Recommended Free Tools
Cloudflare OHTTP Gateway is a managed gateway for Oblivious HTTP (OHTTP): it decrypts client-encrypted requests so an application can process them, then encrypts the response for the client. It is not Cloudflare OHTTP Relay, the separate service that forwards those encrypted requests. OHTTP is designed to separate a visitor’s network identity from the request content—but it does not make a request anonymous if identifying details are included in the data.
What Cloudflare OHTTP Gateway does
Oblivious HTTP divides request handling between two roles. A relay forwards an encrypted message without reading its application contents; a gateway decrypts that message and handles or forwards the inner HTTP request. Cloudflare announced its managed Gateway on October 2, 2026, as a paid add-on to a Cloudflare zone entering closed beta. The announcement gave neither a price nor a general-availability date. Cloudflare’s announcement describes the product and its intended deployment options.
That distinction matters because Cloudflare’s OHTTP products have opposite jobs:
| Service or role | What it does | Who operates it |
|---|---|---|
| OHTTP relay | Forwards the encrypted request to the gateway; it does not decrypt the application request. | Cloudflare offers OHTTP Relay as a separate managed service. Its overview labels it Enterprise-only. Cloudflare OHTTP Relay overview |
| OHTTP gateway | Decrypts the request, makes it available to the application, and encrypts the response for the client. | With Cloudflare OHTTP Gateway, Cloudflare operates this role for customers in the announced beta. |
Cloudflare says customers can use its Relay while running their own gateway, or use its new Gateway with a third-party relay. It positions the former for applications hosted outside Cloudflare and the latter for applications already behind Cloudflare, traffic arriving from a third party, or teams that want managed gateway operations. These are Cloudflare’s deployment recommendations, not independent performance findings. Cloudflare’s product announcement
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
- Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
- Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
- 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
- Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.
How an OHTTP request travels
- The client creates an HTTP request for the target and encodes it as Binary HTTP.
- Using the gateway’s public-key configuration, the client encrypts the request with HPKE.
- The client sends the encrypted message to a relay, which forwards it to the gateway.
- The gateway decrypts the request and processes or forwards it to the application.
- The gateway encrypts the response for the client, which receives it through the relay.
This is the protocol specified by IETF RFC 9458, Oblivious HTTP, a Standards Track document published in January 2024. In the intended trust arrangement, the relay can see the client’s network connection and the gateway it contacts, but not the plaintext application request. The gateway can see the decrypted request, but because traffic reaches it through the relay, it does not receive the client’s transport-layer address. The protocol’s privacy separation depends on the relay and gateway being separate operators and behaving as expected. RFC 9458
What OHTTP hides—and what it does not
OHTTP is meant to prevent the application server from directly linking a request to the client’s transport address, while limiting the relay’s view of the request’s contents. That is a separation of knowledge, not a guarantee of anonymity. The IETF describes OHTTP as a way to make multiple requests without the origin being able to link them to the client or identify them as coming from the same client, subject to the protocol’s trust model. RFC 9458
Rank #2
- 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
- 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
- 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
- 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
- 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.
- Information in the request still reaches the application. Names, email addresses, login credentials, cookies, or other identifying details in the payload can identify or correlate a user. Cloudflare advises customers using its Relay to scrub identifying data before forwarding requests. Cloudflare Relay setup guidance
- The relay still observes connection-level information. It can see the connecting device’s IP address, encrypted message boundaries and sizes, and the gateway destination. It can refuse to forward a request. Timing and message size may also support traffic analysis; padding can reduce some such signals but does not eliminate them. RFC 9458
- The gateway must be authorized for the target. OHTTP is not end-to-end authentication of the target server. A client needs to establish which gateway is allowed to serve which target. Key configuration, key replacement, and target restrictions therefore matter. RFC 9458
- It is not a universal replacement for HTTP. Both client and service infrastructure need OHTTP support. The protocol is best suited to applications that do not rely on connection-level state, and it adds cryptographic and network overhead. RFC 9458 notes that deployment topology affects added latency.
