Live Feed/Cloudflare/Fact Record
Cloudflare logo
Cloudflare
feature 96% Confidence Gate September 8, 2026

Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)

Cloudflare has introduced Automatic Key Exchange to proactively probe TLS 1.3-capable origins for supported key agreement algorithms. The system now automatically prioritizes post-quantum cryptographic algorithms during the TLS handshake process.

Verified State Diff

Comparison Mode:
- Previous State
Cloudflare relied on standard TLS handshake negotiation, which often defaulted to classical key exchange algorithms unless specifically configured otherwise.
+ Verified New State
Cloudflare actively probes origins for TLS 1.3 key agreement support and enforces the most secure, post-quantum capable algorithm by default.

Impact & Verification Analysis

WHO IS AFFECTED

Cloudflare customers utilizing TLS 1.3-capable origin servers.

WHY IT MATTERS

This feature reduces handshake latency and provides automated, transparent migration to post-quantum cryptography, significantly improving long-term data confidentiality for enterprise traffic.

Full Fact Overview

Automatic Key Exchange functions as an intelligent negotiation layer between Cloudflare's edge network and customer origin servers. By performing background probes to identify supported key exchange mechanisms, the system eliminates the latency overhead of traditional fallback negotiations. By prioritizing post-quantum algorithms, Cloudflare is hardening the transit layer against future 'harvest now, decrypt later' attacks, effectively upgrading the security posture of the origin-to-edge connection without requiring manual configuration from the customer.

Multi-Source Evidence Chain (1)

Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)Cloudflare
TRACKED ENTITY
Explore all historical Cloudflare changes
View Cloudflare Hub ➔