Cloudflare tests a gateway that separates requests from users’ IP addresses
Cloudflare has opened a waiting list for a closed beta of OHTTP Gateway, designed to let applications receive requests without seeing a user’s IP address. The system splits the connection between a relay and a gateway operated by different parties. That separation is central to the privacy design: one side sees the network identity, while the other can read the request.
Artificial Intelligence··Midday
A closed beta brings a new privacy gateway
Cloudflare opened a waiting list for a closed beta of OHTTP Gateway on October 2. Oblivious HTTP, abbreviated OHTTP, is a request protocol that separates the client’s network identity from the contents sent to an application. The new managed gateway is intended for applications hosted behind Cloudflare. It works with a relay operated by another party, keeping the two roles apart.[1], [2]
Relay and gateway hold different information
The relay sees a client’s IP address but cannot read the encrypted request. The gateway decrypts the request without seeing that network identity. Privacy depends on the operators remaining separate and not combining their information. Cloudflare’s relay, introduced in 2022 as Privacy Gateway, is being renamed OHTTP Relay. Its customers need a different operator’s gateway; the new Cloudflare gateway instead needs a third-party relay.[1]
The gateway restricts destinations and trust roles
Gateway decrypts requests at a dedicated endpoint, forwards them to the customer’s application and encrypts the response. Destinations are restricted to the customer’s zone. To preserve separation, it refuses requests originating from Cloudflare Workers or hosts proxied through Cloudflare. Hiding the IP address does not remove identifying information from a request’s body: an email address or username sent there remains part of the application’s contents.[1]