What shipped, and how small the change is
An engineer at an auction house who wanted a private real-time media path used to spend a week on it. On 31 July Cloudflare published a provisioning API that reduces the task to a single POST carrying a relay name, or four clicks in the dashboard under Media, Realtime, MoQ Relay.
What gets provisioned is not a server. Cloudflare describes it as creating an isolated scope across the existing global network, separating namespaces and tracks and defining access permissions, and compares it to adding a virtual host rather than standing up new hardware. Relays become available across the network within seconds, with nothing to deploy, size or load balance. The relay network itself has been running since 2025 on every Cloudflare server across more than 330 cities, coordinating cross-region state through Durable Objects.
The API manages two resource types, relays and tokens, and both creation routes generate default tokens with publish and subscribe permissions and a subscribe-only pair. The stated use case is the one that makes the design legible: a live auction where a bid has to reach every viewer at the same millisecond, and where the bidders must not hold the credential that lets them broadcast.
The support matrix is the risk disclosure
Cloudflare supports draft-14 and draft-16 of MoQ Transport. The IETF working group document is at revision 19, published on 6 July 2026 and carrying an expiry of 7 January 2027. It is an active Internet-Draft authored by engineers from Cisco, Google and Meta, and the milestone for requesting publication to the IESG sits in December 2026. There is no RFC.
Three revisions between the shipping product and the current text is the single most useful number in this launch, and it appears in no announcement. It is not a criticism of Cloudflare. Supporting older drafts is exactly what a relay operator does when client implementations in the field are pinned, and supporting two of them is more conservative than supporting one. But it tells you what you are actually buying. The risk in adopting MoQ this year is not latency and it is not scale; it is interop drift, and the two-draft matrix is the evidence rather than the reassurance.
Internet-Drafts expiring is routine and means only that the document is refreshed, so nothing breaks in January. The date that matters is the December 2026 milestone, because a publication request is the point after which the wire format stops moving. Anything built against draft-16 before then is built against a version the working group has already left behind twice.
Splitting publish from subscribe is the part to copy
A token in this model is a credential granting a set of operations, publish, subscribe, or both, on a single relay. That sentence describes the fix to a failure mode the live-video industry has carried for twenty years.
The legacy design hands out one stream key that grants the right to broadcast, and everything downstream shares it. A key pasted into a contractor's encoder, left in a support ticket or committed to a repository lets whoever finds it transmit to your audience under your name. Separating the publishing credential from the viewing credential removes the class of incident entirely, rather than mitigating it with rotation policies that nobody runs on schedule.
This is worth writing into a requirement document whether or not you ever provision a Cloudflare relay. Ask any real-time media vendor whether viewing and publishing use distinct credentials, whether a viewer credential can be revoked without interrupting the broadcast, and whether credentials are scoped to a single stream rather than an account. A vendor that cannot answer the first question is selling the 2006 architecture with a new transport underneath.
Free at any scale is a price you have not seen
The service is in beta and free to use at any scale during the preview period. That is generous, and it is also an unpriced dependency sitting in a production media path.
A cost you cannot forecast is worse than a high one, because you cannot compare it. An auction house running two hundred sales a year against a free relay has no basis on which to evaluate a competing quote, and no anchor when the preview ends. If the alternative is a self-managed cluster at roughly 4,000 euro a month, or 3,400 pounds for a UK operator, that number is the one to keep in the model even while the relay costs nothing, because it is what the eventual invoice will be judged against.
The switching cost is where this connects back to the draft versions. Your leverage when pricing arrives is how cheaply you can move, and moving means re-pointing a client fleet at a relay that may support a different draft. Free today and pinned to draft-16 is a weaker position than paid today and portable, which is an argument for keeping one non-MoQ path warm through the preview rather than decommissioning it on launch day.
Eleven vendors is a better signal than one launch
At NAB 2026, eleven independent MoQ implementations demonstrated interoperating with each other: Ant Media, AWS, Bitmovin, Broadpeak, CacheFly, Cloudflare, Nomad Media, Norsk, Oracle, Red5 and Synamedia. That is the fact that should move a planning assumption, and it got a fraction of the attention of any individual product announcement.
A protocol with one enthusiastic vendor is a proprietary system with an open specification attached. A protocol where eleven implementations talk to each other in public is a market. MoQ crossed that line before it crossed the RFC line, which is the normal order of events and the reason the missing RFC is a scheduling detail rather than a reason to wait.
The planning conclusion is narrow and worth stating plainly. Budget for MoQ in your next real-time media refresh, specify split publish and subscribe credentials now because that requirement is vendor-neutral and permanent, and do not let a preview-priced relay become the only path your live product can take before the working group stops moving the wire format.
Read next: Post-Quantum Now Needs OpenSSL 3.5 on Your Origin | The Model Changed but the API Name Did Not



