Skip to content

Response body inspection

Last updated View as MarkdownAgent setup

When no enabled feature needs response content, Cloudflare can send data to the client as it arrives. Some features inspect or change response content at the edge.

Inspection can hold part of a response at the edge. This may increase time to first byte (TTFB) or delay incremental delivery. The amount of data held depends on the feature and response.

Features that inspect response bodies

Cloudflare features primarily inspect responses with a Content-Type of text/html. Some features change the body, while others only read it.

The following features can change HTML response bodies when turned on and applicable:

Feature Body change
AI Labyrinth Adds invisible links for unauthorized AI crawlers
Always Online Adds a banner to archived pages
Automatic HTTPS Rewrites Rewrites eligible HTTP links to HTTPS
Cloudflare challenge features Injects challenge scripts or returns challenge content
Cloudflare Fonts and Automatic Platform Optimization Rewrites Google Fonts references
Email Address Obfuscation Obfuscates email addresses in page content
Markdown for Agents Converts HTML to Markdown for eligible requests
Replace insecure JavaScript libraries Rewrites supported insecure library URLs
Rocket Loader Changes script loading behavior
Web Analytics Injects the Real User Monitoring beacon

Security and AI features may also read HTML without changing it. Prefetch URLs reads URL manifests served as text/plain.

This list excludes explicit rules that inspect response content. Review each rule separately when troubleshooting.

Streaming considerations

Response body inspection most often affects progressive HTML and plain-text streams. It can affect other responses selected by explicit inspection rules. A client may receive data later or in larger groups than the origin sent it.

Set an accurate Content-Type at your origin. Do not serve streaming API responses as text/html or text/plain unless that media type is required.

The Cache-Control: no-transform response directive prevents body changes by supported features. It does not prevent read-only inspection. Refer to Cache-Control directives for other effects of this directive.

Isolate inspection issues

If a response stops streaming after you proxy it through Cloudflare:

  1. Verify that the origin sends data incrementally without Cloudflare.
  2. Check the origin response's Content-Type and Cache-Control headers.
  3. Review features and rules that apply to the response path.
  4. Create a path-specific Configuration Rule that sets Response Body Buffering to None.
  5. Test the response again through Cloudflare.

The None setting streams the body without inspection. It can prevent security, optimization, and analytics features from working on matching responses. Use the narrowest matching expression possible.

For setting values and API configuration, refer to Response Body Buffering.

Was this helpful?