Workers Embrace Post-Quantum Crypto
Alps Wang
Oct 1, 2026 · 1 views
Post-Quantum Primitives Arrive
Cloudflare's integration of ML-KEM and ML-DSA into Workers' Web Crypto API is a timely and impactful development. By providing direct access to these post-quantum cryptographic building blocks, they are significantly lowering the barrier to entry for developers preparing for the inevitable cryptographic transition. This move is particularly noteworthy because it avoids the need for developers to bundle external cryptographic libraries, thus reducing application bloat and maintenance overhead. The availability of these primitives via a compatibility flag is a sensible approach, allowing for experimentation and feedback while the underlying specifications are still evolving. The inclusion of helper functions like getPublicKey() and the SubtleCrypto.supports() method further enhances usability and encourages robust, cross-runtime development practices.
However, it's crucial to acknowledge the limitations. As the article rightly points out, this is not a complete migration path but rather a set of building blocks. Developers will still need to integrate these primitives into higher-level protocols like HPKE or other security mechanisms. The increased key and signature sizes inherent to these post-quantum algorithms will also present challenges for bandwidth and storage, a reality that developers must plan for. Furthermore, the current opt-in nature via a compatibility flag means that widespread adoption will require developers to actively enable it, and the eventual transition to a default setting will depend on specification stability and community consensus. While BoringSSL is a robust foundation, the exclusion of ML-KEM-512 due to its unavailability in the specific BoringSSL version used by Workers is a minor point of concern, though understandable given the implementation strategy.
Key Points
- Cloudflare Workers now supports ML-KEM (key encapsulation) and ML-DSA (digital signatures) via the Web Crypto API.
- These are post-quantum resistant cryptographic algorithms, crucial for future-proofing applications.
- Developers can experiment with these primitives without bundling separate cryptographic implementations.
- New APIs include
encapsulateBits,decapsulateBits,getPublicKey, andSubtleCrypto.supports. - Support is opt-in via the
webcrypto_modern_algorithmscompatibility flag. - This enables easier integration with libraries like
joseandhpkefor JWT signing and hybrid encryption. - While not a full migration path, these are essential building blocks for post-quantum transition.
- Increased key and signature sizes are an inherent consequence of these algorithms.

📖 Source: Support for modern cryptographic algorithms in Workers
Related Articles
Comments (0)
No comments yet. Be the first to comment!
