
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[ The Cloudflare Blog ]]></title>
        <description><![CDATA[ Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet. ]]></description>
        <link>https://blog.cloudflare.com</link>
        <atom:link href="https://blog.cloudflare.com/" rel="self" type="application/rss+xml"/>
        <language>en-us</language>
        <image>
            <url>https://blog.cloudflare.com/favicon.png</url>
            <title>The Cloudflare Blog</title>
            <link>https://blog.cloudflare.com</link>
        </image>
        <lastBuildDate>Thu, 09 Apr 2026 02:55:06 GMT</lastBuildDate>
        <item>
            <title><![CDATA[Automatic Signed Exchanges may dramatically boost your site visitor numbers]]></title>
            <link>https://blog.cloudflare.com/automatic-signed-exchanges-desktop-android/</link>
            <pubDate>Fri, 08 Jul 2022 12:27:53 GMT</pubDate>
            <description><![CDATA[ Automatic Signed Exchanges may dramatically boost your site visitor numbers ]]></description>
            <content:encoded><![CDATA[ 
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4mUZ1vtinqv4i8DyEobO4K/012a7dcbaca4f70e6664d8432d5374e4/pasted-image-0--4-.png" />
            
            </figure><p>It’s been about nine months since <a href="/from-amp-to-signed-exchanges-or-how-innovation-happens-at-cloudflare/">Cloudflare announced</a> support for Signed Exchanges (SXG), a <a href="https://wicg.github.io/webpackage/draft-yasskin-http-origin-signed-responses.html">web platform specification</a> to deterministically verify the cached version of a website and enable third parties such as search engines and news aggregators to serve it much faster than the origin ever could.</p><p>Giving Internet users fast load times, even on slow connections in remote parts of the globe, is to <i>help build a better Internet</i> (our mission!) and <a href="/from-amp-to-signed-exchanges-or-how-innovation-happens-at-cloudflare/">we couldn’t be more excited about the potential of SXG</a>.Signed Exchanges drive quite impressive benefits in terms of performance improvements. <a href="https://web.dev/signed-exchanges/#impact-of-signed-exchanges">Google’s experiments</a> have shown an average 300ms to 400ms reduction in <a href="https://web.dev/lcp/">Largest Contentful Paint (LCP)</a> from SXG-enabled prefetches.  <b>And speeding up your website usually results in a</b> <a href="https://www.thinkwithgoogle.com/marketing-strategies/app-and-mobile/mobile-page-speed-new-industry-benchmarks/"><b>significant bounce rate reduction</b></a> <b>and improved SEO</b>.</p><p><i>faster websites= better SEO and lower bounce rates</i></p><p>And if setting up and maintaining SXGs through the <a href="https://web.dev/signed-exchanges/#tooling">open source toolkit</a> is a complex yet very valuable endeavor, with Cloudflare’s <a href="/automatic-signed-exchanges/">Automatic Signed Exchanges</a> it becomes a no-brainer. Just enable it with one click and see for yourself.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4O7ZL4hRXnDPWWIqrP68Jr/87665ba214b9a23c13c9ac6518433d4d/pasted-image-0--5-.png" />
            
            </figure>
    <div>
      <h3>Our own measurements</h3>
      <a href="#our-own-measurements">
        
