Security · HTTP headers
Cache-Control analyzer.
Paste a Cache-Control header, optionally with Age, Date, Expires, ETag and Vary, and get each directive explained, conflicts flagged, and the freshness lifetime worked out for shared caches (CDNs) and for browsers. Everything runs in your browser; this page never fetches a URL, so nothing you paste is sent anywhere.
Headers
Breakdown
Paste a Cache-Control header and press Analyze.
How caches read Cache-Control
Freshness lifetime. RFC 9111 section 4.2.1 takes the first rule that matches: (1) for a shared cache, s-maxage; (2) max-age; (3) Expires minus Date; (4) otherwise there is no explicit expiry and a cache may apply a heuristic (section 4.2.2, which suggests a fraction such as 10% of the time since Last-Modified). A response is fresh while freshness_lifetime > current_age. This tool uses the Age you enter as the current age, so the remaining time is a best case: the real current age also includes time spent since the response arrived.
no-cache is not no-store. no-cache lets a cache keep the response but requires successful revalidation with the origin before each reuse. no-store forbids storing it at all, in any cache. private keeps it out of shared caches but lets a browser store it. Neither no-store nor private is a reliable privacy control (section 5.2.2.5, 5.2.2.7).
Extensions. stale-while-revalidate and stale-if-error (RFC 5861) allow a stale response to be served for a further number of seconds, while revalidating or when the origin errors. immutable (RFC 8246) says the content will not change during its freshness lifetime, so clients should not revalidate on reload.
Conflicts. When directives conflict, for example max-age with no-cache, the most restrictive is honored (section 4.2.1). Invalid freshness values, such as max-age=abc, should be treated as stale. Expires is ignored when max-age is present, and by shared caches when s-maxage is present (section 5.3); an invalid Expires date such as 0 means already expired. Delta-seconds above 2,147,483,648 are capped at that value (section 1.2.2).
Sources: RFC 9111: HTTP Caching; RFC 5861: HTTP Cache-Control Extensions for Stale Content; RFC 8246: HTTP Immutable Responses; see also MDN: Cache-Control for browser notes.
What this analysis does and doesn’t tell you
This tool applies the written standard to the header text you paste. Real browsers, CDNs and proxies may add their own rules, ignore some directives, override lifetimes, or key their caches differently, so test against your actual stack. Nothing is fetched, stored or transmitted: the analysis runs entirely in your browser.