Cloudflare Gateway beta, Relay terms, and logging
Cloudflare’s October 2, 2026 announcement describes OHTTP Gateway as a paid zone add-on in closed beta, without publishing a price or general-availability date. It does not establish that the new Gateway has the same eligibility or terms as Cloudflare OHTTP Relay. Cloudflare’s product announcement
Cloudflare’s Relay overview labels that separate service Enterprise-only, and its setup documentation also describes Relay as being in closed beta. Those Relay details should not be treated as Gateway eligibility terms. Relay overview · Relay setup documentation
Rank #3
- 【DUAL BAND AX TRAVEL ROUTER】Products with US, UK, EU Plug; Dual band network with wireless speed 574Mbps (2.4G)+2402Mbps (5G); 2.5G Multi-gigabit WAN port and a 1G gigabit LAN port; USB 3.0 port; Wi-Fi 6 offers more than double the total Wi-Fi speed with the MT3000 VPN Router.
- 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Beryl AX automatically encrypts all network traffic within the connected network. Max. VPN speed of 150 Mbps (OpenVPN); 300 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
- 【OpenWrt 21.02 FIRMWARE】The Beryl AX is a portable wifi box and mini router that runs on OpenWrt 21.02 firmware. It supports more than 5,000 ready-made plug-ins for customization. Simply browse, install, and manage packages with our no-code interface within Beryl AX's Admin Panel.
- 【PROTECT YOUR NETWORK SECURITY】Our pocket wifi, unlike other vulnerable portable wifi hotspot for travel purposes supports WPA3 protocol–Preventive measures against password brute-force attacks; DNS over HTTPS & DNS over TLS–Protecting domain name system traffic and preventing data eavesdropping from malicious parties; IPv6–Built-in authentication for privacy protection, eliminating the need for network address translation.
- 【VPN CASCADING AT EASE】Surpassing the mediocre performance of most VPN routers for home usage, the Beryl AX is capable of hosting a VPN server and VPN client at the same time within the same device, enabling users to remote access local network resources like Wi-Fi printers or local web servers, and accessing the public internet as a VPN client simultaneously.
Cloudflare’s legal disclosure is specifically about Cloudflare OHTTP Relay Logs. It says Cloudflare cannot see the encrypted application HTTP content, but can see the connecting device’s IP address, the application service’s DNS name and IP, and request metadata such as browser type, device operating system, hardware configuration, and timestamp. Cloudflare says it retains those Relay logs for approximately 124 days. The disclosure does not establish that the same details or retention period apply to the new Gateway. Cloudflare OHTTP Relay legal disclosure
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Should a team use Cloudflare OHTTP Gateway?
The choice is mainly about who should operate each role and where the application runs:
Rank #4
- Wi-Fi 6 Mesh Wi-Fi - Next-gen Wi-Fi 6 AX3000 whole home mesh system to eliminate weak Wi-Fi for good(2×2/HE160 2402 Mbps plus 2×2 574 Mbps)
- Whole Home WiFi Coverage - Covers up to 6500 square feet with seamless high-performance Wi-Fi 6 and eliminate dead zones and buffering. Better than traditional WiFi booster and Range Extenders
- Connect More Devices - Deco X55(3-pack) is strong enough to connect up to 150 devices with strong and reliable Wi-Fi
- Our Cybersecurity Commitment - TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement
- More Gigabit Ports - Each Deco X55 has 3 Gigabit Ethernet ports(6 in total for a 2-pack) and supports Wired Ethernet Backhaul for better speeds. Any of them can work as a Wi-Fi Router
- Use Cloudflare Relay with your own gateway if you want Cloudflare to run the relay but can build and operate the gateway yourself. Cloudflare positions this arrangement for applications hosted off Cloudflare.
- Consider Cloudflare Gateway with an independent, third-party relay if you want Cloudflare to manage the gateway role, especially for an application already behind Cloudflare or OHTTP requests received from another party. The relay and gateway still need separate operators for OHTTP’s intended trust separation.
- Do not choose OHTTP solely to conceal identity already in the payload. The application still receives the request content, so payload minimization and careful handling of identifiers remain necessary.
A customer-run gateway also involves operational security work: authenticated key configuration, key replacement or rotation, and restrictions on which targets it can serve. Cloudflare’s public Go reference implementation, privacy-gateway-server-go, is not a turnkey production answer: the project currently lacks key rotation. Cloudflare markets its managed Gateway as reducing operational overhead and latency for suitable deployments, but the announcement does not provide independent benchmark results. Cloudflare’s announcement
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

