875,899,915,938,947,956,960,983,988,991,994],[10,11,13],"h1",{"id":12},"no-cache-vs-no-store-vs-max-age0-what-each-directive-actually-does","no-cache vs no-store vs max-age=0: What Each Directive Actually Does",[15,16,17,18,23,24,28,29,33],"p",{},"This comparison clarifies the most misunderstood corner of ",[19,20,22],"a",{"href":21},"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002F","HTTP Cache-Control Headers Explained",", within ",[19,25,27],{"href":26},"\u002Fadvanced-caching-strategies-cdn-architecture\u002F","Advanced Caching Strategies & CDN Architecture",". The names suggest a ladder of strictness — \"no cache\", \"no store\", \"zero age\" — and many teams reach for the strongest-sounding option to be safe. That choice has real costs: ",[30,31,32],"code",{},"no-store"," disables storage entirely, so every navigation, every back button press and every repeat visit downloads the full response again, and it can make pages ineligible for the back\u002Fforward cache.",[15,35,36,37,39,40,43,44,47,48,50,51,54],{},"In practice the directives answer different questions. ",[30,38,32],{}," says \"never write this response to any cache\". ",[30,41,42],{},"no-cache"," says \"you may store it, but must check with the server before each reuse\". ",[30,45,46],{},"max-age=0"," says \"it is stale immediately\" — which, with validators present, behaves almost like ",[30,49,42],{},", and with ",[30,52,53],{},"must-revalidate"," is effectively the same. For most HTML that \"must always be fresh\", the right answer is revalidation, not refusal to store.",[15,56,57],{},[58,59,65,66,65,73,65,77,65,80,65,89,65,95,65,101,65,108,65,112,65,117,65,120,65,124,65,127,65,131,65,135,65,138,65,143,65,147,65,149,65,152,65,154,65,157,65,160,65,163,65,167,65,170,65,172,65,175,65,177,65,180,65,183,65,187,65,189,65,191,65,193,65,195,65,197,65,199,65,203,65,207,65,209,65,211,65,213,65,217,65,221,65,223,65],"svg",{"viewBox":60,"width":61,"role":62,"ariaLabel":63,"style":64},"0 0 760 244","100%","img","Comparison of no-store, no-cache and max-age=0 across storage, reuse, revalidation cost and bfcache effect.","height:auto;max-width:760px;display:block;margin:1.75rem auto;font-family:inherit;color:var(--fp-svg-ink)"," ",[67,68],"rect",{"className":69,"x":71,"y":71,"width":61,"height":61,"fill":72},[70],"svg-canvas","0","#ffffff",[74,75,76],"title",{},"The three directives side by side",[78,79,63],"desc",{},[67,81],{"x":82,"y":82,"width":83,"height":84,"rx":85,"fill":86,"stroke":87,"style":88},"1","758","242","10","none","currentColor","stroke-opacity:0.18",[90,91,76],"text",{"x":92,"y":93,"fill":87,"style":94},"28.0","34.0","font-size:16px;font-weight:700",[67,96],{"x":92,"y":97,"width":98,"height":99,"rx":71,"fill":87,"stroke":87,"style":100},"56.0","181.5","30.0","fill-opacity:0.06;stroke-opacity:0.4",[90,102,107],{"x":103,"y":104,"fill":87,"style":105,"textAnchor":106},"38.0","75.5","font-size:12.5px;font-weight:700","start","Directive",[67,109],{"x":110,"y":97,"width":111,"height":99,"rx":71,"fill":87,"stroke":87,"style":100},"209.5","174.2",[90,113,116],{"x":114,"y":104,"fill":87,"style":105,"textAnchor":115},"296.6","middle","Stored?",[67,118],{"x":119,"y":97,"width":111,"height":99,"rx":71,"fill":87,"stroke":87,"style":100},"383.6",[90,121,123],{"x":122,"y":104,"fill":87,"style":105,"textAnchor":115},"470.7","Reused without asking?",[67,125],{"x":126,"y":97,"width":111,"height":99,"rx":71,"fill":87,"stroke":87,"style":100},"557.8",[90,128,130],{"x":129,"y":104,"fill":87,"style":105,"textAnchor":115},"644.9","Repeat-visit cost",[67,132],{"x":92,"y":133,"width":98,"height":99,"rx":71,"fill":86,"stroke":87,"style":134},"86.0","stroke-opacity:0.35",[90,136,32],{"x":103,"y":137,"fill":87,"style":105,"textAnchor":106},"105.5",[67,139],{"x":110,"y":133,"width":111,"height":99,"rx":71,"fill":140,"stroke":141,"style":142},"#ffc300","#b8860b","fill-opacity:0.24;stroke-opacity:0.9",[90,144,146],{"x":114,"y":137,"fill":87,"style":145,"textAnchor":115},"font-size:12px","never",[67,148],{"x":119,"y":133,"width":111,"height":99,"rx":71,"fill":140,"stroke":141,"style":142},[90,150,151],{"x":122,"y":137,"fill":87,"style":145,"textAnchor":115},"no",[67,153],{"x":126,"y":133,"width":111,"height":99,"rx":71,"fill":140,"stroke":141,"style":142},[90,155,156],{"x":129,"y":137,"fill":87,"style":145,"textAnchor":115},"full