Cloudflare has opened a closed beta for a self-service Oblivious HTTP gateway, expanding its privacy infrastructure for developers whose applications already run behind the company’s network.
Oblivious HTTP, or OHTTP, is an Internet Engineering Task Force standard that places independently operated services between a client and an application. One service acts as a relay, forwarding an encrypted request without gaining access to its contents. A gateway performs the cryptographic work needed to deliver the request to the application. The design is intended to prevent any single participant from seeing both identifying network information and the plaintext request.
Cloudflare said customers will be able to add the gateway to a zone as a paid service. The company is accepting registrations for the beta and plans to launch the product more broadly in the autumn. It did not disclose pricing in the announcement.
The gateway complements an existing Cloudflare relay service, previously called Privacy Gateway and now renamed Cloudflare OHTTP Relay. That distinction matters for customers hosting applications on Cloudflare: using both a Cloudflare-operated relay and a Cloudflare-hosted application would put information from both sides of the exchange within one company’s infrastructure, undermining the separation on which the OHTTP model depends. Those customers can instead use an independent relay with Cloudflare’s gateway.
In an ordinary web exchange, an application server can receive an IP address and other connection characteristics that may help link requests to the same device. Under OHTTP, the relay can see network identifiers but receives encrypted content. The gateway can decrypt the message for the application but receives it after the relay has removed the original client details. The privacy benefit therefore depends on the relay and gateway remaining independent and not combining their observations.
Cloudflare said the new gateway will operate across its global edge network. For applications using its content-delivery network, the company expects requests to be decrypted and handled on nearby infrastructure, reducing some of the extra travel introduced by the two-hop design. Encryption and additional routing still create overhead, so performance will be an important measure during the beta.
The company cited existing deployments of its relay technology, including anonymous access features in Flo Health and Apple’s Private Cloud Compute, as evidence of demand for infrastructure that separates requests from user identity. The gateway release gives developers another way to divide the relay and decryption roles while keeping application delivery on Cloudflare.


