Skip to content

Cloudflare OS

Agent workspace for companies, with AI-built mini apps and approval controls on outside actions with side effects

Cloudflare OS workspace with the agent chat beside a six-slide Q3 planning deck it generated

Cloudflare built this agent workspace for its own staff and open-sourced it so other companies can run their own copy. Users ask agents for documents, slide decks and small apps called Gadgets, while Gatekeepers log each call to an outside service and hold side effects until a person approves them.

Each user gets an agent chat preloaded with context about how the company operates, plus a private copy of every app they use. When a user asks for a slide deck, a whiteboard or an issue dashboard, the built-in coding agent writes a Gadget: a small app whose server runs in a sandboxed Dynamic Worker with internet access disabled and whose client runs in a sandboxed iframe. Gadgets can be shared with colleagues like documents and edited together in real time, or published as Blueprints that others copy and change. The agent works with many model providers. Agents reach outside systems only through Gatekeepers. Each one wraps a service API, handles OAuth and limits access to the specific resource a user introduced. When an agent takes an action with side effects, the Gatekeeper simulates the result so the agent can keep working, and the user approves or rejects the queued actions later, in bulk or one at a time. The repository ships Gatekeepers for GitHub, Google, Slack, Notion, Confluence, Supabase and several other services. A router Worker serves the frontend from static assets and forwards API calls to the workshop backend. The backend keeps every workspace in a Durable Object, stores Blueprints in R2 and KV, and renders Gadget exports with Browser Run. Gadgets load through the Worker Loader binding, and the default model catalog runs on Workers AI through AI Gateway. The repository also runs locally on wrangler and workerd with pnpm run-local, which the README presents as a way to try the product rather than a production setup.

Built for: Companies that want a self-hosted AI workspace with sandboxed apps and approval controls for non-technical staff

What you can use it for

  • Give staff an agent chat that knows company context and connected tools
  • Generate slide decks, documents and dashboards from a prompt
  • Build small internal apps that colleagues can edit together or copy as Blueprints
  • Review and approve an agent's GitHub or Google actions after it finishes

Deploy

  • One-click

    requires Workers Paid

    The hosted flow at os.cloudflare.app/deploy deploys a release to a workers.dev address in your account and sets up sign-in and admin emails. For a custom domain, Access sign-in or custom Gatekeepers, use the cloudflare-os-starter repository (pnpm check, then pnpm deploy).

The hosted flow needs no local tools. The starter repository needs Node.js 24.19 or newer, pnpm and a deployment.jsonc filled in with the account ID, hostname, Access audience tag and admin emails.

What it needs to run

  • Browser RunBROWSER
  • KV namespacesAVATARS, BLUEPRINTS, CONTEXT_COLLECTIONS
  • R2 bucketsgadgets-blueprint-content

Also uses

  • Anthropic API (optional): Claude models for the agent, as an alternative to the default Workers AI catalog
  • GitHub OAuth (optional): OAuth app for GitHub sign-in and the GitHub GatekeeperSource
  • Google OAuth (optional): OAuth client for Google sign-in and the Google Gatekeeper (Gmail, Docs, Sheets, Drive, Calendar, BigQuery)
  • OpenAI API (optional): OpenAI models for the agent, as an alternative to the default Workers AI catalog
  • Supabase (optional): OAuth app for the Supabase Gatekeeper, which queries Supabase projectsSource

Good to know

The maintainers call v2 an early access release that still has many rough edges. The email Gatekeeper and a custom domain need the starter repository and a zone on Cloudflare. Many Gatekeepers need OAuth client credentials from each provider (GitHub, Google, Slack and others). Running on your own servers with workerd is not documented yet.

Cost on Cloudflare

Paid Cloudflare plan required

Gadgets run on Dynamic Workers, and Cloudflare states that Dynamic Workers are only available on the Workers Paid plan. Workers AI model calls through AI Gateway, Browser Run, Dynamic Workers, R2 and KV each have included allowances on Workers Paid and are billed by usage beyond them.

Source

The estimate is based on Cloudflare’s documented limits and the app’s configuration. What you pay depends on your usage and plan.

Where this comes from

Listing history

  • Oct 2, 2026 · Cloudflare OS listed
  • Moltworker assistant in Slack answering a route request with a Google Maps screenshot taken through Browser Run

    Cloudflare's proof of concept for hosting the OpenClaw personal AI assistant in a Sandbox container

    Deploy
    One-click
    License
    Apache-2.0
    GitHub stars
    9.9k stars
    Last commit
  • Telegram chat where the bot offers Claude models under /models and identifies a dog in an uploaded photo

    Telegram bot that answers private and group chats with OpenAI, Anthropic or Workers AI models, set up in a Mini App

    Deploy
    One-click
    License
    MIT
    GitHub stars
    3.8k stars
    Last commit
  • Company Brain Proactivity settings: All channels or Only its own channel, with a picker for channel exceptions

    Slack assistant that remembers team conversations, answers from them and acts in GitHub, Linear and Notion

    Deploy
    One-click
    License
    Apache-2.0
    GitHub stars
    963 stars
    Last commit