ohttp.io
The Independent, Privacy-First OHTTP Provider

Split the request
from the requester.

ohttp.io is the independent Oblivious HTTP provider. Our relay knows who your users are, and can never know what they're doing. Our gateway knows what they're doing, and never learns who they are. That's a strong guarantee; we can operate either an Oblivious Relay or an Oblivious Gateway service for you, on one side of your flow, with high availability, reliable service, and strong guarantees.

We operate a multi-provider resilient anycast network, so your users always reach the most performant point of presence.

message/ohttp-req · chunked HTTP/1.1 → HTTP/3 Privacy Pass ready Free tier · no card

The OHTTP promise
The relay

Knows who you are.
Never what you're doing.

The gateway

Knows what you're doing.
Never who you are.

That's the guaranteed OHTTP promise, and it only holds when the two are different companies.


The protocol

Four roles. Two trust boundaries.
Zero plaintext in the middle.

Oblivious HTTP (RFC 9458) wraps a Binary HTTP message in HPKE encryption and routes it through an independent relay. The relay learns the client's network identity but never the content; the gateway learns the content but never the client. Unlinkability comes from keeping those two roles in different hands.


Why ohttp.io

A relay you don't
have to trust.

Compliance

RFC 9458, to the letter

Binary HTTP (RFC 9292) encapsulated with HPKE (RFC 9180). Key discovery via application/ohttp-keys. Interoperable with every conformant client and gateway.

Blind by design

We couldn't read it if we tried

Payloads are HPKE ciphertext end to end. Per RFC 9458 §6.2 we drop unknown header fields and never inject Forwarded or Via metadata.

Streaming

Chunked OHTTP built in

Incremental message/ohttp-chunked-req/res support for streaming workloads, anonymous LLM inference, agent tool calls, and long responses don't have to buffer end to end.

Abuse control

Privacy Pass, operated

Anonymous token issuance and redemption (RFC 9576–9578) for rate limiting and abuse control, no IP tracking, no CAPTCHAs, no content inspection.

Separation of duties

Never both ends of a flow

RFC 9458 §6 forbids one entity running relay and gateway for the same traffic. We enforce it commercially: a customer may use ohttp.io for one side of a flow, never both.

Gateway tooling

Gateway-in-a-box

Deployable gateway templates, Terraform modules, key-rotation runbooks, and a key-config consistency checker. The whole topology runs in an afternoon, and the gateway stays yours.


Why teams switch

How we compare.

Same full conformance, same instant self-serve signup, then further. Free to start, roughly 7× the requests per dollar at the Scaling tier, a zero-logging guarantee in writing, and features the other hosted relays only link to in their docs.

Capability ohttp.io Other hosted relays
Free tier, no credit card ✓ 100K requests / month ✗ starts at $15 / month
Requests at ~$50 / month 100M 13.1M
Chunked OHTTP (streaming) ✓ from $20/mo Starter tier ✗ mentioned in docs only
Privacy Pass tokens ✓ support at $49, issuance at Pro ✗ explainer page only
Gateway templates & runbooks ✓ Worker template, Terraform, key rotation ✗
Multi-provider anycast network ✓ most performant PoP per user ? not stated
SLA & public status page ✓ 99.9% on paid plans ✗ not advertised
Usage analytics dashboard ✓ bytes, counts, latency by region ✗
Zero logging beyond billing records ✓ in writing ? not stated
Agent-ready (llms.txt, capability file) ✓ ✗

Compare the plans.

Every feature, every tier. Full details on the pricing page.

  Community Starter Scaling Pro Enterprise
Price $0 $20 / mo $49 / mo $399 / mo Custom
Requests / month 50K 5M Unlimited Unlimited Custom
Bandwidth / month 50 GB 150 GB 500 GB 4 TB Custom
Max request size 1 MB 50 MB 100 MB Unlimited (fair use) Custom
Max request rate 2 req/s 25 req/s 150 req/s 1,000 req/s Custom
Regional bursting ✗ 2× regional burst 2× regional burst 2× regional burst Custom
Relay endpoint Shared Dedicated Dedicated Dedicated + capacity Single-tenant
Classic OHTTP (message/ohttp-req) ✓ ✓ ✓ ✓ ✓
Chunked OHTTP (streaming) ✗ ✓ ✓ ✓ ✓
HTTP/1.1 + HTTP/2 ✓ ✓ ✓ ✓ ✓
HTTP/3 (QUIC) ✗ ✗ ✓ ✓ ✓
mTLS to your gateway ✗ ✓ ✓ ✓ ✓
Acceptable Use Policy Fair-use ✓ ✓ ✓ ✓
Auto provider compliance ✗ ✗ ✓ ✓ ✓
Privacy Pass support ✗ ✗ ✓ ✓ ✓
Privacy Pass issuance ✗ ✗ ✗ ✓ ✓
Usage analytics dashboard ✗ ✓ ✓ ✓ ✓
Configurable rate limits ✗ ✗ ✓ ✓ ✓
Region pinning ✗ ✗ ✗ ✓ ✓
Gateway-in-a-box templates ✗ ✗ ✗ ✓ ✓
Uptime SLA ✗ 99.9% 99.9% 99.95% Custom
Support Community Email Priority Dedicated channel Dedicated team
Zero logging

Nothing retained beyond billing records. Client IPs, connection metadata, timing, discarded the moment a request completes.

No collusion

Legally unconnected to every other relay and gateway operator. No shared ownership, no partnerships, no data agreements.

Status & SLA

Public uptime at status.ohttp.io; 99.9% SLA with credits on paid plans.

Conformance

Published RFC 9458 §6.2 conformance statement, versioned with each release.


Developer experience

The whole API is
a single POST.

Clients fetch your gateway's key configuration, encapsulate, and POST the ciphertext to your dedicated relay endpoint. We forward it and stream the encapsulated response straight back. No accounts on the hot path, no payload inspection, nothing to rotate on our side.

Full quickstart →

terminal
# 1. Client fetches your gateway's key configuration
curl -H "Accept: application/ohttp-keys" \
  https://gateway.example.com/.well-known/ohttp-gateway

# 2. Client encapsulates a Binary HTTP request with HPKE,
#    then POSTs the ciphertext to your ohttp.io relay
curl -X POST https://relay.ohttp.io/<your-relay-id> \
  -H "Content-Type: message/ohttp-req" \
  --data-binary @encapsulated-request.bin

# 3. Response comes back as message/ohttp-res -
#    still ciphertext. Only the client can open it.
0
payloads readable by the relay
2
independent operators, by design
1
POST to integrate
100%
RFC 9458 message coverage
Get started

Give your users unlinkability
they don't have to ask for.

Create a relay endpoint in minutes. Free tier included, no credit card required.