VYPR
researchPublished Oct 1, 2026· 1 source

Cloudflare Workers Adds Post-Quantum Cryptography Support via Web Crypto API

Cloudflare Workers now supports ML-KEM and ML-DSA post-quantum cryptographic algorithms through the Web Crypto API, enabling developers to experiment with future-proofing their applications.

Cloudflare Workers has announced the integration of post-quantum-resistant cryptographic algorithms, ML-KEM and ML-DSA, directly into its platform via the Web Crypto API. This move aims to simplify the transition to quantum-resistant cryptography for developers by providing access to essential primitives without requiring them to bundle separate cryptographic libraries.

The newly supported algorithms include ML-KEM-768 and ML-KEM-1024 for key encapsulation, and ML-DSA-44, ML-DSA-65, and ML-DSA-87 for digital signatures. Developers can now utilize functions such as encapsulateBits(), decapsulateBits(), and signature generation/verification directly within their Workers applications. The feature also includes support for JWK import and export for these algorithms, along with a getPublicKey() helper function.

This integration is currently available behind a compatibility flag, webcrypto_modern_algorithms, acknowledging that the underlying specifications are still evolving. Cloudflare emphasizes that this provides building blocks for experimentation rather than a complete migration path, allowing developers to test and validate their post-quantum integrations.

The necessity for such features stems from the broader challenge of post-quantum migration, which is not a single event but a complex process involving numerous protocols, libraries, and services. As organizations prepare for the eventual obsolescence of current cryptographic standards due to quantum computing threats, having native support for emerging quantum-resistant primitives becomes crucial.

Examples of how these primitives can be applied include signing JSON Web Tokens (JWTs) using ML-DSA, a process that can be delegated to the runtime instead of requiring libraries to carry their own implementations. Similarly, protocols like Hybrid Public Key Encryption (HPKE) and Oblivious HTTP (OHTTP) can leverage ML-KEM for secure key establishment, feeding the generated material into AEAD ciphers for complete encryption.

Cloudflare's initiative addresses the limitations of existing Web Crypto APIs, which often lack the necessary primitives for newer cryptographic standards. Previously, developers needing to experiment with post-quantum cryptography in JavaScript environments had to resort to bundling external libraries, increasing application size and maintenance overhead. This native support aims to streamline that process.

While the initial implementation supports ML-KEM-768 and ML-DSA-44, Cloudflare plans to expand support as specifications mature. The company also highlights the importance of checking for API support using SubtleCrypto.supports() to ensure compatibility across different runtimes, including browsers, Node.js, and Deno.

This development is a significant step towards enabling widespread adoption and testing of post-quantum cryptography, allowing developers to proactively prepare their applications and services for a future where current encryption methods may no longer be secure.

Synthesized by Vypr AI