Cloudflare OS
Agent workspace for companies, with AI-built mini apps and approval controls on outside actions with side effects
Cloudflare OS workspace with the agent chat beside a six-slide Q3 planning deck it generated
Cloudflare built this agent workspace for its own staff and open-sourced it so other companies can run their own copy. Users ask agents for documents, slide decks and small apps called Gadgets, while Gatekeepers log each call to an outside service and hold side effects until a person approves them.
Each user gets an agent chat preloaded with context about how the company operates, plus a private copy of every app they use. When a user asks for a slide deck, a whiteboard or an issue dashboard, the built-in coding agent writes a Gadget: a small app whose server runs in a sandboxed Dynamic Worker with internet access disabled and whose client runs in a sandboxed iframe. Gadgets can be shared with colleagues like documents and edited together in real time, or published as Blueprints that others copy and change. The agent works with many model providers. Agents reach outside systems only through Gatekeepers. Each one wraps a service API, handles OAuth and limits access to the specific resource a user introduced. When an agent takes an action with side effects, the Gatekeeper simulates the result so the agent can keep working, and the user approves or rejects the queued actions later, in bulk or one at a time. The repository ships Gatekeepers for GitHub, Google, Slack, Notion, Confluence, Supabase and several other services. A router Worker serves the frontend from static assets and forwards API calls to the workshop backend. The backend keeps every workspace in a Durable Object, stores Blueprints in R2 and KV, and renders Gadget exports with Browser Run. Gadgets load through the Worker Loader binding, and the default model catalog runs on Workers AI through AI Gateway. The repository also runs locally on wrangler and workerd with pnpm run-local, which the README presents as a way to try the product rather than a production setup.
Built for: Companies that want a self-hosted AI workspace with sandboxed apps and approval controls for non-technical staff
What you can use it for
- Give staff an agent chat that knows company context and connected tools
- Generate slide decks, documents and dashboards from a prompt
- Build small internal apps that colleagues can edit together or copy as Blueprints
- Review and approve an agent's GitHub or Google actions after it finishes
Deploy
One-click
requires Workers Paid
The hosted flow at os.cloudflare.app/deploy deploys a release to a workers.dev address in your account and sets up sign-in and admin emails. For a custom domain, Access sign-in or custom Gatekeepers, use the cloudflare-os-starter repository (pnpm check, then pnpm deploy).
The hosted flow needs no local tools. The starter repository needs Node.js 24.19 or newer, pnpm and a deployment.jsonc filled in with the account ID, hostname, Access audience tag and admin emails.
What it needs to run
- Browser RunBROWSER
- KV namespacesAVATARS, BLUEPRINTS, CONTEXT_COLLECTIONS
- R2 bucketsgadgets-blueprint-content
Also uses
- Anthropic API (optional): Claude models for the agent, as an alternative to the default Workers AI catalog
- GitHub OAuth (optional): OAuth app for GitHub sign-in and the GitHub GatekeeperSource
- Google OAuth (optional): OAuth client for Google sign-in and the Google Gatekeeper (Gmail, Docs, Sheets, Drive, Calendar, BigQuery)
- OpenAI API (optional): OpenAI models for the agent, as an alternative to the default Workers AI catalog
- Supabase (optional): OAuth app for the Supabase Gatekeeper, which queries Supabase projectsSource
Good to know
The maintainers call v2 an early access release that still has many rough edges. The email Gatekeeper and a custom domain need the starter repository and a zone on Cloudflare. Many Gatekeepers need OAuth client credentials from each provider (GitHub, Google, Slack and others). Running on your own servers with workerd is not documented yet.
Cost on Cloudflare
Paid Cloudflare plan required
Gadgets run on Dynamic Workers, and Cloudflare states that Dynamic Workers are only available on the Workers Paid plan. Workers AI model calls through AI Gateway, Browser Run, Dynamic Workers, R2 and KV each have included allowances on Workers Paid and are billed by usage beyond them.
The estimate is based on Cloudflare’s documented limits and the app’s configuration. What you pay depends on your usage and plan.
Where this comes from
- Repositoryhttps://github.com/cloudflare/cloudflare-os
- App websitehttps://os.cloudflare.app
- Documentationhttps://github.com/cloudflare/cloudflare-os-starter
Listing history
- Oct 2, 2026 · Cloudflare OS listed
Similar apps
All AI Assistants & Agents apps
Cloudflare's proof of concept for hosting the OpenClaw personal AI assistant in a Sandbox container
- Deploy
- One-click
- License
- Apache-2.0
- GitHub stars
- 9.9k stars
- Last commit

Telegram bot that answers private and group chats with OpenAI, Anthropic or Workers AI models, set up in a Mini App
- Deploy
- One-click
- License
- MIT
- GitHub stars
- 3.8k stars
- Last commit

Slack assistant that remembers team conversations, answers from them and acts in GitHub, Linear and Notion
- Deploy
- One-click
- License
- Apache-2.0
- GitHub stars
- 963 stars
- Last commit