Website Tools

Cache-Control Header Generator

Decide how long browsers and CDNs may keep your files, and get a Cache-Control header with an explanation in plain words of what each cache will do. Presets cover versioned assets, HTML pages, CDN-cached pages, images, personal data and sensitive responses, and the output can be limited to chosen file types.

  • Runs in your browser
  • No sign-up
  • Free to use
Start from
s
s

Leave empty to apply to every response.

How to use Cache-Control Header Generator

  1. Pick a preset for the kind of content.
  2. Adjust who may store it and for how long.
  3. Optionally list file extensions the rule applies to.
  4. Copy the configuration for your server and check the explanation below it.

Cache-Control Header Generator features

All common directives

public, private, no-store, no-cache, max-age, s-maxage, must-revalidate, immutable, stale-while-revalidate, stale-if-error.

Plain explanation

What the browser and the CDN will do with the response.

Conflict checks

Warns when settings cancel each other or are risky.

Per file type

FilesMatch, nginx location or headers-file patterns for chosen extensions.

Unit conversion

Enter minutes, hours or days; the header uses seconds.

Many outputs

Apache, Nginx, IIS, Netlify, Vercel, Cloudflare, Express and PHP.

When to use Cache-Control Header Generator

  • Fixing “serve static assets with an efficient cache policy” in PageSpeed reports.
  • Making sure HTML updates reach visitors immediately.
  • Letting a CDN cache pages for a few minutes with background refresh.
  • Preventing account pages or downloads with personal data from being cached.

Cache-Control Header Generator FAQ

What is the difference between no-cache and no-store?

no-cache allows storing but requires checking with the server before each use, which is cheap when nothing changed. no-store forbids keeping any copy at all and is meant for sensitive data.

How long should static files be cached?

Files whose names contain a version or content hash, such as app.3f9a2c.js, can be cached for a year with immutable. Files whose names stay the same when they change should get a short lifetime or no-cache.

What does s-maxage do?

It sets the lifetime for shared caches such as CDNs and proxies only, overriding max-age for them. Browsers ignore it.

What is stale-while-revalidate?

After the response expires, a cache may keep serving it for the given number of seconds while it fetches a fresh copy in the background, so visitors do not wait.

Should HTML pages be cached?

Usually with no-cache, so browsers always check for a new version but can reuse the copy when nothing changed. Pages behind a CDN can also get a short s-maxage.

Do I still need the Expires header?

No. Cache-Control max-age takes precedence over Expires in every current browser and cache.

How HTTP caching decides

Every response can be stored by the browser and by shared caches between the server and the user, such as a CDN or a company proxy. The Cache-Control header tells them whether they may store it, for how long it stays fresh, and what to do when it is no longer fresh. A fresh response is used without contacting the server at all, which is what makes repeat visits fast.

max-age gives the lifetime in seconds for every cache, while s-maxage overrides it for shared caches only. When a stored response becomes stale, the cache revalidates it: it asks the server whether the resource changed, using the ETag or Last-Modified value it kept. If nothing changed, the server answers 304 Not Modified without a body, so even revalidation saves most of the transfer.

Who may store the response is the next question. private limits storage to the user’s own browser, which is right for anything personal. public explicitly allows shared caches, including for requests that carried an Authorization header. no-store forbids storage everywhere and suits banking pages, one-time tokens and downloads of sensitive documents.

The best strategy for static assets is to put a version or content hash into each file name and cache those files for a year with immutable. When a file changes, its name changes, so the HTML points to the new file and old copies simply stop being used. HTML itself keeps a stable address, so it usually gets no-cache or a short lifetime with stale-while-revalidate.

Caching rules are only as good as the deployment process behind them. A long lifetime on a file without a version in its name means visitors may run old code for weeks. Before choosing long lifetimes, check how your build tool names files, and test the result in the browser’s developer tools, where the Size column shows “disk cache” or “memory cache” for responses served from cache.

Other useful tools