      </a>
    </div>
    <p>Now that Signed Exchanges have been available on Chromium for Android for several months we dove into the change in performance our customers have experienced in the real world.</p><p>We picked the 500 most visited sites that have Automatic Signed Exchanges enabled and saw that 425 of them (85%) saw an improvement in <a href="https://web.dev/lcp/">LCP</a>, which is widely considered as the Core Web Vital with the most impact on SEO and where SXG should make the biggest difference.</p><p>Out of those same 500 Cloudflare sites 389 (78%) saw an improvement in <a href="https://web.dev/fcp/">First Contentful Paint (FCP)</a> and a whopping 489 (98%) saw an improvement in <a href="https://web.dev/ttfb/">Time to First Byte (TTFB)</a>. The TTFB improvement measured here is an interesting case since if the exchange has already been prefetched, when the user clicks on the link the resource is already in the client browser cache and the TTFB measurement becomes close to zero.</p><p><b>Overall, the median customer saw an improvement of over 20% across these metrics. Some customers saw improvements of up to 80%.</b></p><p>There were also a few customers that did not see an improvement, or saw a slight degradation of their metrics.</p><p>One of the main reasons for this is that SXG wasn’t compatible with server-side personalization (e.g., serving different HTML for logged-in users) until today. To solve that, today Google added ‘Dynamic SXG’, that selectively enables SXG for visits from cookieless users only (more details on the Google blog post <a href="https://developer.chrome.com/blog/sxg-desktop/">here</a>). Dynamic SXG are supported today - all you need to do is add a `Vary: Cookie’ annotation to the HTTP header of pages that contain server-side personalization.</p><p><i>Note: Signed Exchanges are compatible with client-side personalization (lazy-loading).</i></p><p>To see what the <a href="https://www.cloudflare.com/learning/performance/what-are-core-web-vitals/">Core Web Vitals</a> look like for your own users across the world we recommend a RUM solution such as our free and privacy-first <a href="https://www.cloudflare.com/web-analytics/">Web Analytics</a>.</p>
    <div>
      <h3>Now available for Desktop and Android</h3>
      <a href="#now-available-for-desktop-and-android">
        
      </a>
    </div>
    <p><b>Starting today, Signed Exchanges is also supported by Chromium-based desktop browsers, including Chrome, Edge and Opera.</b></p><p>If you enabled Automatic Signed Exchanges on your Cloudflare dashboard, no further action is needed - the supported desktop browsers will automatically start being served the SXG version of your site’s content. Google estimates that this release will, on average, double SXG’s coverage of your site’s visits, enabling improved loading and performance for more users.</p><p>And if you haven’t yet enabled it but are curious about the impact SXG will have on your site, Automatic Signed Exchanges is available through the <a href="https://dash.cloudflare.com/?to=/:account/:zone/speed/optimization">Speed &gt; Optimization link</a> on your Cloudflare dashboard (more details <a href="https://support.cloudflare.com/hc/en-us/articles/4411075595661-Automatic-Signed-Exchanges-SXGs-">here</a>).</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7B9QWzclctIMHPsOzHUasO/851d54a61126ea21486d96951a200716/image3.png" />
            
            </figure><p></p> ]]></content:encoded>
            <category><![CDATA[Speed & Reliability]]></category>
            <category><![CDATA[Signed Exchanges (SXG)]]></category>
            <category><![CDATA[SEO]]></category>
            <guid isPermaLink="false">6Me41Kp2wjTeaIi9xVwkrk</guid>
            <dc:creator>João Sousa Botto</dc:creator>
        </item>
        <item>
            <title><![CDATA[From AMP to Signed Exchanges, Or How Innovation Happens at Cloudflare]]></title>
            <link>https://blog.cloudflare.com/from-amp-to-signed-exchanges-or-how-innovation-happens-at-cloudflare/</link>
            <pubDate>Tue, 14 Sep 2021 12:59:58 GMT</pubDate>
            <description><![CDATA[ This is the story of how we decided to work with Google to build Signed Exchanges support at Cloudflare. But, more generally, it's also a story of how Cloudflare thinks about building disruptive new products. ]]></description>
            <content:encoded><![CDATA[ <p></p><p>This is the story of how we decided to work with Google to build Signed Exchanges support at Cloudflare. But, more generally, it's also a story of how Cloudflare thinks about building disruptive new products and how we've built an organization designed around continuous innovation and long-term thinking.</p>
    <div>
      <h3>A Threat to the Open Web?</h3>
      <a href="#a-threat-to-the-open-web">
        
