AI NewsInfrastructureAnnouncement

Cloudflare opens a closed beta for its OHTTP gateway, a way to receive encrypted web requests without seeing who sent them

Cloudflare's new OHTTP gateway lets a web service accept Oblivious HTTP requests without learning the client's IP address, as a paid add-on in closed beta on CDN and Workers zones.

AI News

Editorial2 min read

LinkedInX
Cloudflare blog header for the OHTTP gateway announcement

Image: Cloudflare

Why it mattersA team shipping a privacy-sensitive feature can now accept requests through the IETF relay-and-gateway split without running the gateway, which is the part most backends never built.

A privacy feature that used to need two servers you did not own can now live on one that you already pay. Cloudflare opened a closed beta on 2 October for an OHTTP gateway that accepts Oblivious HTTP requests on a zone and forwards the plain traffic to the origin, run by Lara Schull on the Cloudflare blog.

Oblivious HTTP is an IETF standard, RFC 9458, that splits a web request between a relay and a gateway. The relay sees the client's IP address but only ciphertext for the body and URL. The gateway sees the body and the URL but only the relay's IP address. No single party sees both. The design is why Apple's LiveCallerID can tell an iPhone whether a number is a known scammer without Apple learning what number the user looked up, and why Flo Health's Anonymous Mode lets a user record health data without the service linking the record to the account.

What Cloudflare is running

Cloudflare says the gateway decapsulates the encrypted request, hands the plain traffic to an origin on the same zone, and encapsulates the response on the way back. Enabling it on a zone, by the company's own account, is a couple of clicks and gives the zone a dedicated OHTTP endpoint with key management included. The gateway runs on the same CDN and Workers infrastructure the zone already uses, which is the paragraph that removes the usual blocker: you did not have to stand up a second service to be the gateway.

The post names three use cases the company sees already: receiving OHTTP requests from a third-party client such as Apple's LiveCallerID SDK, serving Private Cloud Compute AI inference calls, and relaying Flo Health's Anonymous Mode. Each one is a case where the client already knows how to speak OHTTP and the backend needed somebody to answer in it.

What is in the beta and what is not

The gateway is a paid add-on, with no public price in the announcement. A waitlist is open. Cloudflare has not stated general availability. The post does not say what request rates the beta will carry or whether the gateway can be chained with Workers code that runs on the decrypted request before it reaches the origin. Both of those are reasons to join the waitlist and ask rather than assume.

Readers should also note what the gateway does not do. OHTTP does not hide the fact that a request was made, and it does not protect against a hostile relay that colludes with the gateway operator. The RFC states the trust model, and the Cloudflare announcement does not change it.

A team building a privacy-sensitive feature on the web now has one less piece of plumbing to run. If the client speaks OHTTP, the Cloudflare zone can be the service that answers it, instead of forcing the team to operate a separate gateway host that most backends never had.

Source

Primary source: Announcing Cloudflare's OHTTP Gateway, Cloudflare, 2 October 2026.

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX