- Cloudflare Workers added ML-KEM and ML-DSA to Web Crypto behind an opt-in flag. Libraries can use the runtime instead of bundling their own code.
- Cloudflare says these are building blocks, not a full migration path. The spec is a draft, and key and signature sizes grow.
- Leaders should ask where their software bundles its own cryptography and which libraries and vendors are testing these primitives.
Post-quantum migration will not come as one switch. It is a long list of libraries, protocols and services. Each must learn to use new building blocks. A small Cloudflare change shows one place where that work begins, and who has been carrying it.
On October 1, Cloudflare said its Workers platform now supports post-quantum algorithms in Web Crypto. Web Crypto is the standard cryptography interface for JavaScript. The support follows a draft report called Modern Algorithms in the Web Cryptography API. It is opt-in. Developers turn it on with a flag named webcrypto_modern_algorithms.
The idea: the burden moves from every app to the runtime
Until now, a Workers developer had to bring their own post-quantum code. It came as JavaScript or WebAssembly. Cloudflare names the costs. Teams must pick and maintain that code. Their applications grow larger. Every downstream library repeats the same work.
The lesson here is about ownership. A primitive is a basic cryptographic operation. When the runtime offers it, libraries can hand the job over. One maintained copy could replace many private ones where the runtime supports it.
For an executive, the question shifts. It is no longer "which of our teams wrote crypto code?" It becomes "which of our dependencies carry it?"
How the two algorithms work
ML-KEM is a way for two parties to agree on a shared secret. One side holds a public key. The other side uses it to lock a fresh secret. Only the private key holder can unlock it. Both sides then hold the same secret.
That is not encryption yet. A protocol such as HPKE must still turn the secret into working encryption. It does this with extra steps and a cipher such as AES-GCM. Cloudflare says its code samples are hooks for these primitives. They are not protocols.
ML-DSA is for digital signatures. Developers who have used Ed25519 or ECDSA will find the workflow familiar. You make a key pair, sign data, then check the signature. Cloudflare's example is a signed JSON Web Token. It uses the panva/jose library, which maps ML-DSA algorithms onto Web Crypto.
Cloudflare also included ML-KEM-1024, ML-DSA-65 and ML-DSA-87 "for completeness". One variant, ML-KEM-512, is missing. The native crypto library under Workers, BoringSSL, does not expose it in the version Cloudflare uses. Cloudflare chose not to add a separate implementation just for that one. The changes sit in workerd, the open-source runtime that powers Workers and is built on V8.
What this does not do
Cloudflare is direct about the limits. It calls the support "building blocks" for testing an integration. It does not call it a full migration path.
The feature is not on by default. The spec is still a draft. Cloudflare wants library authors to try it and report problems before it treats the API as stable.
The scope is narrow. SHA-3, ChaCha20-Poly1305, cSHAKE, TurboSHAKE and HPKE from the wider proposal are not in this change. Libraries should also check that the API exists before calling it. Other runtimes do not all support it yet.
Size is the cost that stays. Cloudflare warns that ML-DSA keys and signatures are much bigger than RSA or Ed25519 ones. Native support helps speed and trims bundles. It does not shrink what crosses the network or sits in storage.
Questions to put to your teams
This is one vendor's opt-in feature. It is not proof of a broad shift. It is still a useful prompt for an inventory.
Ask where your applications bundle their own cryptographic code. Ask who maintains it. Ask which libraries, such as those for tokens or HPKE, are testing runtime-native post-quantum support.
Ask whether larger keys, signatures and ciphertext fit your storage and network limits. Ask vendors what they have in place. Ask whether their tests run outside production.
Cloudflare says the ecosystem needs to move to post-quantum algorithms sooner than expected. The first practical step is not a rewrite. It is knowing who holds the cryptography in your software.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cloudflare.