download",[67,158],{"x":92,"y":159,"width":98,"height":99,"rx":71,"fill":86,"stroke":87,"style":134},"116.0",[90,161,42],{"x":103,"y":162,"fill":87,"style":105,"textAnchor":106},"135.5",[67,164],{"x":110,"y":159,"width":111,"height":99,"rx":71,"fill":165,"stroke":165,"style":166},"#0466c8","fill-opacity:0.14;stroke-opacity:0.9",[90,168,169],{"x":114,"y":162,"fill":87,"style":145,"textAnchor":115},"yes",[67,171],{"x":119,"y":159,"width":111,"height":99,"rx":71,"fill":140,"stroke":141,"style":142},[90,173,174],{"x":122,"y":162,"fill":87,"style":145,"textAnchor":115},"no — revalidate first",[67,176],{"x":126,"y":159,"width":111,"height":99,"rx":71,"fill":165,"stroke":165,"style":166},[90,178,179],{"x":129,"y":162,"fill":87,"style":145,"textAnchor":115},"304 if unchanged",[67,181],{"x":92,"y":182,"width":98,"height":99,"rx":71,"fill":86,"stroke":87,"style":134},"146.0",[90,184,186],{"x":103,"y":185,"fill":87,"style":105,"textAnchor":106},"165.5","max-age=0, must-revalidate",[67,188],{"x":110,"y":182,"width":111,"height":99,"rx":71,"fill":165,"stroke":165,"style":166},[90,190,169],{"x":114,"y":185,"fill":87,"style":145,"textAnchor":115},[67,192],{"x":119,"y":182,"width":111,"height":99,"rx":71,"fill":140,"stroke":141,"style":142},[90,194,174],{"x":122,"y":185,"fill":87,"style":145,"textAnchor":115},[67,196],{"x":126,"y":182,"width":111,"height":99,"rx":71,"fill":165,"stroke":165,"style":166},[90,198,179],{"x":129,"y":185,"fill":87,"style":145,"textAnchor":115},[67,200],{"x":92,"y":201,"width":98,"height":202,"rx":71,"fill":86,"stroke":87,"style":134},"176.0","46.0",[90,204,206],{"x":103,"y":205,"fill":87,"style":105,"textAnchor":106},"203.5","max-age=0 (alone)",[67,208],{"x":110,"y":201,"width":111,"height":202,"rx":71,"fill":165,"stroke":165,"style":166},[90,210,169],{"x":114,"y":205,"fill":87,"style":145,"textAnchor":115},[67,212],{"x":119,"y":201,"width":111,"height":202,"rx":71,"fill":87,"stroke":87,"style":100},[90,214,216],{"x":122,"y":215,"fill":87,"style":145,"textAnchor":115},"195.5","may serve stale if origin",[90,218,220],{"x":122,"y":219,"fill":87,"style":145,"textAnchor":115},"211.5","unreachable",[67,222],{"x":126,"y":201,"width":111,"height":202,"rx":71,"fill":165,"stroke":165,"style":166},[90,224,179],{"x":129,"y":205,"fill":87,"style":145,"textAnchor":115},[226,227,229],"h2",{"id":228},"rapid-diagnosis","Rapid Diagnosis",[231,232,233,256,265,281],"ul",{},[234,235,236,65,240,243,244,247,248,251,252,255],"li",{},[237,238,239],"strong",{},"Inventory headers by content type.",[30,241,242],{},"curl -sI"," key HTML, API and asset URLs; record ",[30,245,246],{},"Cache-Control",", ",[30,249,250],{},"ETag"," and ",[30,253,254],{},"Last-Modified",".",[234,257,258,264],{},[237,259,260,261,263],{},"Look for ",[30,262,32],{}," on public content."," It is often set globally by frameworks or security middleware.",[234,266,267,65,270,251,272,274,275,277,278,280],{},[237,268,269],{},"Check for validators.",[30,271,42],{},[30,273,46],{}," only produce cheap 304 responses if ",[30,276,250],{}," or ",[30,279,254],{}," is present.",[234,282,283,286,287,289],{},[237,284,285],{},"Check repeat-visit transfer sizes."," In DevTools, a reload should show small transfers (304) for revalidated resources; full sizes indicate ",[30,288,32],{}," or missing validators.",[226,291,293],{"id":292},"root-cause-analysis","Root Cause Analysis",[15,295,296,299,300,302],{},[237,297,298],{},"1. Name-based assumptions."," \"no-cache\" sounds like it prevents caching; it actually requires revalidation. Teams then add ",[30,301,32],{}," to \"really\" prevent caching.",[15,304,305,308,309,311],{},[237,306,307],{},"2. Security checklists applied globally."," Guidance to use ",[30,310,32],{}," for sensitive