Cloudflare is launching a paid add-on that lets customers hide user IP addresses from their own servers. The company announced the Cloudflare OHTTP Gateway today, a service that wraps HTTP requests so app servers never see the original client’s identity. It is the latest move in a privacy push that started with Apple’s Private Cloud Compute and Flo Health’s Anonymous Mode.
The announcement comes from Lara Schull and Akshat Mahajan, Cloudflare engineers leading the project. They describe a growing problem: developers want privacy features, but building them from scratch is hard. The OHTTP Gateway aims to fix that by putting the trust-separation machinery in Cloudflare’s hands.
What OHTTP Does
OHTTP is an IETF standard designed to let app backends receive HTTP requests without seeing the user’s IP address. Requests pass through two hops: a relay and a gateway. The relay forwards requests blindly, hiding client identifiers from the server. The gateway handles the cryptographic work of wrapping and unwrapping requests so the app server gets plain HTTP on the other side.
The separation of trust is the point. No single party sees both the client identifier and the request contents. That distinction is why Cloudflare is launching the new gateway product: customers who already sit behind Cloudflare’s infrastructure needed a way to use OHTTP without giving the company full visibility into their traffic.
The Old Problem
For years, developers had to choose between two bad options. They could run their own relay and gateway, which meant managing encryption, decryption, and the performance costs of extra hops. Or they could skip privacy entirely and expose user data to their own servers.
Cloudflare’s existing OHTTP Relay product, Privacy Gateway, solved part of the problem. Flo Health used it for their app’s Anonymous Mode. Apple’s Private Cloud Compute used it to disassociate AI inference requests from user identities. But those customers who were already protected behind Cloudflare’s CDN or Workers still couldn’t use a Cloudflare-operated relay.
The reason: Cloudflare would see both client metadata and the decrypted contents of requests, breaking OHTTP’s privacy model. The new gateway changes that. Customers can now choose between a Cloudflare OHTTP Relay and a Cloudflare OHTTP Gateway, depending on where their servers live and who sends the requests.
The Beta Launch
The closed beta for the self-serve Cloudflare OHTTP Gateway is live today. Cloudflare is also renaming its Privacy Gateway to Cloudflare OHTTP Relay to better distinguish the two products. The renaming reflects the separation between the two roles: the relay hides client identifiers, and the gateway handles the cryptographic work.
The pricing model is simple. Customers enable the OHTTP Gateway as a paid add-on to their zone and start receiving OHTTP traffic with just a few clicks. Register through the form to join the waitlist.
Why Latency Matters
Building a performant OHTTP gateway is hard. Every proxying architecture introduces latency because requests must travel extra hops around the Internet. Add the cost of decrypting requests and encrypting responses, and the homegrown setup can hit significant delays.
Cloudflare says its experience running OHTTP relays showed this firsthand. The company is well-positioned to solve it. The same building blocks that enable fast, reliable privacy infrastructure for products like 1.1.1.1 and iCloud Private Relay make Cloudflare a good home for an OHTTP gateway.
The company’s anycast approach means the OHTTP Gateway runs on every server on Cloudflare’s global edge network, minimizing latency in relay-to-gateway hops. If you use Cloudflare’s CDN, user requests can be decrypted by the Gateway and resolved by app servers on the same Cloudflare metals, saving gateway-to-origin latency.
The Separation Requirement
OHTTP’s privacy model requires that the relay and app server be operated by separate, non-colluding parties. Cloudflare wants to give customers the best range of options. Before, developers who protected their app servers behind Cloudflare couldn’t use the OHTTP Relay because Cloudflare would see both client metadata and the decrypted contents of requests.
Now, developers can choose. The OHTTP Relay is best if your application servers are hosted off Cloudflare and you’re able to run your own gateway. The OHTTP Gateway is best if your app servers are already behind Cloudflare (on the CDN or Workers), if you’re accepting OHTTP requests from a third party (like Apple’s LiveCallerID), or if you want a managed gateway to minimize latency and operational overhead.
The Growing Appetite
Since Cloudflare launched its OHTTP Relay product, the company has observed a few things:
- There’s a growing appetite among developers for accessible, usable privacy infrastructure.
- Developers of privacy-oriented apps want to bake network privacy into their applications by default.
- Doing so remains harder than it should be.
Building and operating an OHTTP gateway can be tough for customers. The latency hit of a homegrown setup can be significant. Cloudflare’s position as a global edge network gives it a natural advantage.
How the Interaction Works
A typical client-server exchange reveals information about the client. Each packet carries a source IP address, similar to the “from” label on an envelope. App servers can also fingerprint a client based on attributes like supported TLS versions or cipher suites. These signals make it possible to link multiple requests back to the same user.
But what if you want to build an app that really doesn’t know much about its users? Flo Health wanted to build an Anonymous Mode to enable users to access persona. The OHTTP Gateway makes that possible without requiring the developer to run their own infrastructure.
The Road Ahead
Cloudflare’s goal is to expand its OHTTP product suite and make its trusted privacy infrastructure accessible to a broader swath of the Internet. The company believes that protocols like OHTTP can help if they are easy enough to adopt.
| Product | Role | Target Customer |
|---|---|---|
| OHTTP Relay | Blindly forwards requests | Servers hosted off Cloudflare |
| OHTTP Gateway | Wraps and unwraps requests | Servers already behind Cloudflare |
The beta launch is a step toward that goal. The renaming is a cleanup. And the paid add-on model is a bet that developers will pay for privacy that used to require a full rebuild.
Our View
This is a genuine advance. Cloudflare is not just selling a faster CDN or a fancier firewall. It is selling a protocol that makes privacy the default behavior of HTTP itself, and it is making that protocol available as a managed service.
The company has spent years building infrastructure for Apple’s Private Cloud Compute and Flo Health’s Anonymous Mode, both of which use OHTTP. Now it is offering that same machinery to everyone else. The OHTTP Gateway is a practical product with a principled foundation.
The market appetite is real. Developers want privacy, but they don’t want to become cryptographers. Cloudflare is positioning itself as the middle layer that makes OHTTP usable at scale.
The beta is live. The waitlist is open. The product is real.
Source material: “Cloudflare OHTTP gateway,” cloudflare.com.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

