Cloudflare announced a closed beta for its self-serve Cloudflare OHTTP Gateway, a new option in its OHTTP product suite designed to make privacy-preserving HTTP more accessible to developers.
The Gateway is offered as a paid add-on to a zone, and customers can start sending OHTTP traffic with a few clicks. A waitlist form is provided for those who want to participate.
HOW OHTTP GATEWAYS FIT INTO CLOUDFLARE’S PRIVACY MODEL
Oblivious HTTP (OHTTP) is an IETF standard that enables app backends to receive HTTP requests without seeing user IP addresses. In Cloudflare’s model, requests pass through two independently operated hops: a relay and a gateway. TechStaged has also covered Cloudflare launches Web Search API via AI Gateway with live-internet grounding.
The relay forwards encrypted requests to hide client identifiers from the app server, while the gateway decapsulates the requests and re-encapsulates responses so app servers can process them as regular HTTP. This separation of trust is central: no single party sees both client identities and request contents.
TWO DEPLOYMENT PATHS AND A RENAMED PRODUCT LINE
Since launching the original OHTTP Relay, Cloudflare renamed it to Cloudflare OHTTP Relay (formerly Privacy Gateway). Customers now have two options: use Cloudflare’s OHTTP Relay and run their own gateway, or use Cloudflare’s new OHTTP Gateway with a third-party relay.
The gateway is designed to be used when app servers are behind Cloudflare (CDN or Workers) or when a third-party relay is involved, helping minimize latency and operational overhead.
WHAT THE GATEWAY DOES AND HOW IT’S MANAGED
The Gateway is built as a managed service deployed across Cloudflare’s edge network. Clients enable it on their zone at /.well-known/ohttp-gateway and can choose between standard and chunked OHTTP for better performance.
Key management is automated, and public keys are served via GET requests to the well-known endpoint. Cloudflare Access sits before decryption to authenticate traffic, helping protect the gateway from abuse.
- Key management is automated by the Gateway.
- Public keys are served at /.well-known/ohttp-gateway.
- Cloudflare Access authenticates incoming traffic before decryption.
- The Gateway enforces the OHTTP privacy model by preventing users from running both a relay and a gateway on Cloudflare.
WHAT THIS MEANS FOR DEVELOPERS AND WHAT COMES NEXT
Cloudflare contends that the Gateway aims to lower the barriers to adopting privacy infrastructure, delivering a scalable, easy-to-onboard solution for OHTTP. The company notes that if developers want an integrated Cloudflare experience, the Gateway is likely the better fit when app servers live behind Cloudflare or when using third-party clients (e.g., Apple or other relays).
RELATED COVERAGE
- Cloudflare launches Web Search API via AI Gateway with live-internet grounding
- Cloudflare unveils Account Abuse Protection dashboard with Hashed User IDs to anchor investigation
- Cloudflare unifies logs, traces, analytics, and dashboards with eight major Observability updates
- Cloudflare unveils Streamline for custom video pipelines powered by Stream and Workers
- Developer Tools articles