pages gets applied to every response.",[15,313,314,317,318,320,321,323,324,326,327,255],{},[237,315,316],{},"3. Missing validators."," Without ",[30,319,250],{},"\u002F",[30,322,254],{},", revalidation degrades to a full download, making ",[30,325,42],{}," look no better than ",[30,328,32],{},[15,330,331,65,334,336,337,340,341,255],{},[237,332,333],{},"4. Confusion between browser and CDN behaviour.",[30,335,42],{}," applies to all caches; teams wanting \"CDN may cache, browser must revalidate\" need ",[30,338,339],{},"s-maxage"," with ",[30,342,46],{},[15,344,345],{},[58,346,65,349,65,352,65,355,65,357,65,374,65,377,65,379,65,384,65,390,65,393,65,397,65,400,65,404,65,412,65,415,65,418,65,424,65,429,65,433,65,438,65,443,65,447,65,452,65],{"viewBox":347,"width":61,"role":62,"ariaLabel":348,"style":64},"0 0 760 290","Sequence of a browser revalidating a stored response with If-None-Match and receiving a 304 Not Modified.",[67,350],{"className":351,"x":71,"y":71,"width":61,"height":61,"fill":72},[70],[74,353,354],{},"Repeat visit with no-cache and an ETag",[78,356,348],{},[358,359,360],"defs",{},[361,362,369],"marker",{"id":363,"viewBox":364,"refX":365,"refY":366,"markerWidth":367,"markerHeight":367,"orient":368},"fadbfbdab5","0 0 10 10","9","5","7","auto-start-reverse",[370,371],"path",{"d":372,"fill":87,"style":373},"M0 0 L10 5 L0 10 z","fill-opacity:0.7",[67,375],{"x":82,"y":82,"width":83,"height":376,"rx":85,"fill":86,"stroke":87,"style":88},"288",[90,378,354],{"x":92,"y":93,"fill":87,"style":94},[67,380],{"x":381,"y":97,"width":382,"height":93,"rx":383,"fill":87,"stroke":87,"style":100},"70.3","150.0","6",[90,385,389],{"x":386,"y":387,"fill":87,"style":388,"textAnchor":115},"145.3","78.0","font-size:13px;font-weight:700","Browser cache",[67,391],{"x":392,"y":97,"width":382,"height":93,"rx":383,"fill":87,"stroke":87,"style":100},"305.0",[90,394,396],{"x":395,"y":387,"fill":87,"style":388,"textAnchor":115},"380.0","Browser",[67,398],{"x":399,"y":97,"width":382,"height":93,"rx":383,"fill":87,"stroke":87,"style":100},"539.7",[90,401,403],{"x":402,"y":387,"fill":87,"style":388,"textAnchor":115},"614.7","Server",[405,406],"line",{"x1":386,"y1":407,"x2":386,"y2":408,"stroke":87,"strokeWidth":409,"strokeDashArray":410,"style":134},"90.0","268.0","1.5",[411,411],"4",[405,413],{"x1":395,"y1":407,"x2":395,"y2":408,"stroke":87,"strokeWidth":409,"strokeDashArray":414,"style":134},[411,411],[405,416],{"x1":402,"y1":407,"x2":402,"y2":408,"stroke":87,"strokeWidth":409,"strokeDashArray":417,"style":134},[411,411],[405,419],{"x1":395,"y1":420,"x2":421,"y2":420,"stroke":87,"strokeWidth":409,"style":422,"markerEnd":423},"124.0","147.3","stroke-opacity:0.6","url(#fadbfbdab5)",[90,425,428],{"x":426,"y":427,"fill":87,"style":145,"textAnchor":115},"262.7","117.0","lookup (stored, stale)",[405,430],{"x1":395,"y1":431,"x2":432,"y2":431,"stroke":87,"strokeWidth":409,"style":422,"markerEnd":423},"164.0","612.7",[90,434,437],{"x":435,"y":436,"fill":87,"style":145,"textAnchor":115},"497.3","157.0","If-None-Match: v42",[405,439],{"x1":402,"y1":440,"x2":441,"y2":440,"stroke":87,"strokeWidth":409,"strokeDashArray":442,"style":422,"markerEnd":423},"204.0","382.0",[366,411],[90,444,446],{"x":435,"y":445,"fill":87,"style":145,"textAnchor":115},"197.0","304 Not Modified (no body)",[405,448],{"x1":386,"y1":449,"x2":450,"y2":449,"stroke":87,"strokeWidth":409,"strokeDashArray":451,"style":422,"markerEnd":423},"244.0","378.0",[366,411],[90,453,455],{"x":426,"y":454,"fill":87,"style":145,"textAnchor":115},"237.0","reuse stored body",[226,457,459],{"id":458},"step-by-step-choosing-correctly","Step-by-Step: Choosing Correctly",[461,462,464],"h3",{"id":463},"_1-reserve-no-store-for-genuinely-sensitive-responses","1. Reserve no-store for genuinely sensitive responses",[15,466,467],{},"Account statements, payment details, health records, one-time tokens. Everything else is a candidate for a weaker directive.",[461,469,471],{"id":470},"_2-use-no-cache-with-validators-for-always-fresh-html","2. Use no-cache (with validators) for \"always fresh\" HTML",[473,474,479],"pre",{"className":475,"code":476,"language":477,"meta":478,"style":478},"language-http shiki shiki-themes github-light-high-contrast github-dark-high-contrast github-light-high-contrast","Cache-Control: no-cache\nETag: \"a1b2c3\"\n","http","",[30,480,481,488],{"__ignoreMap":478},[482,483,485],"span",{"class":405,"line":484},1,[482,486,487],{},"Cache-Control: no-cache\n",[482,489,491],{"class":405,"line":490},2,[482,492,493],{},"ETag: \"a1b2c3\"\n",[15,495,496],{},"The browser stores the page and revalidates on each use; unchanged pages cost a header round trip, not a full download, and remain bfcache-eligible. (HTTP headers cannot carry comments — the trade-off: each navigation still pays one round trip to the server for revalidation.)",[461,498,500],{"id":499},"_3-separate-browser-and-cdn-policies-with-s-maxage","3. Separate browser and CDN policies with s-maxage",[473,502,506],{"className":503,"code":504,"language":505,"meta":478,"style":478},"language-nginx shiki shiki-themes github-light-high-contrast github-dark-high-contrast github-light-high-contrast","add_header Cache-Control \"public, max-age=0, s-maxage=600, stale-while-revalidate=60\";\n# trade-off: browsers revalidate on every use while the CDN serves its copy for\n# ten minutes. Content changes need a CDN purge to appear within that window.\n","nginx",[30,507,508,525,531],{"__ignoreMap":478},[482,509,510,514,518,522],{"class":405,"line":484},[482,511,513],{"class":512},"sPARh","add_header ",[482,515,517],{"class":516},"saISM","Cache-Control ",[482,519,521],{"class":520},"sZ8jY","\"public, max-age=0, s-maxage=600, stale-while-revalidate=60\"",[482,523,524],{"class":516},";\n",[482,526,527],{"class":405,"line":490},[482,528,530],{"class":529},"sjfSM","# trade-off: browsers revalidate on every use while the CDN serves its copy for\n",[482,532,534],{"class":405,"line":533},3,[482,535,536],{"class":529},"# ten minutes. Content changes need a CDN purge to appear within that window.\n",[15,538,539],{},"Expected outcome: browsers always check freshness — against the nearby CDN, cheaply — and the origin is shielded.",[461,541,543],{"id":542},"_4-add-validators-everywhere-you-revalidate","4. Add validators everywhere you revalidate",[15,545,546,547,277,549,551,552,556],{},"Make sure the origin (or CDN) emits a stable ",[30,548,250],{},[30,550,254],{}," for HTML and API responses, so revalidation returns 304s. ",[19,553,555],{"href":554},"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fetag-vs-last-modified-validators\u002F","ETag vs Last-Modified validators"," covers the details.",[15,558,559],{},[58,560,65,563,65,566,65,569,65,571,65,578,65,581,65,583,65,587,65,591,65,594,65,598,65,604,65,608,65,612,65,617,65,621,65,625,65,629,65,631,65,635,65,638,65,641,65,643,65,647,65,650,65,653,65,656,65,658,65,661,65,664,65,667,65,671,65,674,65,677,65],{"viewBox":561,"width":61,"role":62,"ariaLabel":562,"style":64},"0 0 760 342","Decision sequence for choosing between no-store, no-cache and max-age-based policies.",[67,564],{"className":565,"x":71,"y":71,"width":61,"height":61,"fill":72},[70],[74,567,568],{},"Which directive for this response?",[78,570,562],{},[358,572,573],{},[361,574,576],{"id":575,"viewBox":364,"refX":365,"refY":366,"markerWidth":367,"markerHeight":367,"orient":368},"fabc22a7a4",[370,577],{"d":372,"fill":87,"style":373},[67,579],{"x":82,"y":82,"width":83,"height":580,"rx":85,"fill":86,"stroke":87,"style":88},"340",[90,582,568],{"x":92,"y":93,"fill":87,"style":94},[67,584],{"x":92,"y":97,"width":585,"height":586,"rx":383,"fill":87,"stroke":87,"style":100},"320.0","35.0",[90,588,590],{"x":589,"y":387,"fill":87,"style":388,"textAnchor":115},"188.0","Must never be written to disk (sensitive)?",[67,592],{"x":593,"y":97,"width":585,"height":586,"rx":383,"fill":165,"stroke":165,"style":166},"412.0",[90,595,32],{"x":596,"y":387,"fill":87,"style":597,"textAnchor":115},"572.0","font-size:12.5px",[405,599],{"x1":600,"y1":601,"x2":602,"y2":601,"stroke":87,"strokeWidth":409,"style":422,"markerEnd":603},"348.0","73.5","410.0","url(#fabc22a7a4)",[90,605,169],{"x":395,"y":606,"fill":165,"style":607,"textAnchor":115},"66.5","font-size:11.5px;font-weight:700",[405,609],{"x1":589,"y1":610,"x2":589,"y2":611,"stroke":87,"strokeWidth":409,"style":422,"markerEnd":603},"91.0","125.0",[90,613,151],{"x":614,"y":615,"fill":616,"style":607},"196.0","113.0","#51617a",[67,618],{"x":92,"y":619,"width":585,"height":620,"rx":383,"fill":87,"stroke":87,"style":100},"127.0","52.0",[90,622,624],{"x":589,"y":623,"fill":87,"style":388,"textAnchor":115},"149.0","Must be checked with the server before",[90,626,628],{"x":589,"y":627,"fill":87,"style":388,"textAnchor":115},"166.0","every use?",[67,630],{"x":593,"y":619,"width":585,"height":620,"rx":383,"fill":165,"stroke":165,"style":166},[90,632,634],{"x":596,"y":633,"fill":87,"style":597,"textAnchor":115},"149.5","no-cache + ETag (or max-age=0 + s-maxage for",[90,636,637],{"x":596,"y":185,"fill":87,"style":597,"textAnchor":115},"CDN)",[405,639],{"x1":600,"y1":640,"x2":602,"y2":640,"stroke":87,"strokeWidth":409,"style":422,"markerEnd":603},"153.0",[90,642,169],{"x":395,"y":182,"fill":165,"style":607,"textAnchor":115},[405,644],{"x1":589,"y1":645,"x2":589,"y2":646,"stroke":87,"strokeWidth":409,"style":422,"markerEnd":603},"179.0","213.0",[90,648,151],{"x":614,"y":649,"fill":616,"style":607},"201.0",[67,651],{"x":92,"y":652,"width":585,"height":586,"rx":383,"fill":87,"stroke":87,"style":100},"215.0",[90,654,655],{"x":589,"y":454,"fill":87,"style":388,"textAnchor":115},"Content-hashed asset?",[67,657],{"x":593,"y":652,"width":585,"height":586,"rx":383,"fill":165,"stroke":165,"style":166},[90,659,660],{"x":596,"y":454,"fill":87,"style":597,"textAnchor":115},"max-age=31536000, immutable",[405,662],{"x1":600,"y1":663,"x2":602,"y2":663,"stroke":87,"strokeWidth":409,"style":422,"markerEnd":603},"232.5",[90,665,169],{"x":395,"y":666,"fill":165,"style":607,"textAnchor":115},"225.5",[405,668],{"x1":589,"y1":669,"x2":589,"y2":670,"stroke":87,"strokeWidth":409,"style":422,"markerEnd":603},"250.0","284.0",[90,672,151],{"x":614,"y":673,"fill":616,"style":607},"272.0",[67,675],{"x":92,"y":676,"width":585,"height":93,"rx":383,"fill":140,"stroke":141,"style":142},"286.0",[90,678,680],{"x":589,"y":679,"fill":87,"style":597,"textAnchor":115},"307.5","Short max-age with stale-while-revalidate",[226,682,684],{"id":683},"verification","Verification",[15,686,687,688,690,691,693,694,696],{},"Reload pages with DevTools open (without \"Disable cache\"): HTML using ",[30,689,42],{}," should show 304s with tiny transfer sizes when unchanged; ",[30,692,32],{}," responses will show full sizes. Run the bfcache test on pages you moved off ",[30,695,32],{},". In RUM, compare repeat-visit TTFB and transfer sizes before and after.",[226,698,700],{"id":699},"worked-example-a-global-no-store-removed","Worked Example: A Global no-store Removed",[15,702,703,704,707,708,710,711,713],{},"A web app's security middleware set ",[30,705,706],{},"Cache-Control: no-store"," on every response, including public marketing pages, CSS and JavaScript (served from the app server rather than a CDN). Repeat visits downloaded 1.1MB each time, LCP for returning visitors was barely better than for new ones, and back navigations always reloaded. The team scoped ",[30,709,32],{}," to authenticated account routes, set ",[30,712,42],{}," with ETags on public HTML, and long-lived immutable caching on hashed assets. Returning-visitor LCP p75 improved by 900ms, repeat-visit transfer fell by 85%, and the bfcache restoration rate on public pages rose from near zero to over 70%.",[226,715,717],{"id":716},"choosing-between-no-cache-and-a-short-max-age","Choosing Between no-cache and a Short max-age",[15,719,720,722,723,726,727,730,731,734,735,737,738,255],{},[30,721,42],{}," guarantees a freshness check on every use, which costs a round trip even when nothing changed. A short ",[30,724,725],{},"max-age"," (say 60 seconds) lets the browser reuse the response without asking for that period, saving the round