Cloudflare Workers adds post-quantum crypto to Web Crypto
Cloudflare Workers now supports ML-KEM and ML-DSA inside Web Crypto, giving developers post-quantum building blocks without bundling their own cryptography.

Cloudflare has added opt-in support for post-quantum-resistant algorithms to Web Crypto inside Workers, giving developers quantum-safe primitives without bundling a separate cryptography library. The company announced the support on 1 October 2026.
The additions follow the Modern Algorithms in the Web Cryptography API draft and cover ML-KEM-768 and ML-KEM-1024 for key encapsulation, plus ML-DSA-44, ML-DSA-65 and ML-DSA-87 for digital signatures.
What developers actually get
Alongside the algorithms, Workers exposes encapsulateBits(), decapsulateBits(), encapsulateKey() and decapsulateKey(), a getPublicKey() call, a SubtleCrypto.supports() check and JWK import and export for the new algorithms. The feature sits behind the webcrypto_modern_algorithms compatibility flag while the underlying specification is still moving.
In practice, a developer can generate an ML-KEM-768 key pair, encapsulate a shared secret against the public key and decapsulate it with the private key, all through the same crypto.subtle interface that Workers already uses for older algorithms.
Why it matters now
Cloudflare's argument is a familiar one by now. Web Crypto is easy to overlook until it lacks the primitive you need, and experimenting with post-quantum algorithms in a JavaScript runtime has usually meant either giving up or shipping a large JavaScript or WebAssembly cryptography bundle.
Cloudflare says the ecosystem needs to move to post-quantum-resistant algorithms sooner than expected, and that developers need the primitives now to test and improve their integrations. It is careful to describe the new APIs as building blocks rather than a complete migration path, which is the honest framing: ML-KEM and ML-DSA protect specific operations, not an entire protocol.
Our opinion
The interesting thing about this release is not that Cloudflare supports post-quantum cryptography; it has for years, and it has been cheerfully telling everyone else to catch up. The interesting thing is where the support lands. Putting ML-KEM and ML-DSA in Web Crypto, behind a flag, on a runtime millions of developers already use, moves the work out of the hands of a few cryptography specialists and into the hands of anyone writing a Workers function. That is how standards actually spread. There is a caveat worth repeating, because Cloudflare repeats it too: these are primitives, not a migration. A developer who wires ML-KEM into the wrong part of a handshake will have a post-quantum problem and a classic security problem. Still, a compatibility flag is exactly the right amount of ceremony for code the specification has not finished blessing.