Cloudflare has rolled out a provisioning API for its Media over QUIC (MoQ) network, allowing operators to create isolated relays with distinct access controls for publishers and subscribers. The move shifts MoQ from an open testing environment to a production-ready infrastructure for low-latency media delivery, gaming, and real-time applications without requiring users to deploy or scale dedicated servers themselves.
What the API enables
The new API lets developers provision a relay—a logical boundary for media streams—across Cloudflare’s global network in seconds. Each relay operates as an isolated scope, preventing streams from mixing with those of other applications. Operators can issue separate credentials (tokens) for publishing and subscribing, each with customizable permissions and expiration dates. Tokens are embedded in the connection URL and enforced by the relay when a session opens, ensuring only authorized clients can publish or subscribe to specific tracks.
Provisioning is available via both an HTTP API and the Cloudflare dashboard. A single API call creates a relay and returns two default tokens: one with publish-and-subscribe rights and another restricted to subscribing. Additional tokens can be generated with narrower permissions, such as subscribe-only access for viewers. The API also supports token revocation without disrupting other clients.
Protocol updates and interoperability
Cloudflare’s relays now support both draft-14 and draft-16 of the IETF MoQ Transport protocol. Draft-16 introduces two key features: PUBLISH, which allows a publisher to send a track to a relay before any viewer requests it, and SUBSCRIBE_NAMESPACE, which lets subscribers request all current and future tracks under a namespace with a single subscription. These additions reduce latency and simplify dynamic stream management, such as adding new audio or video renditions during a live broadcast.
Background: Media over QUIC (MoQ) is an emerging IETF standard for publish-subscribe media delivery over QUIC, the transport protocol underlying HTTP/3. Unlike traditional CDNs, MoQ relays do not inspect or modify media content, enabling a single protocol to handle live video, video calls, and low-latency messaging. The standard is developed openly at the IETF, with no single company controlling its specification.
How it differs from existing deployments
Most MoQ relays today run as dedicated servers or processes, requiring manual scaling and load balancing as demand fluctuates. Cloudflare’s approach treats relays as configuration objects rather than compute instances. Provisioning a relay does not spin up virtual machines, containers, or dedicated processes; instead, it creates an isolated namespace across Cloudflare’s existing global infrastructure. This model eliminates the need to select regions, estimate capacity, or configure load balancers, as routing is handled automatically via Anycast.
The provisioning API is documented in an Internet-Draft titled MoQ CDN Provisioning, which proposes a common control plane model for relays across different providers. While the draft is not yet an RFC, Cloudflare aims to foster interoperability by aligning its implementation with the evolving standard.
Availability and limitations
The MoQ relay provisioning API is available now as part of Cloudflare’s MoQ beta, with no usage fees during the preview period. However, the API is expected to evolve, and breaking changes may occur. Cloudflare has invited feedback on potential enhancements, such as finer-grained permissions and support for bring-your-own signing keys. Developers can provision relays, manage tokens, and test draft-16 features using the API or dashboard, with documentation and community support available through Cloudflare’s developer resources.
What to watch
The introduction of isolated relays addresses a key limitation of Cloudflare’s initial MoQ rollout, which lacked authentication and access controls. With these features now in place, the network is positioned for production use cases requiring confidentiality and role separation, such as live auctions, gaming, and enterprise video streaming. The next milestones to monitor include the finalization of the MoQ Transport protocol as an IETF RFC and the adoption of the provisioning draft by other CDN providers, which would further standardize relay management across the industry.
Companies mentioned
Automated pipeline · Cloud & Infrastructure
Synthesized from 1 industry feed on 31 Jul 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No recent or in-pipeline article covers Cloudflare's MoQ relay provisioning API.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers Cloudflare's MoQ relay provisioning API.
- Writing the article — Draft created article_id=379 slug=cloudflare-launches-isolated-moq-relays-with-access-controls
-
Editor review — Approved
- Score: 95/100
- Style compliance: Background block exceeds the 2-4 sentence limit (5 sentences).
- Factual grounding: The draft states 'Cloudflare has rolled out' implying a past event, but the source only confirms availability as of the publication date (31 July 2026). The phrasing should reflect current availability rather than a completed rollout.
- No copied phrasing: The phrase 'isolated scope across the existing global network' closely mirrors the source wording. While the idea is correctly paraphrased elsewhere, this instance should be restructured further.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Reused library image reused image #47
- Linking related stories — Linked 5 relations from 323 candidates
- Publishing — Published cloudflare-launches-isolated-moq-relays-with-access-controls
- Mastodon — Posted https://mstdn.social/@hostingpaper/117015155913687193




Discussion · coming soon
Be the first to join the thread when community discussion launches.