trip on quick repeat navigations at the cost of up to a minute of staleness. For HTML that changes rarely and where a minute of staleness is harmless — articles, documentation, product pages with CDN purging — ",[30,728,729],{},"max-age=60"," plus ",[30,732,733],{},"stale-while-revalidate"," often gives a faster experience than ",[30,736,42],{},". For HTML that reflects rapidly changing state, or where a stale page would be harmful (a ticket checkout), keep ",[30,739,42],{},[226,741,743],{"id":742},"common-mistakes","Common Mistakes",[231,745,746,760,769,777],{},[234,747,748,65,754,756,757,759],{},[237,749,750,753],{},[30,751,752],{},"no-cache, no-store"," together.",[30,755,32],{}," dominates; ",[30,758,42],{}," adds nothing.",[234,761,762,768],{},[237,763,764,765,255],{},"Relying on ",[30,766,767],{},"Pragma: no-cache"," It is an HTTP\u002F1.0 request header with no defined meaning on responses.",[234,770,771,776],{},[237,772,773,775],{},[30,774,42],{}," without validators."," Revalidation then downloads the full body every time.",[234,778,779,785,786,788],{},[237,780,781,782,784],{},"Using ",[30,783,46],{}," and expecting CDNs to cache."," Use ",[30,787,339],{}," for shared caches.",[226,790,792],{"id":791},"edge-cases","Edge Cases",[15,794,795,799,800,803],{},[237,796,797,255],{},[30,798,53],{}," Prevents serving stale content when the origin is unreachable. Combine with ",[30,801,802],{},"stale-if-error"," deliberately if you want resilience.",[15,805,806,811,812,815],{},[237,807,808,255],{},[30,809,810],{},"private"," Orthogonal to these three: it restricts storage to the browser. ",[30,813,814],{},"private, no-cache"," is a common, sensible policy for personalised HTML.",[15,817,818,821],{},[237,819,820],{},"Service workers."," They can implement their own caching regardless of headers; headers still govern the HTTP cache and CDNs.",[15,823,824,827,828,830,831,255],{},[237,825,826],{},"Heuristic caching."," Responses with no ",[30,829,246],{}," at all may be cached heuristically — see ",[19,832,834],{"href":833},"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fheuristic-freshness-when-cache-control-is-missing\u002F","heuristic freshness when Cache-Control is missing",[226,836,838],{"id":837},"faq","FAQ",[840,841,844,848],"details",{"className":842},[843],"faq-item",[845,846,847],"summary",{},"Is no-cache safe for sensitive pages?",[15,849,850,851,853,854,856],{},"It allows the response to be stored on disk, which may be unacceptable for highly sensitive data on shared devices. For those pages use ",[30,852,32],{},"; for ordinary personalised pages, ",[30,855,814],{}," is usually appropriate.",[840,858,860,863],{"className":859},[843],[845,861,862],{},"Does max-age=0 behave exactly like no-cache?",[15,864,865,866,868,869,871,872,874],{},"Almost. Both require revalidation before reuse in normal operation. Without ",[30,867,53],{},", caches may serve a ",[30,870,46],{}," response stale in some situations (for example, when the origin is unreachable); ",[30,873,42],{}," forbids reuse without successful validation.",[840,876,878,881],{"className":877},[843],[845,879,880],{},"Which directive do CDNs respect?",[15,882,883,884,251,886,888,889,891,892,894,895,898],{},"Most respect ",[30,885,32],{},[30,887,810],{}," by not caching, treat ",[30,890,42],{}," as \"revalidate\", and use ",[30,893,339],{}," (or vendor headers such as ",[30,896,897],{},"CDN-Cache-Control",") for their own TTLs. Check your CDN's documentation for HTML defaults.",[840,900,902,905],{"className":901},[843],[845,903,904],{},"Does no-store affect the back\u002Fforward cache?",[15,906,907,908,910,911,255],{},"Historically, yes — pages served with ",[30,909,32],{}," were not stored in bfcache. See ",[19,912,914],{"href":913},"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fback-forward-cache-bfcache\u002Fcache-control-no-store-and-bfcache\u002F","Cache-Control no-store and bfcache",[840,916,918,921],{"className":917},[843],[845,919,920],{},"What should API responses