Cloudflare Launches OHTTP Gateway to Keep User IPs Out of App Servers

Cloudflare Ohttp Gateway

Cloudflare Launches OHTTP Gateway to Keep User IPs Out of App Servers

Cloudflare has launched a closed beta for its new OHTTP Gateway, a managed service that decrypts Oblivious HTTP requests so app servers never see user IP addresses or TLS fingerprints. The gateway runs on Cloudflare's global edge, minimizing latency, and automatically manages encryption keys. It refuses to decrypt requests from Cloudflare Workers or proxied hosts to preserve OHTTP's double-blind privacy model. The move expands Cloudflare's privacy suite, which already includes an OHTTP relay used by Flo Health and Apple's Private Cloud Compute.

This creates a “double-blind” privacy model: the relay sees only client identifiers; the gateway and app server see only request contents; no party sees both.
  1. robertlagrant

    This is slightly worse than Cloudflare's usual excellent writing.

    But that aside - surely this won't help for websites with Google tracking code embedded, which are the sorts of sites that track you anyway?

  2. simondotau

    I have absolutely no reason to think Cloudflare is a covert CIA operation. In fact, I’m sure there are plenty of good reasons to think it isn’t. But if it were, pretty much everything it does is exactly what you'd expect from one.

  3. jt2190

    > Meanwhile, some app developers end up knowing more about their users than they’d care to: a typical client-server exchange creates a trail of user data, like the client’s IP address or TLS fingerprint. This level of visibility can be a burden.

    Can someone expand on “burden” here? Scenarios that come to mind for me are something like: “I now need to ensure my log files are stored securely but that’s a PITA.” This doesn’t feel like the best example of why I’d use this though. (Edit: Secure messaging servers for a service like Signal?)

  4. 0x073

    As cloudflare is the gateway for half the Internet and the other half is meta Google and Microsoft, I would prefer to share my IP with the website I visit instead some big tech companies.

    But maybe I get privacy wrong.

  5. ricardobeat

    So.. they continue having access to private identifiers, while you willingly give it up to "protect privacy"? Piping all of that data into a massive central database instead of your nginx logs? How is this supposed to be better?

More from this day

2026-10-03