What is an Access-Control-Max-Age header?
How long, in seconds, the results of a CORS preflight request may be cached.
Access-Control-Max-Age lets a website tell the browser to cache the results of a CORS preflight check for a while, so every actual API call doesn't have to be preceded by a fresh OPTIONS round-trip. Setting it too low adds a real, measurable latency tax to every cross-origin request; setting it appropriately is a small tweak that noticeably improves perceived API responsiveness.
Common use case
An API sets Access-Control-Max-Age: 86400 so a browser only needs to repeat the CORS preflight check once a day per endpoint, instead of before every single cross-origin API call.
Example
Access-Control-Max-Age: 86400History
Defined as part of the CORS specification, standardised by the W3C starting around 2014.
Did you know?
Chrome caps the effective value at 2 hours regardless of what a server sends, even though the spec technically allows much longer - a good example of a browser deliberately overriding a server's stated preference for security reasons.