Cloudflare opens a closed beta for its OHTTP Gateway
Cloudflare has opened a self-serve OHTTP Gateway in closed beta and renamed Privacy Gateway to Cloudflare OHTTP Relay, giving developers a managed gateway that never sees a client's address.

Cloudflare has opened a closed beta for a self-serve OHTTP Gateway, and renamed its Privacy Gateway product to Cloudflare OHTTP Relay. Together the two changes give developers a managed way to keep client identifiers away from the servers that answer their requests.
Oblivious HTTP (OHTTP) is an IETF standard built for exactly that split. A request travels through two independently operated hops: a relay that blindly forwards encrypted traffic, and a gateway that performs the cryptographic work of decapsulating requests and encapsulating responses. Because the relay never sees the plaintext and the gateway never sees the client's address, no single party learns both who is asking and what was asked.
Why the missing half mattered
Cloudflare launched the relay half in 2022 as Privacy Gateway. Flo Health uses OHTTP for the anonymous mode in its app, and Apple's Private Cloud Compute uses it to disassociate AI inference requests from user identities. But a customer already sitting behind Cloudflare could not also use a Cloudflare-operated relay, because the entire point of OHTTP is that the two hops are run by different parties. Anyone in that position had to build and operate their own gateway, which Cloudflare describes as difficult, latency-heavy and expensive to get right.
That is the gap the beta fills. Customers now choose between using Cloudflare's relay alongside their own gateway, or pairing Cloudflare's new managed gateway with a third-party relay. Cloudflare pitches the second option at teams whose app servers already sit on its CDN or on Workers, at services accepting OHTTP requests from another provider, and at developers who would rather not run the cryptography themselves. Apple's LiveCallerID is the example it leans on for the last of those.
What it costs and when it lands
The OHTTP Gateway arrives this autumn as a paid add-on to a zone, switched on with a few clicks. Cloudflare has opened a form for the closed-beta waitlist, and argues that a managed gateway trims latency by reusing the same infrastructure that carries 1.1.1.1 and iCloud Private Relay, rather than adding a fresh proxy hop in front of it.
Our opinion
Cloudflare is quietly assembling every piece of the privacy stack that an app developer would otherwise have to bolt together alone, and this is the least glamorous, most useful brick yet. The honest caveat is architectural: when the relay and the gateway both sit on one company's network, the separation of trust that OHTTP depends on becomes a promise between two internal teams rather than a fact about two operators. Building the relay first and the gateway second was the right order, and a managed gateway will get privacy features into far more apps than a self-hosted one ever would. The standard is only as strong as the number of genuinely independent hops in front of it.