Cloudflare said on Thursday that developers on its Workers platform can now test post-quantum cryptography natively, adding opt-in support for algorithms designed to withstand attack by future quantum computers.

The addition brings two families of post-quantum-resistant algorithms into the Web Crypto API the runtime already provides: ML-KEM-768 and ML-KEM-1024 for key encapsulation, and ML-DSA-44, ML-DSA-65 and ML-DSA-87 for digital signatures. With them come new operations, including encapsulateBits(), decapsulateBits(), encapsulateKey() and decapsulateKey(), a getPublicKey() helper, a SubtleCrypto.supports() check and JWK import and export for the new algorithms. The company said in a blog post that the APIs “do not provide a full migration path,” but are building blocks for validating an integration ahead of the broader changeover.

Until now, a developer who wanted to try these algorithms in JavaScript had two bad options, Cloudflare said: build on primitives Web Crypto doesn’t have, or bundle a cryptography implementation in JavaScript or WebAssembly. That makes applications bigger and repeats the same work in every downstream library. “Developers need access to these primitives now so they can test, evaluate, and improve post-quantum integrations,” the post said.

Some of that transition is already visible. OpenSSH added support for mlkem768x25519 in 2024. The Internet Engineering Task Force published RFC 9964 for ML-DSA in JOSE and has adopted drafts for post-quantum and hybrid key encapsulation in HPKE, the encryption construction used by protocols such as Oblivious HTTP.

With the primitives in place, Cloudflare sketched what use looks like. A library such as panva/jose can map ML-DSA to Web Crypto and sign JSON Web Tokens by handing the operation to the runtime. The panva/hpke library can select ML-KEM where the runtime exposes it. The point, the company said, is that libraries “can delegate signing to the runtime rather than shipping their own implementation.”

The new getPublicKey() helper pulls a public key directly from a loaded private key, removing code that libraries now carry for that job. And because the API isn’t yet supported everywhere, the post advises libraries running across Workers, Node.js, Deno, browsers and other runtimes to check with SubtleCrypto.supports() before calling it.

There are gaps. ML-KEM-512 is not supported because the version of BoringSSL that Workers runs on does not expose it, and Cloudflare said it would rather start with what the native crypto library offers than maintain a separate implementation. Everything sits behind a compatibility flag, webcrypto_modern_algorithms, set in a project’s wrangler.jsonc file, while the specification remains in draft in a World Wide Web Consortium community group report.

Workers runs on workerd, an open-source runtime built on Google’s V8 engine, and the change adds ML-KEM and ML-DSA to its Web Crypto layer along with Web Platform Tests for the new API surface and updated TypeScript definitions. Cloudflare said the current list of supported algorithms is kept in its developer documentation.