What is a Vary header?
Lists which request headers a cache must also match on before it can reuse a cached response.
Vary tells a cache which request headers it needs to also match on before reusing a stored response - commonly Accept-Encoding, so a compressed and uncompressed version of a page aren't confused for each other, or Accept-Language on a multilingual website. Getting Vary wrong is a sneaky bug: a cache can end up serving the wrong language or the wrong compressed variant to visitors, and because it depends on cache state, it often only shows up intermittently rather than on every single request.
Common use case
A multilingual site sets Vary: Accept-Language so a CDN caches a separate copy of a page per language, instead of accidentally serving one visitor's cached French page to the next visitor who requested English.
Example
Vary: Accept-Encoding, Accept-LanguageHistory
Part of the original HTTP/1.1 specification, RFC 2068 (1997).
Did you know?
Sending Vary: * effectively makes a response uncacheable by any shared cache at all, since it would need to match on every possible request header to ever safely reuse it.