Cloudflare has announced the closed beta for its self-serve Cloudflare OHTTP Gateway, a new service designed to help developers implement Oblivious HTTP (OHTTP) easily. OHTTP is an IETF standard that enables application backends to receive HTTP requests without being able to see the client's IP address or TLS fingerprint.
Cloudflare launches closed beta for OHTTP gateway to enhance user privacy
The service operates through a "double-blind" privacy model involving two independent hops: a relay and a gateway. An OHTTP relay forwards encrypted requests while stripping client identifiers, and the OHTTP gateway performs the cryptographic work of decapsulating those requests so that app servers can process them as standard HTTP. This separation of trust ensures that no single party can see both the user's identity and the request content.
The new gateway is particularly useful for customers who already protect their web servers behind Cloudflare's infrastructure. Previously, using Cloudflare's OHTTP Relay alongside Cloudflare-protected servers would break the privacy model because Cloudflare would be able to see both the client metadata and the decrypted request contents. With the OHTTP Gateway, developers can maintain the necessary separation of trust while leveraging Cloudflare's global edge network to minimize latency.
As part of this update, Cloudflare is also renaming its existing "Privacy Gateway" product to "Cloudflare OHTTP Relay" to better distinguish it from the new gateway service.
Sources
- Cloudflare OHTTP gateway (Hacker News Frontpage, 2026-10-03)