Cloudflare Announces OHTTP Gateway Closed Beta
Cloudflare has announced a closed beta for its new self-serve Cloudflare OHTTP Gateway, expanding access to its privacy-preserving infrastructure for developers.

Introducing the Cloudflare OHTTP Gateway
Cloudflare has announced the closed beta of a self-serve Cloudflare OHTTP Gateway, giving developers a new way to bake privacy into their applications. Alongside this launch, the company is renaming its existing Privacy Gateway product to Cloudflare OHTTP Relay to better distinguish between the two distinct infrastructure components.
End users frequently carry a heavy burden when trying to protect their online privacy, often relying on VPNs, disabled cookies, or adblockers. Meanwhile, standard client-server exchanges routinely expose sensitive data such as client IP addresses and TLS fingerprints. To address this, Oblivious HTTP (OHTTP) operates as an IETF standard defined by the IETF standard to help app backends receive HTTP requests without exposing user IP addresses.
How the OHTTP Architecture Works
The OHTTP architecture relies on requests traveling through two independently-operated hops: a relay and a gateway. An OHTTP relay blindly forwards encrypted requests to hide client identifiers, while an OHTTP gateway handles the cryptographic work of decapsulating requests and encapsulating responses. This separation of trust ensures that no single party handles both the client identifiers and the request contents simultaneously.
Previously, Cloudflare offered its Privacy Gateway product, which has now been rebranded. Applications like Flo Health have utilized OHTTP for features such as Anonymous Mode, and Apple has implemented OHTTP within systems like Private Cloud Compute to separate AI inference requests from user identities.

Choosing Between Relay and Gateway Architecture
With the introduction of the new gateway option, customers looking to implement an OHTTP architecture with proper trust separation now have two primary choices depending on their infrastructure setup.
Developers whose application servers are hosted off Cloudflare can utilize Cloudflare's OHTTP Relay while running their own gateway. Alternatively, customers whose application servers are already behind Cloudflare, or those accepting OHTTP requests from third parties like Apple's LiveCallerID, can opt for the new managed gateway option.

Global Network Integration and Low Latency
Building and operating an OHTTP gateway at scale presents performance and operational challenges, particularly because proxying adds extra hops and encryption overhead. Cloudflare notes that its experience running services like 1.1.1.1 and iCloud Private Relay positions it well to handle this infrastructure.
By leveraging an anycast network configuration, the new OHTTP Gateway will execute across every server on Cloudflare's global edge network. This design minimizes latency during relay-to-gateway hops and allows requests to be decrypted and resolved on the same infrastructure if customers already use Cloudflare's CDN.
Participation and Availability
The self-serve Cloudflare OHTTP Gateway is currently available in a closed beta release. Customers interested in adding the service as a paid add-on to their zone can register through the waitlist form provided by Cloudflare.
By expanding its suite of privacy tools, Cloudflare aims to make advanced cryptographic privacy standards easier for developers to adopt by default across modern web applications.
Sources
- Cloudflare BlogAnnouncing Cloudflare OHTTP Gateway – expanding access to Cloudflare’s privacy-preserving infrastructure
Continue chronologically




