HTTP Cache-Control Builder & Inspector
Draft response cache policies or inspect an existing Cache-Control value, with browser/shared TTLs, validation rules, immutable content, stale windows and conflict notes.
Settings
Try the example or enter your own settings.
Generated policies are drafts. Public/shared caching can expose personalized content, and no-store does not erase existing copies or guarantee privacy. Test with your real status codes, authorization, Vary keys, validators and CDN behavior. This tool does not modify ToolSorcerer’s cache policy.
Using HTTP Cache-Control Builder & Inspector
Draft response cache policies or inspect an existing Cache-Control value, with browser/shared TTLs, validation rules, immutable content, stale windows and conflict notes.
- Choose build mode for a response policy or inspect mode to paste a Cache-Control header.
- Set storage scope, browser/shared freshness, validation and optional stale windows. For no-store, other build settings are ignored.
- Generate, read each directive and review conflicts. Copy/export the header or JSON report, then test in your own staging environment.
Example
Try the included editable example. Set storage scope, browser/shared freshness, validation and optional stale windows. For no-store, other build settings are ignored.
Questions & answers
Does no-cache mean no storage?
No. It allows storage but requires successful validation before reuse. no-store tells caches not to store the response; neither directive alone certifies privacy or erases previous copies.
How do max-age and s-maxage differ?
max-age defines a freshness lifetime using response age. s-maxage sets the shared-cache lifetime and overrides max-age there; private browser caches ignore s-maxage.
When should I use immutable?
For representations that will not change during their freshness lifetime, commonly files with versioned URLs. Review how updates are published before enabling it.
Are stale directives always honored?
No. Support and error handling vary, and explicit validation requirements can prohibit stale reuse. The tool flags combinations that need review rather than promising a particular CDN behavior.
Which inspection syntax is supported?
Up to 30 comma-separated bare directives or simple token/numeric arguments. Numeric TTLs may be quoted. Qualified no-cache/private field-name lists and complex extensions are outside the supported subset. This is not a complete HTTP cache validator.
What limits apply?
Existing header input is capped at 8,000 characters. Duration fields support integers from 0 to 2,147,483,647 seconds. Duplicate directives are rejected. No-store build mode ignores freshness/validation fields.
Help improve this tool
Report a problem or suggest an improvement
Describe the issue without pasting private tool input. Feedback goes to our admin inbox.
