Post

Cloudflare opens a beta OHTTP Gateway

Cloudflare’s closed beta adds a managed Oblivious HTTP gateway for applications hosted behind its edge. OHTTP splits trust between a relay that sees client metadata and a gateway that can read request contents, so neither role alone sees both.

The gateway handles HPKE encapsulation and exposes OHTTP traffic through a zone endpoint, while app servers can keep accepting ordinary HTTP. Cloudflare says it refuses requests from its own relays, Workers, and proxied hosts to preserve the separation-of-trust property. This is a paid, opt-in product—not general browser privacy by default—and it still depends on independent relay/gateway operators and clients avoiding identifying details in request bodies.

The Hacker News thread raised deployment and abuse questions, including how OHTTP fits with existing proxy tools; one commenter clarified that the product protects inbound requests to participating services, not users’ general outbound browsing.