Cloudflare Workers adds post-quantum ML-KEM and ML-DSA support to Web Crypto
Key point
Support for ML-KEM-768 and ML-DSA-44 is available behind the webcrypto_modern_algorithms compatibility flag.
Details
Cloudflare Workers now supports post-quantum-resistant algorithms within Web Crypto, specifically ML-KEM for key encapsulation and ML-DSA for signatures. This addition allows developers to experiment with these primitives directly in the runtime without bundling separate cryptographic implementations, addressing the need for early adoption as the ecosystem transitions away from classical algorithms.
Supported Algorithms and Implementation
The initial implementation supports ML-KEM-768 and ML-DSA-44, with additional support for ML-KEM-1024, ML-DSA-65, and ML-DSA-87. ML-KEM-512 is excluded because the underlying BoringSSL library used by workerd does not expose it. The feature is gated behind the webcrypto_modern_algorithms compatibility flag, reflecting the draft status of the specification.
Key API additions include:
encapsulateBits(),decapsulateBits(),encapsulateKey(), anddecapsulateKey()for ML-KEM operations.getPublicKey()to derive public keys from private keys.SubtleCrypto.supports()to check for algorithm availability across runtimes.- JWK import and export capabilities for these algorithms.
Practical Implications for Developers
This update enables libraries like panva/jose and panva/hpke to delegate cryptographic operations to the runtime rather than shipping their own implementations. For example, HPKE can now use native ML-KEM primitives to generate shared key material, which can then be fed into an AEAD like AES-GCM. Similarly, ML-DSA allows for native signing and verification of JSON Web Tokens (JWTs).
While this improves performance and reduces bundle sizes, it does not mitigate the fact that post-quantum keys and signatures are substantially larger than those for RSA or Ed25519. The current scope focuses on ML-KEM and ML-DSA; other algorithms from the WICG proposal, such as SHA-3, ChaCha20-Poly1305, and cSHAKE, are not yet implemented.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.