CLOUDFLARE has announced the Cloudflare OHTTP Gateway, a new managed service designed to make privacy-preserving HTTP traffic more broadly available. Building on their existing OHTTP Relay product, the gateway adds a hosted option for decrypting and re-encrypting requests so that app servers can receive OHTTP traffic as regular HTTP, with the crucial separation of trust between the relay and the gateway. The company is renaming the older Privacy Gateway to Cloudflare OHTTP Relay to differentiate the two components.
Customers can choose between running their own gateway behind Cloudflare’s relay, or using Cloudflare’s gateway in conjunction with a third‑party relay, depending on their architecture and privacy requirements. A waitlist is open for interested organisations.
The article explains how OHTTP works: traffic passes through two hops—an independent relay that strips client identifiers and a gateway that handles the cryptography, decapsulates requests, and forwards them to the app server. This “double-blind” model ensures the app server never sees both the client’s identity and the request content.
Cloudflare highlights that deploying the gateway on its global edge network can reduce latency by keeping decryption and origin resolution near the user, while still maintaining the necessary separation of trust. The gateway supports standard and chunked OHTTP, with key management automated by Cloudflare and authentication options via Cloudflare Access to prevent abuse.
The post also outlines practical steps to get started, including onboarding, client libraries, and guidance to avoid sending identifying data in request bodies.