Trending:

Cloudflare opens closed beta for OHTTP Gateway to broaden privacy-preserving infrastructure

Diagram of Cloudflare OHTTP Gateway showing relay and gateway components across Cloudflare’s edge network
TechStaged-owned

Summary

  • Cloudflare announced a closed beta for its self-serve Cloudflare OHTTP Gateway.
  • The Gateway will be offered as a paid add-on to a zone.
  • Cloudflare renamed its Privacy Gateway to Cloudflare OHTTP Relay.

Cloudflare announced a closed beta for its self-serve Cloudflare OHTTP Gateway, a new option in its OHTTP product suite designed to make privacy-preserving HTTP more accessible to developers.

The Gateway is offered as a paid add-on to a zone, and customers can start sending OHTTP traffic with a few clicks. A waitlist form is provided for those who want to participate.

HOW OHTTP GATEWAYS FIT INTO CLOUDFLARE’S PRIVACY MODEL

Oblivious HTTP (OHTTP) is an IETF standard that enables app backends to receive HTTP requests without seeing user IP addresses. In Cloudflare’s model, requests pass through two independently operated hops: a relay and a gateway. TechStaged has also covered Cloudflare launches Web Search API via AI Gateway with live-internet grounding.

The relay forwards encrypted requests to hide client identifiers from the app server, while the gateway decapsulates the requests and re-encapsulates responses so app servers can process them as regular HTTP. This separation of trust is central: no single party sees both client identities and request contents.

TWO DEPLOYMENT PATHS AND A RENAMED PRODUCT LINE

Since launching the original OHTTP Relay, Cloudflare renamed it to Cloudflare OHTTP Relay (formerly Privacy Gateway). Customers now have two options: use Cloudflare’s OHTTP Relay and run their own gateway, or use Cloudflare’s new OHTTP Gateway with a third-party relay.

The gateway is designed to be used when app servers are behind Cloudflare (CDN or Workers) or when a third-party relay is involved, helping minimize latency and operational overhead.

WHAT THE GATEWAY DOES AND HOW IT’S MANAGED

The Gateway is built as a managed service deployed across Cloudflare’s edge network. Clients enable it on their zone at /.well-known/ohttp-gateway and can choose between standard and chunked OHTTP for better performance.

Key management is automated, and public keys are served via GET requests to the well-known endpoint. Cloudflare Access sits before decryption to authenticate traffic, helping protect the gateway from abuse.

  • Key management is automated by the Gateway.
  • Public keys are served at /.well-known/ohttp-gateway.
  • Cloudflare Access authenticates incoming traffic before decryption.
  • The Gateway enforces the OHTTP privacy model by preventing users from running both a relay and a gateway on Cloudflare.

WHAT THIS MEANS FOR DEVELOPERS AND WHAT COMES NEXT

Cloudflare contends that the Gateway aims to lower the barriers to adopting privacy infrastructure, delivering a scalable, easy-to-onboard solution for OHTTP. The company notes that if developers want an integrated Cloudflare experience, the Gateway is likely the better fit when app servers live behind Cloudflare or when using third-party clients (e.g., Apple or other relays).

Reporting by Owen Blackridge; editing by TechStaged editors

Editorial disclosure: This article was prepared with AI assistance from a source-limited research package and passed TechStaged's automated factual, originality, licensing, and publication checks.

Our Standards: The TechStaged Editorial Principles.

f in

Owen Blackridge

Owen Blackridge

Technology Editor

Owen covers platform shifts, AI launches, and the practical impact of emerging technology on small teams.