- Cloudflare opened a closed beta of an OHTTP Gateway on October 2. It lets app servers receive requests without seeing user IP addresses.
- The privacy promise holds only if two separate parties run the relay and the gateway, and only if request bodies carry no identifying data.
- Ask who runs your relay, what your logs link together, and what your requests contain.
Privacy is moving from a user chore to a design choice
Cloudflare's announcement starts with who does the work today. Ordinary users are expected to defend themselves, with tools such as VPNs, cookie blocking and ad blockers.
App makers face a problem too. Cloudflare says a normal exchange between a client and a server leaves a trail, such as the client's IP address and TLS fingerprint. The result, it says, is that some app teams hold more personal data than they would like.
This shows a shift. Privacy is becoming something a company builds into its network path, not something it asks customers to manage. That choice sits with whoever buys the infrastructure.
What Cloudflare announced
On October 2, Cloudflare launched a closed beta of a self-serve OHTTP Gateway. It plans to sell the gateway as an extra-cost option that a customer turns on for their zone in a few clicks. There is a waitlist. The announcement gives no pricing.
OHTTP, short for Oblivious HTTP, is an IETF standard. Cloudflare also renamed its existing Privacy Gateway, an OHTTP relay product, to Cloudflare OHTTP Relay.
How it works
In a plain exchange, the app server sees the client's IP address. It can also fingerprint the client from the TLS versions and cipher suites it supports. That lets it link many requests to one person.
OHTTP adds two hops run by different parties. The relay sees who is calling but only forwards encrypted data. The gateway decrypts the request and passes plain HTTP to the app server. Cloudflare calls this a double-blind model: the relay sees client identifiers, the gateway and app see request contents, and no party sees both.
The encryption is Hybrid Public Key Encryption (HPKE). It means only the client and the app server can read the content. The relay sees ciphertext.
Cloudflare's gateway lives at a /.well-known/ohttp-gateway path on the customer's zone. Cloudflare manages the encryption keys. Cloudflare Access, its zero trust product, runs before decryption so customers can check which relays may connect. Options include mutual TLS and static service credentials.
The product guards against its own vendor
The most telling detail is a refusal. The gateway is built to turn away traffic that comes from Cloudflare Workers or from hosts proxied through Cloudflare. If one company ran both hops, it could see both identity and content, and the privacy model would fail.
This is why the two products exist. Cloudflare says its relay suits apps hosted off Cloudflare. The gateway suits apps already behind Cloudflare, or those taking OHTTP traffic from a third party such as Apple's LiveCallerID.
Cloudflare also says a homegrown gateway can add significant delay, and that its own runs on every server on its edge network. These are Cloudflare's claims. The announcement gives no benchmarks.
What OHTTP does not protect
Cloudflare is direct about the limits. OHTTP protects the network layer and does not touch the request body. If an app sends an email address or username inside the request, the privacy gain is lost.
The relay is the other weak spot. Cloudflare says the reason to use a dedicated relay provider is to promise users, verifiably, that logs with client identifiers are not inspected. Without that, a company could match relay logs to decrypted requests.
Questions to put to your team
Who operates our relay, and are they truly separate from us? Can we show users that we do not keep logs linking identities to requests? What do our request bodies contain? If our servers sit behind Cloudflare, have we confirmed that no relay runs on the same platform?
One product in closed beta is one data point, not a market trend. But the questions apply to any privacy architecture. The technology can hide the user. The promise that nobody quietly puts the pieces back together is a matter of contracts, logging and who you choose to run each hop.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cloudflare.





