← All headersResponse header

What is an Access-Control-Max-Age header?

How long, in seconds, the results of a CORS preflight request may be cached.

Access-Control-Max-Age lets a website tell the browser to cache the results of a CORS preflight check for a while, so every actual API call doesn't have to be preceded by a fresh OPTIONS round-trip. Setting it too low adds a real, measurable latency tax to every cross-origin request; setting it appropriately is a small tweak that noticeably improves perceived API responsiveness.

Common use case

An API sets Access-Control-Max-Age: 86400 so a browser only needs to repeat the CORS preflight check once a day per endpoint, instead of before every single cross-origin API call.

Example

Access-Control-Max-Age: 86400

History

Defined as part of the CORS specification, standardised by the W3C starting around 2014.

Did you know?

Chrome caps the effective value at 2 hours regardless of what a server sends, even though the spec technically allows much longer - a good example of a browser deliberately overriding a server's stated preference for security reasons.