use?",[15,922,923,924,926,927,929,930,932,933,277,935,937],{},"Public APIs: ",[30,925,46],{}," or short ",[30,928,725],{}," for browsers with ",[30,931,339],{}," for CDNs. Personal APIs: ",[30,934,814],{},[30,936,32],{}," depending on sensitivity.",[840,939,941,944],{"className":940},[843],[845,942,943],{},"How do I change a global no-store safely?",[15,945,946],{},"Change it per route class rather than globally in one step. Start with static assets (which should be immutable anyway), then public HTML, and leave authenticated routes until the security review is done. Each step is independently verifiable with curl and DevTools, and each delivers its own improvement.",[840,948,950,953],{"className":949},[843],[845,951,952],{},"Do these directives apply to service worker caches?",[15,954,955],{},"No. The Cache Storage API used by service workers ignores HTTP caching directives; your service worker code decides what to store. Headers still govern the browser's HTTP cache, which the service worker's own fetches go through.",[226,957,959],{"id":958},"related","Related",[231,961,962,969,976],{},[234,963,964,968],{},[19,965,967],{"href":966},"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fcache-control-for-html-documents\u002F","Cache-Control for HTML documents"," — complete HTML policies.",[234,970,971,975],{},[19,972,974],{"href":973},"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fsetting-up-immutable-cache-headers-for-hashed-assets\u002F","Setting up immutable cache headers for hashed assets"," — the opposite end of the spectrum.",[234,977,978,982],{},[19,979,981],{"href":980},"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fstale-while-revalidate-implementation\u002Fchoosing-swr-windows-for-html-and-apis\u002F","Choosing SWR windows for HTML and APIs"," — adding staleness tolerance on purpose.",[984,985,987],"script",{"type":986},"application\u002Fld+json","\n{\n  \"@context\": \"https:\u002F\u002Fschema.org\",\n  \"@type\": \"HowTo\",\n  \"name\": \"no-cache vs no-store vs max-age=0: What Each Directive Actually Does\",\n  \"description\": \"A precise comparison of no-cache, no-store and max-age=0, with the performance consequences of choosing the wrong one.\",\n  \"step\": [\n    {\n      \"@type\": \"HowToStep\",\n      \"position\": 1,\n      \"name\": \"Reserve no-store for genuinely sensitive responses\",\n      \"text\": \"Account statements, payment details, health records, one-time tokens.\"\n    },\n    {\n      \"@type\": \"HowToStep\",\n      \"position\": 2,\n      \"name\": \"Use no-cache (with validators) for \\\"always fresh\\\" HTML\",\n      \"text\": \"The browser stores the page and revalidates on each use; unchanged pages cost a header round trip, not a full download, and remain bfcache-eligible.\"\n    },\n    {\n      \"@type\": \"HowToStep\",\n      \"position\": 3,\n      \"name\": \"Separate browser and CDN policies with s-maxage\",\n      \"text\": \"Expected outcome: browsers always check freshness — against the nearby CDN, cheaply — and the origin is shielded.\"\n    },\n    {\n      \"@type\": \"HowToStep\",\n      \"position\": 4,\n      \"name\": \"Add validators everywhere you revalidate\",\n      \"text\": \"Make sure the origin (or CDN) emits a stable ETag or Last-Modified for HTML and API responses, so revalidation returns 304s.\"\n    }\n  ]\n}\n",[984,989,990],{"type":986},"\n{\n  \"@context\": \"https:\u002F\u002Fschema.org\",\n  \"@type\": \"TechArticle\",\n  \"headline\": \"no-cache vs no-store vs max-age=0: What Each Directive Actually Does\",\n  \"description\": \"A precise comparison of no-cache, no-store and max-age=0, with the performance consequences of choosing the wrong one.