AI Briefing
KOSign in

Cloudflare launches closed beta of OHTTP Gateway for privacy-preserving request handling

·2026.10.02 22:00

Key point

Cloudflare has launched a closed beta for its new OHTTP Gateway, a paid add-on allowing developers to receive Oblivious HTTP traffic without exposing user IP addresses to their servers.

Details

Cloudflare has launched the Cloudflare OHTTP Gateway in closed beta, a new paid add-on designed to help developers implement Oblivious HTTP (OHTTP) privacy standards. This service allows app backends to receive HTTP requests without seeing user IP addresses or TLS fingerprints, addressing the privacy burden currently placed on end users and developers.

How OHTTP Works

OHTTP relies on a "double-blind" privacy model involving two independently operated hops: a relay and a gateway.

  • The relay forwards encrypted requests, hiding client identifiers from the app server.
  • The gateway performs cryptographic decapsulation and encapsulation, allowing app servers to handle requests as plain HTTP.
  • This separation ensures no single party sees both client identifiers and request contents.

Cloudflare previously launched an OHTTP relay product, now renamed Cloudflare OHTTP Relay (formerly Privacy Gateway). The new Gateway complements this by serving customers whose app servers are already behind Cloudflare, who previously could not use Cloudflare's relay due to the separation-of-trust requirement.

Key Features and Architecture

The OHTTP Gateway is deployed across Cloudflare's global edge network to minimize latency. Key implementation details include:

  • Zone Integration: Enabled as a feature on a customer's zone, accepting requests at /.well-known/ohttp-gateway.
  • Key Management: Cloudflare manages all HPKE keys, serving public keys via GET requests to the gateway endpoint.
  • Security: Integrates with Cloudflare Access to authenticate incoming traffic from relays, supporting mutual TLS and other policies.
  • Privacy Safeguard: The Gateway refuses to decrypt requests sent from Cloudflare Workers or proxied hosts on Cloudflare to prevent breaking the separation of trust.

Use Cases

The Gateway is best suited for:

  • Developers hosting app servers on Cloudflare (CDN or Workers).
  • Applications receiving OHTTP requests from third-party relays, such as Apple’s LiveCallerID.
  • Teams seeking to minimize operational overhead and latency associated with self-hosted gateways.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.