deniz.in

Markets

Weather

Loading weather

· via Cloudflare blog

Cloudflare launches OHTTP Gateway beta and claims fastest provider in 74% of top networks

Cloudflare announced a closed beta of its managed OHTTP Gateway and reported it is now the fastest provider in 74% of the 1,000 largest networks, measured with a newly expanded methodology.

Cloudflare launches OHTTP Gateway beta and claims fastest provider in 74% of top networks

Cloudflare opened its 2026 Birthday Week with two announcements that lean on the same argument: that its global edge network can deliver privacy and speed at once. The company launched a closed beta of a managed Oblivious HTTP (OHTTP) Gateway, and separately reported that it is now the fastest provider in 74% of the world's 1,000 largest networks. Both posts appeared on the Cloudflare blog on 2 October 2026.

A managed gateway for a privacy protocol

According to the Cloudflare blog, OHTTP is an IETF standard that lets application backends receive HTTP requests without learning who sent them. A request passes through two independently operated hops: a relay, which sees the client's IP address and TLS fingerprint but strips them before forwarding, and a gateway, which does the cryptographic work of decapsulating requests and encapsulating responses using Hybrid Public Key Encryption. The app server then handles what looks like plain HTTP. The privacy guarantee rests on separation of trust: no single party should see both the client's identity and the contents of the request.

Cloudflare has run the relay half since 2022, originally under the name Privacy Gateway. The company cites Flo Health, which uses OHTTP for its app's Anonymous Mode, and Apple's Private Cloud Compute, which uses the protocol to disassociate AI inference requests from user identities, as existing adopters.

The gap in the product line was the gateway side. Customers whose origin servers already sat behind Cloudflare could not also use a Cloudflare-operated relay, because Cloudflare would then see both client metadata and decrypted request contents, breaking the privacy model. Those customers had to build and run their own gateway, which Cloudflare says it has learned is hard to operate securely and with acceptable latency, since proxying adds hops and encryption carries real cost.

The new OHTTP Gateway fills that gap. It is entering closed beta now, with general availability as a paid zone add-on planned for this fall and a waitlist open for registration. Cloudflare is also renaming Privacy Gateway to Cloudflare OHTTP Relay, leaving customers two paths: use Cloudflare's relay and run your own gateway, best when origins are hosted elsewhere; or use Cloudflare's gateway with a third-party relay, best when origins are already on Cloudflare's CDN or Workers, when accepting OHTTP traffic from a third party such as Apple's LiveCallerID, or when you want a managed gateway to cut latency and operational overhead.

Because of Cloudflare's anycast approach, the gateway runs on every server in the edge network, which the company says minimises relay-to-gateway latency. For CDN customers, decryption and origin resolution can happen on the same physical hardware.

The performance claim behind it

A separate Cloudflare blog post reports that, as of its August measurements, Cloudflare was the fastest provider in 74% of the 1,000 largest networks, up from 60% at its April update during Agents Week. That covers 150 additional networks where Cloudflare now ranks first, and 38 additional countries. The networks are ranked by estimated user population using APNIC data, and performance is judged by connection time, how long a user's device takes to complete a TCP handshake, aggregated as a trimean of the 25th, 50th and 75th percentiles to dampen outliers.

The data comes from real users. Since 2021, Cloudflare-branded error pages have run background measurements that fetch lightweight files from Cloudflare, Amazon CloudFront, Google, Fastly and Akamai and time each connection from the visitor's browser and network. New this round, Cloudflare is also measuring from Challenge Pages, the Turnstile-based verification screens served across a broad set of websites, currently on a small fraction of eligible free pages, with limits on how far sampling will scale.

Cloudflare itself flags two caveats worth noting. The jump to 74% coincides with the introduction of the new measurement methodology, and in many networks the leading providers are separated by only a millisecond or two of trimean connection time, a gap small enough that ordinary day-to-day variation can flip the ranking. The company says it expects future ranking movements to better reflect real performance changes as the dataset grows.

Why it matters

Privacy protocols live or die on convenience. OHTTP has real adopters, but until now a full separation-of-trust deployment required someone to operate a gateway, complete with HPKE cryptography and the latency that proxying introduces. A managed gateway removes that barrier for teams already on Cloudflare, and the edge-performance numbers are precisely the commercial case for trusting the company with those extra hops.

The 74% figure, however, is self-reported, measured through Cloudflare's own instrumentation, and arrived alongside a methodology change. It is a plausible claim from an operator at this scale, but it is Cloudflare's view of the race rather than an independent benchmark, and anyone weighing CDN options should treat it accordingly.

  • #cloudflare
  • #privacy
  • #networking
  • #cdn
  • #ohttp

Related posts