TL;DR
Get monitors, keyboards and dev gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
Cloudflare says its self-serve OHTTP Gateway is entering a closed beta, adding a managed gateway to complement its existing OHTTP Relay. The two-hop protocol is designed to keep a relay from seeing request contents and a gateway from seeing a client’s identifying network information; Cloudflare says customers must use a third-party relay with its gateway to preserve that separation.
Cloudflare has opened a closed beta for a self-serve Oblivious HTTP (OHTTP) Gateway, adding a managed option for developers whose application servers run on Cloudflare or receive OHTTP requests from outside services. The announcement expands Cloudflare’s OHTTP products, but the privacy design depends on using the gateway with a separately operated relay, so one party does not handle both client identifiers and request contents.
Cloudflare said the gateway performs the cryptographic work needed to process OHTTP traffic: it decapsulates encrypted requests and encapsulates responses so an application can handle the traffic in a form comparable to ordinary HTTP, complementing its existing Cloudflare Quick Tunnels offering. A relay, by contrast, forwards encrypted requests without reading their contents. In the intended arrangement, the relay can see information needed to forward traffic but not the request itself, while the gateway processes the request without receiving the client’s IP address from the relay.
The company said developers can use its new gateway with a third-party OHTTP relay. It described this setup as suitable for applications already hosted behind Cloudflare, including services using its CDN or Workers, as well as services accepting OHTTP requests from a third party; nearly 9 in 10 European companies that use a CDN use Cloudflare. Cloudflare said running the gateway on its global edge network could reduce the distance between relay and gateway, and that applications using its CDN may also avoid some gateway-to-origin network travel. These are Cloudflare’s descriptions of the intended architecture and performance benefits; the announcement provides no independent latency measurements.
Cloudflare also renamed its existing Privacy Gateway product to Cloudflare OHTTP Relay. Customers using that relay can operate their own gateway, while customers using Cloudflare’s new gateway should pair it with a relay operated separately. The company said the gateway is in closed beta. Its earlier blog text also describes customer access as a paid add-on and refers to a waitlist; the announcement does not give pricing, general availability dates, or beta enrollment numbers.
A Managed Gateway, Separate Trust
The launch gives developers an additional way to implement OHTTP without building and operating the gateway themselves. That could lower the operational burden for teams that want to limit what their application servers learn about users, including network identifiers such as IP addresses. It also addresses a particular deployment gap: Cloudflare says customers protecting their application servers on its infrastructure could not use Cloudflare’s own relay without compromising the protocol’s intended separation of trust.
That separation is the central privacy issue, not simply whether a request is encrypted in transit. OHTTP’s design calls for a relay and gateway controlled by independent, non-colluding parties. If one operator can associate client metadata with decrypted request contents, the intended privacy benefit is weakened. Cloudflare’s product pairing therefore leaves developers responsible for selecting and configuring an independent relay; the availability of a managed gateway alone does not establish that a deployment meets every privacy or security need.
The announcement also matters to service operators weighing privacy against performance and maintenance. Cloudflare says its distributed edge can reduce the extra network distance introduced by OHTTP’s two-hop path. Actual results will depend on the relay, users’ locations, application architecture and workload, none of which were quantified in the source material.
As an affiliate, we earn on qualifying purchases.
Cloudflare’s Relay-First OHTTP History
Oblivious HTTP is an IETF standard for carrying HTTP requests through two separate services. A direct client-to-server connection can expose the client’s IP address to the application server, and connection characteristics such as supported TLS versions or cipher suites may help link requests. OHTTP is designed to reduce that visibility by having a relay forward encrypted traffic to a gateway, which handles the cryptographic processing before the application receives the request.
Cloudflare said it launched its OHTTP relay product in 2022. It cited Flo Health’s Anonymous Mode and Apple’s Private Cloud Compute as examples of services using OHTTP, but those examples do not establish that either service uses the newly announced gateway. Until this announcement, Cloudflare customers using its relay needed to supply their own gateway. The new product reverses that arrangement for some deployments: customers can use Cloudflare’s gateway while selecting a separate relay.
The company framed the gateway as an addition to its privacy infrastructure, rather than a replacement for the relay. Its product names now identify the distinct roles more clearly: Cloudflare OHTTP Relay forwards encrypted requests, while the new Cloudflare OHTTP Gateway processes them for application servers.
““The separation of trust between relay and gateway is critical: it ensures that no single party sees both client identifiers and request contents.””
— Cloudflare
As an affiliate, we earn on qualifying purchases.
Beta Access and Privacy Conditions
The announcement does not state the beta’s calendar start date, how many customers will be admitted, when access will expand, or when the service will become generally available. It refers both to a closed beta and to a waitlist, and describes the product as a paid add-on, but gives no price or detailed eligibility terms.
Cloudflare has not supplied independent performance figures or a detailed account of the gateway’s operational controls in the provided material. The privacy properties described depend on deployment choices, particularly using a relay operated independently from the gateway and avoiding arrangements in which a single party can connect client metadata to request contents. The source does not specify which third-party relays beta users can select or what verification is available to customers evaluating that separation.
The blog announcement also does not report external testing, a security audit, or measured privacy outcomes for the new service. Those points should not be inferred from the company’s description of OHTTP’s intended design.
As an affiliate, we earn on qualifying purchases.
Beta Rollout and Customer Details
Cloudflare says interested customers can register for the waitlist, and that the gateway is being offered as a paid add-on. The next concrete details to watch for are beta access terms, supported configurations, pricing and a general availability timeline. The company has not announced dates for those milestones in the supplied material.
As customers test the service, practical questions include which third-party relays they can use, how the gateway fits different Cloudflare hosting arrangements, and whether the edge deployment produces the latency improvements the company expects. Until Cloudflare publishes further information or test results, the confirmed development is limited to the closed beta and the expanded product choices it introduces.
As an affiliate, we earn on qualifying purchases.
Key Questions
What did Cloudflare announce?
Cloudflare announced a closed beta for a self-serve OHTTP Gateway and renamed its existing Privacy Gateway product Cloudflare OHTTP Relay.
What does an OHTTP gateway do?
The gateway processes OHTTP traffic by decapsulating encrypted requests and encapsulating responses so an application server can handle them. It is one part of a two-hop design that also uses a relay.
Does Cloudflare’s gateway replace the need for a relay?
No. OHTTP’s intended separation of trust uses both a relay and a gateway operated independently. Cloudflare says customers using its gateway should pair it with a third-party relay.
When will the gateway be generally available, and what will it cost?
Cloudflare has not provided a general availability date or a price in the announcement. It describes the gateway as a paid add-on and says it is in closed beta.
What privacy benefit is OHTTP designed to provide?
OHTTP is designed to keep the relay from seeing request contents and the gateway from learning the client’s IP address through the relayed request. The intended protection depends on keeping the relay and gateway separate and not colluding.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
