Cloudflare OHTTP gateway
4 hours ago
- Cloudflare launches OHTTP Gateway, a paid add-on that allows app backends to receive HTTP requests without seeing user IP addresses.
- OHTTP uses a two-hop architecture: a relay hides client identifiers, and a gateway handles cryptographic decapsulation and encapsulation.
- The new Gateway is for customers whose servers are already on Cloudflare (e.g., CDN or Workers) or who want a managed gateway, while the existing OHTTP Relay is for those running their own gateway.
- The Gateway runs on Cloudflare’s global edge network to minimize latency and supports automatic scaling, easy key management, and relay authentication via Cloudflare Access.
- Privacy is maintained by ensuring no single entity sees both client identifiers and request contents; the Gateway refuses to decrypt requests from Cloudflare-operated relays.
- Use cases include Flo Health’s Anonymous Mode, Apple’s Private Cloud Compute, and Apple’s LiveCallerID SDK.
- Developers can enable the Gateway on their zone with a few clicks, and it supports both standard and chunked OHTTP for better performance.
- To get started, join the waitlist, implement an OHTTP client, and bring your own relay from a separate provider to preserve privacy.