\",\n  \"datePublished\": \"2026-10-06\",\n  \"dateModified\": \"2026-10-06\",\n  \"author\": {\n    \"@type\": \"Organization\",\n    \"name\": \"frontend-performance.com\"\n  },\n  \"publisher\": {\n    \"@type\": \"Organization\",\n    \"name\": \"frontend-performance.com\"\n  },\n  \"mainEntityOfPage\": {\n    \"@type\": \"WebPage\",\n    \"@id\": \"https:\u002F\u002Ffrontend-performance.com\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fno-cache-vs-no-store-vs-max-age-0\u002F\"\n  }\n}\n",[984,992,993],{"type":986},"\n{\n  \"@context\": \"https:\u002F\u002Fschema.org\",\n  \"@type\": \"BreadcrumbList\",\n  \"itemListElement\": [\n    {\n      \"@type\": \"ListItem\",\n      \"position\": 1,\n      \"name\": \"Home\",\n      \"item\": \"https:\u002F\u002Ffrontend-performance.com\u002F\"\n    },\n    {\n      \"@type\": \"ListItem\",\n      \"position\": 2,\n      \"name\": \"Advanced Caching Strategies & CDN Architecture\",\n      \"item\": \"https:\u002F\u002Ffrontend-performance.com\u002Fadvanced-caching-strategies-cdn-architecture\u002F\"\n    },\n    {\n      \"@type\": \"ListItem\",\n      \"position\": 3,\n      \"name\": \"HTTP Cache-Control Headers Explained\",\n      \"item\": \"https:\u002F\u002Ffrontend-performance.com\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002F\"\n    },\n    {\n      \"@type\": \"ListItem\",\n      \"position\": 4,\n      \"name\": \"no-cache vs no-store vs max-age=0\",\n      \"item\": \"https:\u002F\u002Ffrontend-performance.com\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fno-cache-vs-no-store-vs-max-age-0\u002F\"\n    }\n  ]\n}\n",[995,996,997],"style",{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html pre.shiki code .sPARh, html code.shiki .sPARh{--shiki-default:#A0111F;--shiki-dark:#FF9492;--shiki-light:#A0111F}html pre.shiki code .saISM, html code.shiki .saISM{--shiki-default:#0E1116;--shiki-dark:#F0F3F6;--shiki-light:#0E1116}html pre.shiki code .sZ8jY, html code.shiki .sZ8jY{--shiki-default:#032563;--shiki-dark:#ADDCFF;--shiki-light:#032563}html pre.shiki code .sjfSM, html code.shiki .sjfSM{--shiki-default:#66707B;--shiki-dark:#BDC4CC;--shiki-light:#66707B}",{"title":478,"searchDepth":490,"depth":490,"links":999},[1000,1001,1002,1008,1009,1010,1011,1012,1013,1014],{"id":228,"depth":490,"text":229},{"id":292,"depth":490,"text":293},{"id":458,"depth":490,"text":459,"children":1003},[1004,1005,1006,1007],{"id":463,"depth":533,"text":464},{"id":470,"depth":533,"text":471},{"id":499,"depth":533,"text":500},{"id":542,"depth":533,"text":543},{"id":683,"depth":490,"text":684},{"id":699,"depth":490,"text":700},{"id":716,"depth":490,"text":717},{"id":742,"depth":490,"text":743},{"id":791,"depth":490,"text":792},{"id":837,"depth":490,"text":838},{"id":958,"depth":490,"text":959},"A precise comparison of no-cache, no-store and max-age=0, with the performance consequences of choosing the wrong one.","md",{"slug":1018,"type":1019,"breadcrumb":1020,"datePublished":1027,"dateModified":1027},"no-cache-vs-no-store-vs-max-age-0","article",[1021,1023,1024,1025],{"name":1022,"url":320},"Home",{"name":27,"url":26},{"name":22,"url":21},{"name":5,"url":1026},"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fno-cache-vs-no-store-vs-max-age-0\u002F","2026-10-06",true,"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fno-cache-vs-no-store-vs-max-age-0",{"title":1031,"description":1032},"no-cache vs no-store vs max-age=0: What Each Does","The three most confused Cache-Control directives compared: what is stored, when revalidation happens, effects on CDNs, bfcache and performance, and which to use.","advanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fno-cache-vs-no-store-vs-max-age-0\u002Findex","3MVeXJFr7O6P0AaCWaW7RKuCjN9EAIVWvR_ov_K1dYc",[1036,1040],{"title":1037,"path":1038,"stem":1039},"Heuristic Freshness When Cache-Control Is Missing","\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fheuristic-freshness-when-cache-control-is-missing","advanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fheuristic-freshness-when-cache-control-is-missing\u002Findex",{"title":974,"path":1041,"stem":1042},"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fsetting-up-immutable-cache-headers-for-hashed-assets","advanced-caching-strategies-cdn-architecture\u002Fhttp-cache-control-headers-explained\u002Fsetting-up-immutable-cache-headers-for-hashed-assets\u002Findex",1791308074899]