      </a>
    </div>
    <p>The story starts with me pretty freaked out. In May 2015, Facebook had announced a new format for the web called Instant Articles. The format allowed publishers to package up their pages and serve them directly from Facebook's infrastructure. This was a threat to Google, so the company responded in October with Accelerated Mobile Pages (AMP). The idea was generally the same as Facebook's but using Google's infrastructure.</p><p>As a general Internet user, if these initiatives were successful they were pretty scary. The end game was that the entirety of the web would effectively be slurped into Facebook and Google's infrastructure.</p><p>But as the cofounder and CEO of Cloudflare, this presented an even more immediate risk. If everyone moved their infrastructure to Facebook and Google, there wasn't much left for us to do. Our mission is to help build a better Internet, but we've always assumed there would be an Internet. If Facebook and Google were successful, there was real risk there would just be Facebook and Google.</p><p>That said, the rationale behind these initiatives was compelling. While they ended with giving Facebook and Google much more control, they started by trying to solve a real problem. The web was designed with the assumption that the devices connecting to it would be on a fixed, wired connection. As more of the web moved to being accessed over wireless, battery-powered, relatively low-power devices, many of the assumptions of the web were holding back its performance.</p><p>This is particularly true in the developing world. While a failed connection can happen anywhere, the further you get from where content is hosted, the more likely it is to happen. Facebook and Google both reasoned that if they could package up the web and serve complete copies of pages from their infrastructure, which spanned the developing world, they could significantly increase the usability of the web in areas where there was still an opportunity for Internet usage to grow. Again, this is a laudable goal. But, if successful, the results would have been dreadful for the Internet as we know it.</p>
    <div>
      <h3>Seeds of Disruption</h3>
      <a href="#seeds-of-disruption">
        
      </a>
    </div>
    <p>So that's why I was freaked out. In our management meetings at Cloudflare I'd walk through how this was a risk to the Internet and our business, and we needed to come up with a strategy to address it. Everyone on our team listened and agreed but ultimately and reasonably said: that's in the future, and we have immediate priorities of things our customers need, so we'll need to wait until next quarter to prioritize it.</p><p>That's all correct, and probably the right decision if you are forced to make one, but it's also how companies end up getting disrupted. So, in 2016, we decided to fund a small team led by Dane Knecht, Cloudflare’s founding product manager, to set up a sort of skunkworks team in Austin, TX. The idea was to give the team space away from headquarters, so it could work on strategic projects with a long payoff time horizon.</p><p>Today, Dane's team is known as the Emerging Technologies &amp; Incubation (ETI) team. It was where products like <a href="https://www.cloudflare.com/teams/">Cloudflare for Teams</a>, <a href="https://1.1.1.1/">1.1.1.1</a>, and <a href="https://workers.cloudflare.com/">Workers</a> were first dreamed up and prototyped. And it remains critical to how Cloudflare continues to be so innovative. Austin, since 2016, has also grown from a small skunkworks outpost to what will, before the end of this year, be our largest office. That office now houses members from every Cloudflare team, not just ETI. But, in some ways, it all started with trying to figure out how we should respond to Instant Articles and AMP.</p><p>We met with both Facebook and Google. Facebook's view of the world was entirely centered around their app, and didn't leave much room for partners. Google, on the other hand, was born out of the open web and still ultimately wanted to foster it. While there has been a lot of criticism of AMP, much of which we discussed with them directly, it's important to acknowledge that it started from a noble goal: to make the web faster and easier to use for those with limited Internet resources.</p><p>We built a number of products to extend the AMP ecosystem and make it more open. Viewed on their own, those products have not been successes. But they catalyzed a number of other innovations. For instance, building a third party AMP cache on Cloudflare required a more programmable network. That directly resulted in us prototyping a number of different serverless computing strategies and finally settling on Workers. In fact, many of the AMP products we built were the first products built using Workers.</p><p>Part of the magic of our ETI team is that they are constantly trying new things. They’re set up differently, in order to take lots of "shots on goal." Some won't work, in which case we want them to fail fast. And, even for those that don't, we are always learning, collaborating, and innovating. That's how you create a culture of innovation that produces products at the rate we do at Cloudflare.</p>
    <div>
      <h3>Signed Exchanges: Helping Build a Better Internet</h3>
      <a href="#signed-exchanges-helping-build-a-better-internet">
        
