# HTTP Caching

URL: https://softwaredictionary.org/terms/http-caching
Category: Backend & APIs
Last updated: 2026-09-30
In Turkish: HTTP önbellekleme

In short: HTTP caching is the reuse of stored HTTP responses by browsers, CDNs and proxies, controlled by headers like Cache-Control and ETag, to avoid repeat downloads.

## What is HTTP caching?

HTTP caching lets a browser, a CDN, or a proxy keep a copy of a response and reuse it for later requests instead of fetching it from the origin server again. A file served from the browser's own cache loads almost instantly and uses no network at all. The server decides what may be cached, by whom, and for how long, using HTTP response headers.

The main header is `Cache-Control`. `max-age=3600` means the response stays fresh for an hour; `public` lets shared caches such as CDNs store it, while `private` limits it to the user's own browser; `no-cache` means a stored copy must be revalidated with the server before each use; and `no-store` forbids storing it at all, which is right for sensitive data. When a stored copy goes stale, the client revalidates it with a conditional request, sending the `ETag` it has in an `If-None-Match` header, or a date in `If-Modified-Since`. If nothing has changed, the server replies `304 Not Modified` with no body, saving bandwidth.

HTTP caching works like keeping a printed timetable at home: you check your own copy instead of calling the station every time, and when it might be out of date, you ask 'has anything changed since this version?' rather than requesting a whole new one. A standard strategy for static assets is cache busting: put a hash of the content in the file name, like `app.3f9a1c.js`, and cache it for a year with `immutable`, because any change produces a new file name. HTML pages, by contrast, are usually revalidated so users see new versions quickly.

Two confusions are common. Despite its name, `no-cache` does allow caching; it only requires a check with the server before reuse, while `no-store` is the directive that truly prevents storage. HTTP caching also differs from an application cache such as Redis on the server: HTTP caching stores whole responses in clients and intermediaries based on headers, while an application cache stores data inside your backend, such as query results, under your code's control.

## Key takeaways

- `Cache-Control` tells browsers and CDNs whether, and for how long, they may reuse a response.
- `ETag` and `Last-Modified` let clients revalidate with a cheap `304 Not Modified` response.
- `no-cache` means revalidate before every use; `no-store` means never store.
- Hashed file names with a long `max-age` and `immutable` are the standard for static assets.
- `private` keeps personalized responses out of shared caches such as CDNs.

## Example: Caching headers for static files and HTML pages

```http
# Response headers for a hashed static file: cache it for a year
HTTP/1.1 200 OK
Cache-Control: public, max-age=31536000, immutable

# Response headers for an HTML page: keep it, but revalidate before reuse
HTTP/1.1 200 OK
Cache-Control: no-cache
ETag: "v42"

# Later, the browser asks whether its stored copy is still current
GET /index.html HTTP/1.1
If-None-Match: "v42"

# Nothing changed, so the server sends no body
HTTP/1.1 304 Not Modified
```

## Frequently asked questions

**What is the difference between no-cache and no-store?**

`no-cache` allows the response to be stored but requires the cache to check with the server before each reuse. `no-store` forbids storing the response anywhere, which is the right setting for sensitive data such as banking pages.

**How do I make browsers load a new version of a cached file?**

Change the file's URL, usually by putting a content hash in its name, which bundlers do automatically. You can't reliably reach into every visitor's cache, which is why long-cached files should never change under the same URL.

**What is an ETag?**

An ETag is an identifier for a specific version of a resource, often a hash of its content, sent in the `ETag` response header. Clients send it back in `If-None-Match`, and the server answers `304 Not Modified` if the version is still current.

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
