---
name: azion-configure-cache-policies-for-an-application
description: >-
  Set how long an object stays cached, bypass the cache for a path, and forward the origin's Set-Cookie header to users.
---

# Configure cache policies for an application

From Azion Console, you set how long an object stays cached, bypass the cache for a path, and forward the origin's `Set-Cookie` header. A cache setting carries the cache policy, and a [Rules Engine](/en/documentation/platform/applications/rules-engine/) rule applies it to the requests you choose.

To vary a cached object by a query string argument or by a cookie, refer to [Configure Advanced Cache Key](/en/documentation/guides/application-performance/cache-and-purge/advanced-cache-key/).

---

## Prerequisites

- An application. To create one, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).
- Access to Azion Console. Refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- Application Accelerator can generate usage-related costs. For the rates, refer to [Pricing](/en/documentation/fundamentals/pricing/#application-accelerator).

---

## Turn on Application Accelerator

A cache setting needs no module, and any application can carry one. [Application Accelerator](/en/documentation/platform/applications/#application-accelerator) is required for a **Max Age** below 60 seconds, for cache variation, and for the **Bypass Cache** and **Forward Cookies** behaviors. The module is off by default. To turn it on:

1. **Open the application**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**.

2. **Turn on the module**

   On the **Main Settings** tab, in the **Modules** section, turn on **Application Accelerator**.

3. **Select Save**

The application runs with Application Accelerator. Its cache settings accept a **Max Age** below 60 seconds, and **Bypass Cache** and **Forward Cookies** become available in **Rules Engine**.

---

## Set the cache TTL for a path

A cache setting holds the time-to-live (TTL) the browser applies and the TTL Azion applies. To create one:

1. **Open the Cache Settings tab**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**, then go to the **Cache Settings** tab.

2. **Select + Cache**

3. **Name the cache setting**

   In **Name**, enter a name that identifies the setting. For example: `/target-uri - Cache TTL`.

4. **Set the browser cache**

   Under **Browser Cache**, select *Override cache settings* and set the maximum age in seconds.

5. **Set Max Age**

   Under **Cache**, select *Override cache behavior* and set **Max Age** to the number of seconds Azion keeps the object.

6. **Select Save**

The cache setting appears in the **Cache Settings** tab. The same setting can also vary the cached object by query string or by cookie, which is the [Advanced Cache Key](/en/documentation/platform/applications/cache/cache-settings/#application-accelerator) feature.

A cache setting takes effect only when a rule applies it. To apply this one to the `/target-uri` path:

1. **Go to the Rules Engine tab**

2. **Select + Rule**

3. **Name the rule**

   Enter a name for the rule. For example: `/target-uri - Cache TTL`.

4. **Select Request Phase**

5. **Select the variable in the Criteria section**

   In the **Criteria** section, select the `${uri}` variable.

6. **Select starts with as the comparison operator**

7. **Enter the argument**

   Enter `/target-uri` as the argument.

8. **In the Behaviors section, select Set Cache Policy**

9. **Select the cache setting you created**

10. **Select Save**

Requests whose URI starts with `/target-uri` carry the cache setting, at both the browser TTL and the Azion TTL you set. A new rule takes a few minutes to propagate.

---

## Bypass the cache for a path

**Bypass Cache** stops Azion from caching the origin response for the requests a rule matches. To create the rule:

1. **Go to the Rules Engine tab**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**, then go to the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the rule**

   Enter a name for the rule. For example: `/target-uri - Bypass Cache`.

4. **Select Request Phase**

5. **Select the variable in the Criteria section**

   In the **Criteria** section, select the `${uri}` variable.

6. **Select starts with as the comparison operator**

7. **Enter the argument**

   Enter `/target-uri` as the argument.

8. **In the Behaviors section, select Bypass Cache**

9. **Select Save**

Requests whose URI starts with `/target-uri` reach the origin, and Azion stores no response for them. A new rule takes a few minutes to propagate.

> **Note**
>
> **Bypass Cache** affects only the cache on Azion, not the browser cache. The browser cache comes from the cache setting that **Set Cache Policy** applies.

For more information, refer to [Bypass Cache](/en/documentation/platform/applications/rules-engine/#bypass-cache). For the difference between **Bypass Cache** and a **Max Age** of `0` seconds, refer to [Cache variation](/en/documentation/platform/applications/application-accelerator/cache-variation/).

---

## Forward cookies from the origin to the user

**Forward Cookies** sends the origin's `Set-Cookie` header to users, including on a cache hit. To create the rule:

1. **Go to the Rules Engine tab**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**, then go to the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the rule**

   Enter a name for the rule. For example: `/target-uri - Forward Cookies`.

4. **Select Request Phase**

5. **Select the variable in the Criteria section**

   In the **Criteria** section, select the `${uri}` variable.

6. **Select starts with as the comparison operator**

7. **Enter the argument**

   Enter `/target-uri` as the argument.

8. **In the Behaviors section, select Forward Cookies**

9. **Select Save**

Requests whose URI starts with `/target-uri` return the origin's `Set-Cookie` header to the user.

The forwarded header can carry session cookies. To stop a user from receiving the session cookies of another user:

1. **Go to the Cache Settings tab**

2. **Select + Cache**

3. **Name the cache setting**

   In **Name**, enter a name that identifies the setting. For example: `/target-uri - Private cookies`.

4. **Denylist the session cookies**

   Under **Application Accelerator**, open **Cache vary by Cookies** and set **Behavior** to *Denylist*.

5. **Enter the cookie names**

   Add each session cookie to the list of cookie names.

6. **Select Save**

The cache setting appears in the **Cache Settings** tab, and it keeps the listed cookies out of the cache key.

To apply that cache setting to the rule that forwards the cookies:

1. **Go to the Rules Engine tab**

2. **Select the rule**

   Select the `/target-uri - Forward Cookies` rule.

3. **In the Behaviors section, select + Behavior**

4. **Select Set Cache Policy**

5. **Select the cache setting**

   Select the `/target-uri - Private cookies` cache setting.

6. **Select Save**

The rule forwards the origin's `Set-Cookie` header and applies the cache setting. A rule change takes a few minutes to propagate. The same rule can also carry the **Bypass Cache** behavior.

---

## Next steps

- [Cache variation](/en/documentation/platform/applications/application-accelerator/cache-variation.md): What Bypass Cache does that a Max Age of 0 seconds does not.
- [Cache Settings](/en/documentation/platform/applications/cache/cache-settings.md): Every field a cache setting carries, with its values and defaults.
- [Verify cache indicators with ModHeader](/en/documentation/guides/application-performance/cache-and-purge/check-page-cache-time.md): Read the cache headers a request returns and confirm the policy you applied.
- [Real-Time Purge](/en/documentation/platform/applications/cache/real-time-purge.md): Expire a cached object before its Max Age runs out.