      </a>
    </div>
    <p>Importantly also, working with the AMP team at Google helped us better collaborate on ideas around Internet performance. Cloudflare's mission is to "help build a better Internet." It's not to "build a better Internet." The word "help" is essential and something I'll always correct if I hear someone leave it out. The Internet is inherently a collection of networks, and also a collection of work from a number of people and organizations. Innovation doesn't happen in a vacuum but is catalyzed by collaboration and open standards. Working with other great companies who are aligned with democratizing performance optimization technology and speeding up the Internet is how we believe we can make significant and meaningful leaps in terms of performance.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3iqW0cbxkc63Sj7XgV0M5A/3a35f9c6ccee04f33542397a450b3aeb/image3-6.png" />
            
            </figure><p>And that's what Signed Exchanges have the opportunity to be. They take the best parts of AMP — in terms of allowing pages to be preloaded to render almost instantly — but give back control over the content to the individual publishers. They don't require you to exclusively use Google's infrastructure and are extensible well beyond just traffic originating from search results. And they make the web incredibly fast and more accessible even in those areas where Internet access is slow or expensive.</p><p>We're proud of the part we played in bringing this new technology to the Internet. We're excited to see how people use it to build faster services available more broadly. And the ETI team is back at work looking over the innovation horizon and continuously asking the question: what's next?</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1HnicbcPep5fNg2CHgNqWI/8e8b8ab1acdee8c4cdba1395ec147482/image1-6.png" />
            
            </figure>
    <div>
      <h3>Watch on Cloudflare TV</h3>
      <a href="#watch-on-cloudflare-tv">
        
      </a>
    </div>
    <div></div> ]]></content:encoded>
            <category><![CDATA[Speed Week]]></category>
            <category><![CDATA[Speed & Reliability]]></category>
            <category><![CDATA[Signed Exchanges (SXG)]]></category>
            <category><![CDATA[Product News]]></category>
            <category><![CDATA[Cloudflare History]]></category>
            <guid isPermaLink="false">5olB9yznoW9WYu15VlOMTj</guid>
            <dc:creator>Matthew Prince</dc:creator>
        </item>
        <item>
            <title><![CDATA[Improve site load times and SEO with one-click support for Signed Exchanges on Google Search]]></title>
            <link>https://blog.cloudflare.com/automatic-signed-exchanges/</link>
            <pubDate>Tue, 14 Sep 2021 12:59:06 GMT</pubDate>
            <description><![CDATA[ Starting today, Cloudflare customers will be able to generate Signed Exchanges (SXG) for Google Search with just one click. ]]></description>
            <content:encoded><![CDATA[ <p></p><p>We’re excited to announce that, starting today, Cloudflare customers will be able to generate Signed Exchanges (SXG) for Google Search with just one click. Signed Exchanges is an open <a href="https://wicg.github.io/webpackage/draft-yasskin-http-origin-signed-responses.html">web platform specification</a> Google developed as a way of verifying a cached version of a website — enabling massively <a href="https://www.cloudflare.com/learning/performance/speed-up-a-website/">faster delivery of a website from a third party</a>, such as Google itself from its search results page, or from a news aggregator that is linking out to other sites.</p><p>The advantage to you as a website owner? Not only will your site load faster when linked to from a site supporting SXG, but because many search engines use page load times in order to determine search results, you should see a very nice <a href="https://www.cloudflare.com/learning/performance/how-website-speed-boosts-seo/">boost in SEO</a>.</p>
    <div>
      <h3>What are signed exchanges, and how do they work?</h3>
      <a href="#what-are-signed-exchanges-and-how-do-they-work">
        
      </a>
    </div>
    <p><a href="https://web.dev/signed-exchanges/">Introduced by Google</a>, a Signed Exchange (SXG) is an open standard delivery mechanism that makes it possible to authenticate the origin of a resource, independent of how it was delivered. This decoupling advances a variety of use cases, such as prefetching, offline Internet experiences, and serving from third-party caches. It does so in a secure and privacy-preserving manner.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4OjZeHJZXsvdoFZoI2cfvj/35372e8e6ea9617382148e7729ac4104/image5-6.png" />
            
