Skip to content

Build1 publisher2 min readPublished

Compression Dictionary Transport cut a 272 KB bundle to a 2.6 KB delta in Cloudflare's lab test

In Cloudflare's lab test, RFC 9842 dictionary compression sent a 272 KB JavaScript file as a 2.6 KB delta, where gzip produced 92.2 KB. Teams that deploy small fixes often can now send returning visitors the change, where today those visitors download the whole bundle again.

The Engineer · Build desk

Illustration accompanying Compression Dictionary Transport cut a 272 KB bundle to a 2.6 KB delta in Cloudflare's lab test

What happened

  • Compression Dictionary Transport became a standard as RFC 9842 in September 2025, and Chrome and Edge support it from version 130.
  • Cloudflare opened a beta for Compression Dictionary Transport in April 2026.
  • A browser holding a cached dictionary adds dcb and dcz (dictionary-compressed Brotli and Zstandard) to Accept-Encoding and sends the dictionary's SHA-256 hash in Available-Dictionary.
  • Dictionary-compressed responses must carry Vary: accept-encoding, available-dictionary. Without it, a CDN can serve the body to a client that never had the dictionary and cannot decode it.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • cost Adopting it adds build work. The pipeline must keep the previous release's files, compress each new asset against its predecessor, and index every delta by path and hash so the server can find it.
  • constraint Deltas built only against the prior release help visitors who come back after every deploy. A visitor two releases behind sends a hash that matches no delta and downloads full Brotli.
  • exposure A server that trusts the Dictionary-ID label without checking the Available-Dictionary hash can send a delta to a client that does not hold the bytes it was built against.

Gzip and Brotli compress each response in isolation [5]. When a one-line fix gets a new hashed filename, a returning visitor downloads the whole file again. In the source's example that file is about 270 KB, and the browser already holds 99 percent of those bytes under the old hash [6]. Dictionary transport lets the server compress the new file against the copy the client says it has cached [4].

The 2.6 KB delta in Cloudflare's test is about 2.8 percent of the gzip size, or roughly 35 times smaller [10]. That result comes from one asset in one vendor's lab. According to the source's author, results depend entirely on how much changed between builds, and frequent small deploys are the case the ratio is meant for [11]. For the figure to transfer to another codebase, each release has to change only a small part of the bundle [11].

The build step is short. The source's pattern compresses each new bundle against the previous release's copy of the same file and stores the result next to it [12]. Its example command [13]:

``` zstd -19 --patch-from=dist-prev/app.8f3c1a.js dist/app.2d9e44.js -o dist/app.2d9e44.js.dcz-raw ```

The -raw suffix is the most useful documentation in that line. The dcz and dcb formats wrap the compressed stream in a short header that embeds the dictionary hash, so the browser can confirm it decoded against the right file [14]. The zstd output still needs that header before it is a valid dcz body [19]. Cloudflare's implementation adds the framing. For anyone doing it by hand, the source's advice is to follow the RFC's format section [15]. Because of that framing step, I would start with a CDN implementation.

On the server, the source's Express handler looks up a delta by filename and dictionary hash [16]. It serves the delta with Content-Encoding: dcz only when one exists and the request advertised dcz. Every other request falls through to the ordinary Brotli or gzip handler [16]. Browsers without support get the same response they got before [16].

The part of the design I like is the chaining. The new bundle's response carries its own Use-As-Dictionary header. Each release becomes the dictionary for the next, so a returning visitor keeps getting deltas across deploys [18]. The match value is a URL pattern for the future requests the stored file can help with: `Use-As-Dictionary: match="/js/app.*.js", id="app-v1"` [3].

What to watch

  • Support for dcb and dcz in browsers other than Chrome and Edge 130+, the only ones the source lists.
  • Whether Cloudflare's feature leaves beta, and whether its 272 KB to 2.6 KB result holds on production bundles where each release changes more code.
  • Bundler or CDN tooling that keeps the previous release and emits framed deltas automatically, so teams do not have to build and maintain that step by hand.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories