Cloudflare OHTTP gateway
Points and comments are a snapshot, not live.
Cloudflare launches an OHTTP gateway as a managed privacy service.
Cloudflare announced the OHTTP Gateway, a paid add-on for zones, enabling app servers behind Cloudflare to receive OHTTP requests without seeing client IP addresses or TLS fingerprints. The gateway handles HPKE decryption and key management, supporting standard and chunked OHTTP. It requires a third-party relay to maintain OHTTP's separation of trust, and it blocks decryption of requests from Cloudflare Workers or proxied hosts to prevent collusion. Customers can join a waitlist for the closed beta.
What commenters are saying
Skepticism about Cloudflare's neutrality dominates, with some questioning whether the service is a covert intelligence operation or creates a single point of failure. Others note that OHTTP is opt-in and that abuse prevention (e.g., IP-based bans) becomes harder because the gateway strips client identifiers. A few commenters point out that while iCloud Private Relay already uses OHTTP, it shifts trust to Apple, and that self-hosted relays exist (e.g., oblivious.network).