            </figure><p>Now, imagine yourself as the ruler of your kingdom with an important message to deliver to all your subjects. You have too many people to reach, so you can’t do it alone. You decide to enlist your trusty knights to ride out with large chests filled with copies of your message. There are villains everywhere that would love to take these messages and modify them for their own nefarious machinations for their own profit.</p><p>You, being the wise ruler you are, have a crafty plan: you have a very special stamp made that can imprint a seal that everyone can recognize, yet no one can recreate. With this wondrous seal, no one can tamper with the messages without breaking the seal and proving the forgery for all to see. Now, your knights can bring these chests to all corners of the kingdom and hand out the messages to the masses, and your subjects can trust that the message came from you. There is a side benefit for your people, too. They can come whenever they want to pick up the message without your watchful eye, so they’re more inclined to read it at their leisure.</p><p>Maybe this is stretching the analogy a bit, but in the case of Signed Exchanges, a cryptographic signature on a digest of the response and headers acts as the tamper proof seal for the message. Fast forwarding our example to the present day: you want to get your newest web experience out to global distribution with the understanding that just about everyone will come through a search engine or aggregator site. Ahead of time, when you publish your content, the search engine <a href="https://www.cloudflare.com/learning/bots/what-is-a-web-crawler/">crawls your site</a> for content, but instead of delivering the raw content, you negotiate the delivery of the signed exchange. (This is accomplished simply through additional “Accept: application/signed-exchange;v=” request headers from the crawler that announces the preference for signed exchanges).</p><p>Then Cloudflare generates the Signed Exchange, using the following process:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/41mWvVJkJcKzFAUhjOexa5/437dfba49fa1cd15ccc8ff5ff425f7ff/image3-7.png" />
            
            </figure><ol><li><p>Cloudflare fetches the original content that you want to sign, including the response headers.</p></li><li><p>An additional Digest header is added that uses Merkle Integrity Content Encoding to support the progressive detection of data modification/corruption.</p></li><li><p>We also strip out headers that don’t make sense within the context of Signed Exchanges (like Connection, Keep-Alive, etc.) as well as security sensitive headers (Set-Cookie, Authentication-Info, etc.).</p></li><li><p>Then these headers, including the digest, along with additional metadata, like request URL, URL of the certificate, hash of the certificate, expiration time, etc., are all chained together into a stream that is used to calculate the final signature.</p></li><li><p>The original content, along with the headers, signature, and a fallback URL are then packed into a final binary for delivery.</p></li></ol><p>This Signed Exchange is then cached and sent to the crawler, which also stores the Signed Exchange. After indexing the content, it can now show up in searches. The user then discovers the link to your content in the search results. The search engine also preloads the signed exchange for your content in the background in the meantime, effectively pre-filling the cache in the client’s browser. This exchange was delivered from the search engine, so no signal has gone to the origin yet. Thus, the search intent of the user isn’t leaked to the origin. Since the exchange is signed and validated against your certificate, the browser trusts the contents and can display the content with attribution to the original URL. Now, when the user clicks on the link to view the contents, it magically loads instantaneously from the local cache.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3fxVcYcnHZHJqUUKXXbr8N/b06a1958c4908c1bfaf22222852a4973/image4-8.png" />
            
