Vercel CDN no longer caches responses with Vary: Cookie
By Steven Van ·
Routes that send Vary: Cookie will now show cache misses on Vercel, and the fix is to drop Cookie from Vary or mark personalized responses private.
Vercel's CDN no longer caches origin responses when the Vary header includes Cookie. Cookies such as session and analytics ones tend to differ for every visitor, so varying on them creates many cache entries that are rarely reused. The response is still generated and served normally, but nothing is stored for later requests.
Affected responses return x-vercel-cache: MISS, and Runtime Logs show vary_key_denied:cookie as the cache reason. Vercel does not drop the header and cache the response anyway, because that could return one visitor's content to another. This matches how Vary: * is already handled.
For a route that should be cached but now logs that reason, the fix depends on the origin's behaviour:
- If the response is the same regardless of cookies, remove Cookie from Vary. The response can then be cached, provided it meets the other caching requirements.
- If the response depends on cookies, keep Cookie in Vary and add Cache-Control: private so personalized responses are not stored in the shared CDN cache.
Caching behaviour for other supported Vary headers is unchanged.