The Workers Web Crypto API now includes a set of post‑quantum algorithms: ML‑KEM‑768, ML‑KEM‑1024 for key encapsulation, and ML‑DSA‑44, ML‑DSA‑65, ML‑DSA‑87 for digital signatures. The addition is opt‑in and brings new methods such as encapsulateBits, decapsulateBits, getPublicKey, as well as SubtleCrypto.supports() and JSON Web Key support with the AKP key type.
Why the new primitives matter
AI pipelines, edge‑deployed services, and any workload that exchanges secrets or validates integrity can now experiment with algorithms that are believed to resist quantum attacks. For a security engineer, the ability to generate and verify post‑quantum signatures directly at the edge removes the need for external key‑management services. Cloud and platform engineers gain a uniform API surface for both classic and post‑quantum operations, simplifying code paths. DevOps and SRE teams can toggle the feature via a compatibility flag without redeploying the entire service, preserving operational continuity.
Enabling the feature in Workers
The algorithms are hidden behind the webcrypto_modern_algorithms compatibility flag. Add the flag to the Wrangler configuration in either JSONC or TOML format:
{
"$schema": "./node_modules/wrangler/config-schema.json",
"compatibility_flags": ["webcrypto_modern_algorithms"]
}
or
compatibility_flags = ["webcrypto_modern_algorithms"]
Once the flag is active, SubtleCrypto.supports() can be used to probe availability before invoking the new methods.
Typical usage pattern
A minimal example shows how two parties can derive the same shared secret using ML‑KEM‑768. The code generates a key pair, encapsulates a secret with the public key, and then decapsulates it on the other side.
const keyPair = await crypto.subtle.generateKey(
"ML-KEM-768",
false,
["encapsulateBits", "decapsulateBits"]
);
if (!"publicKey" in keyPair) {
throw new Error("Expected an ML-KEM key pair");
}
const { sharedKey, ciphertext } = await crypto.subtle.encapsulateBits(
"ML-KEM-768",
keyPair.publicKey
);
const recoveredSharedKey = await crypto.subtle.decapsulateBits(
"ML-KEM-768",
keyPair.privateKey,
ciphertext
);
The same approach applies to ML‑DSA algorithms for signing and verification, using the corresponding sign and verify methods.
Architectural and operational considerations
- Feature flag lifecycle: Because the algorithms are opt‑in, production deployments should guard the flag behind a controlled rollout and monitor for any compatibility regressions.
- Key storage: Generated private keys remain in the Workers runtime. Teams must decide whether to persist them (e.g., in KV or Secrets) or regenerate per request, balancing performance against key‑rotation policies.
- Performance impact: Post‑quantum operations are computationally heavier than classic curves. Benchmarking in the target workload is advisable before scaling.
- Interoperability: The new JWK
AKPtype enables export/import of keys across services that understand the same format, but only if those services also support the algorithms. - Security posture: Adding post‑quantum primitives does not replace existing algorithms; it augments the cryptographic toolbox. Teams should continue to enforce algorithm agility and avoid hard‑coding a single primitive.
Related CloudNinjas coverage: hands-on guides.
What This Means For Practitioners
Practitioners can now prototype quantum‑resistant key exchange and signing directly inside Cloudflare Workers without external libraries. Start by enabling the webcrypto_modern_algorithms flag in a staging environment, verify support with SubtleCrypto.supports(), and run a small performance test. If the results meet latency budgets, consider a phased rollout to production, keeping an eye on key‑management policies and monitoring CPU usage. The addition expands the cryptographic options available at the edge, giving teams a path to future‑proof their security designs while staying within the familiar Web Crypto API.