            </figure><p>There are many resources on the web available that go into detail about the specific format of <a href="https://wicg.github.io/webpackage/draft-yasskin-httpbis-origin-signed-exchanges-impl.html">Signed Exchanges</a>, so we won’t rehash them here in detail. But one important aspect that isn’t obvious at first glance is the complexity of managing the signing process itself. The many details involve:</p><ul><li><p>The inclusion of the atypical CanSignHttpExchanges extension to your certificate.</p></li><li><p>The requirement to deliver your certificates in a specific CBOR (like binary JSON) format.</p></li><li><p><a href="/high-reliability-ocsp-stapling/">OCSP stapling</a> to ensure the validity of the certificates is required.</p></li><li><p>Renewals of these certificates on a more frequent basis (i.e. requires <a href="https://www.cloudflare.com/application-services/solutions/certificate-lifecycle-management/">automation</a>).</p></li><li><p>Caching of the generated signed exchanges, since they can be expensive to generate.</p></li></ul><p>Luckily, all of these are in Cloudflare’s wheelhouse, since we already have deep expertise in <a href="https://www.cloudflare.com/advanced-certificate-manager/">Certificate Management</a> and <a href="https://www.cloudflare.com/learning/ssl/transport-layer-security-tls/">TLS delivery</a> infrastructure. By partnering with Google on the Signed Exchange implementation, we can ensure the consistency of implementation, but improve the simplicity of integrating the technology with the single push of a button.</p><blockquote><p><i>“Signed Exchanges make the web faster and a better user experience for users, by enabling cross-site prefetching. Site owners have seen clear improvement to Largest Contentful Paint, one of the Core Web Vitals, as well as increased user stickiness. Cloudflare now makes it simple for sites to implement Signed Exchanges and derive these benefits.” —</i> Jeff Jose, Product Manager, Google</p></blockquote>
    <div>
      <h3>Bigger than search alone</h3>
      <a href="#bigger-than-search-alone">
        
      </a>
    </div>
    <p>The broader implication of SXGs is that they make content portable: content delivered via an SXG can be easily distributed by third parties while maintaining full assurance and attribution of its origin. Historically, the only way for a site to use a third party to distribute its content while maintaining attribution has been for the site to share its <a href="https://www.cloudflare.com/application-services/products/ssl/">SSL certificates</a> with the distributor. This has security drawbacks. Moreover, it is a far stretch from making content truly portable.</p><p>In the long-term, truly portable content can be used to achieve use cases like fully offline experiences. In the immediate term, the primary use case of SXGs is the delivery of faster user experiences by providing content in an easily cacheable format. Specifically, <a href="https://web.dev/signed-exchanges/#google-search">Google Search</a> will cache and sometimes prefetch SXGs. For sites that receive a large portion of their traffic from Google Search, SXGs can be an important tool for delivering faster page loads to users.</p><p>It’s also possible that all sites could eventually support this standard. Every time a site is loaded, all the linked articles could be pre-loaded. Web speeds across the board would be dramatically increased. <a href="/from-amp-to-signed-exchanges-or-how-innovation-happens-at-cloudflare/">Matthew’s blog post</a> talks more about this possibility.</p>
    <div>
      <h3>Sign up today</h3>
      <a href="#sign-up-today">
        
      </a>
    </div>
    <p>Automatic Signed Exchanges will be free for all Cloudflare Pro, Business and Enterprise customers as well as for customers using our <a href="https://www.cloudflare.com/automatic-platform-optimization/wordpress/">Advanced Platform Optimization</a> product.</p><p>Sign up for the Automatic Signed Exchange beta waitlist today and after being approved, activating is only one flip of a switch.</p><p>To sign up for the waitlist go to the <a href="https://dash.cloudflare.com?to=/:account/:zone/speed/optimization#sxg-card">Speed page</a> on the Cloudflare dashboard and click on “Join Waitlist” on the Automatic Signed Exchanges (SXGs) card.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/IAJGfwzNRXcjVs5nzhi5W/1abf7168ca5caef0b460ce643bdffb85/image1-7.png" />
            
            </figure><p>We’ll take care of the rest.</p>
    <div>
      <h3>Watch on Cloudflare TV</h3>
      <a href="#watch-on-cloudflare-tv">
        
      </a>
    </div>
    <div></div><p></p> ]]></content:encoded>
            <category><![CDATA[Speed Week]]></category>
            <category><![CDATA[Signed Exchanges (SXG)]]></category>
            <category><![CDATA[Internet Performance]]></category>
            <guid isPermaLink="false">1UzU9qeTQcJmghaVMksLAz</guid>
            <dc:creator>Marc Lamik</dc:creator>
            <dc:creator>Oliver Yu</dc:creator>
        </item>
    </channel>
</rss>