VYPR
advisoryPublished Oct 2, 2026· 1 source

Cloudflare Launches OHTTP Gateway to Enhance User Privacy

Cloudflare introduces its OHTTP Gateway, a new service designed to allow application backends to receive HTTP requests without exposing user IP addresses, bolstering online privacy.

Cloudflare is expanding its suite of privacy-preserving infrastructure with the launch of its new OHTTP Gateway. This service aims to address the growing burden of online privacy placed on end-users by enabling developers to bake privacy directly into their applications. Oblivious HTTP (OHTTP) is an Internet Engineering Task Force (IETF) standard that allows application backends to receive HTTP requests without direct visibility into user IP addresses or other identifying client information.

The OHTTP protocol operates by routing requests through two independently managed components: a relay and a gateway. The relay encrypts requests and forwards them, obscuring client identifiers from the ultimate destination. The gateway then performs the necessary cryptographic operations to decapsulate these encrypted requests and encapsulate responses, allowing application servers to process them as if they were standard HTTP requests. This separation of trust between the relay and the gateway is crucial, ensuring that no single entity possesses both the client's identifying information and the content of their requests.

Previously, Cloudflare offered a product called Privacy Gateway, now renamed Cloudflare OHTTP Relay, which served as an OHTTP relay. This allowed customers to provide more private experiences for their users, with examples including Flo Health's Anonymous Mode and Apple's Private Cloud Compute. However, customers who already utilize Cloudflare's services to protect their servers could not use Cloudflare's relay if they also wanted a managed gateway, as this would break the OHTTP privacy model by having Cloudflare see both client metadata and request contents.

To address this gap, Cloudflare is launching the OHTTP Gateway, currently in closed beta. This new offering is designed for customers whose application servers are already behind Cloudflare's network, or for those who prefer a managed solution to minimize latency and operational overhead. The gateway will be available as a paid add-on, allowing customers to enable it with minimal configuration.

Cloudflare's decision to build the OHTTP Gateway stems from observed trends and learned challenges. There is a clear demand from developers for accessible and usable privacy infrastructure, with many wanting to integrate network privacy by default into their applications. Furthermore, operating a secure and performant OHTTP gateway at scale can be complex and introduce significant latency due to the additional network hops and cryptographic processing involved.

Leveraging its global edge network and anycast architecture, Cloudflare's OHTTP Gateway aims to minimize latency by running on servers worldwide. For customers using Cloudflare's CDN or Workers, requests can be decrypted by the gateway and then processed by their application servers on the same infrastructure, further reducing latency. This integrated approach simplifies the adoption of OHTTP for businesses already invested in Cloudflare's ecosystem.

The OHTTP Gateway provides a critical option for developers who need to maintain the separation of trust required by the OHTTP protocol. By offering both a managed gateway and the option to run their own relay, Cloudflare aims to provide flexibility and support for a wider range of privacy-focused application architectures. This move is part of Cloudflare's broader commitment to raising the standard for online privacy and making privacy-enhancing technologies more accessible.

Synthesized by Vypr AI