Today, Cloudflare Workers is adding support for post-quantum-resistant algorithms within Web Crypto. These are defined in Modern Algorithms in the Web Cryptography API draft community group report, and include:
- ML-KEM-768 and ML-KEM-1024 for key encapsulation
- ML-DSA-44, ML-DSA-65, and ML-DSA-87 for signatures
encapsulateBits(),decapsulateBits(),encapsulateKey(), anddecapsulateKey()getPublicKey()SubtleCrypto.supports()- JWK import and export for these algorithms
For developers preparing for the post-quantum transition, these opt-in Web Crypto APIs make it easier to experiment with ML-KEM and ML-DSA without bundling a separate cryptographic implementation. They do not provide a full migration path, but rather building blocks that can be used to validate your integration.
This support is available behind the webcrypto_modern_algorithms compatibility flag while the specification is still moving.
Background
Web Crypto is one of those APIs you only notice when it lacks the primitive you need. If you want to experiment with newer post-quantum algorithms in a JavaScript environment, it’s hard. You either cannot build the protocol directly on top of Web Crypto, or you bring your own cryptography implementation in JavaScript or WebAssembly.
Neither option is ideal. They put the burden of selecting and maintaining cryptographic implementations on implementers, who see their applications get larger as they bundle cryptographic code. And this is work that needs to be reproduced for all downstream libraries. As the ecosystem needs to transition to post-quantum-resistant algorithms sooner than expected, we cannot wait for better post-quantum algorithms. Developers need access to these primitives now so they can test, evaluate, and impro
…
Source: Cloudflare Blog (Published: Thu, 01 Oct 2026 13:00:00 GMT). Read the full article on the original site.





