BetaEditorial Listing

Cloudflare OS

Cloudflare · Cloudflare OS: Open-Source Agent Workspace for Your Company, Built on Cloudflare Workers

Open Cloudflare OS

Cloudflare OS is an open-source (Apache-2.0) agent workspace that a company deploys for its employees: in the browser, people ask an agent to research, write documents, slides, and spreadsheets, work in GitHub and Google Workspace, and build small shareable apps, with every agent's access scoped and logged. It suits IT and platform teams that want to roll out agents company-wide on infrastructure they control. A fully managed version is waitlist-only.

PricingFree
Setuphard
Runs onWeb · Self-hosted
Open sourceYes
DocsYes
CategoryProductivity
Open SourceSelf-HostedEnterpriseGovernanceHuman-in-the-LoopModel-AgnosticDocument WorkflowsAI App BuilderGoogle WorkspaceMCPSandboxCode Execution

Best for

IT, security, and platform teams at companies that already use Cloudflare and want to give every employee a governed agent workspace with scoped access to company systems, curated skills, model choice, and spend controls, on infrastructure they control

Not ideal for

Individuals or small teams who want a ready-made hosted agent with no setup, organizations without staff to configure OAuth apps and maintain the deployment, and companies that need a managed, generally available service today

Who it's for

IT, security, and platform teams rolling out agents across a company, and the employees in engineering, sales, finance, and other functions who use the workspace

Capabilities

  • Browser-based agent workspace for every employee, loaded with company-curated context and skills, with no terminal required
  • Code Mode agent that writes and runs code in an isolated runtime to research, analyze data, and complete tasks
  • Creates documents, slides, and spreadsheets that can stay connected to live data, with export to Excel (.xlsx), CSV, PDF, Markdown, or HTML
  • Builds full-stack apps (Gadgets), each in its own sandboxed Dynamic Worker with SQLite storage and outbound internet access disabled by default
  • Real-time multiplayer sharing of apps, or Blueprints that give colleagues their own modifiable copy without your data or credentials
  • Every app's server methods are callable by the agent too, so a tool you build can be run by the agent on your behalf
  • Capability-based access: agents and apps start with no access, and users grant individual resources such as one repository or one Drive folder
  • Gatekeepers per service hold OAuth credentials, log every read, can mask fields or apply rate limits, and queue side-effecting actions for deferred approval in bulk or one by one
  • Observation tracking: anyone opening shared work must have access to every resource the agent saw to produce it
  • Works in connected GitHub repositories: explore code, edit files, commit, and open pull requests
  • Model choice through Cloudflare AI Gateway (Workers AI by default in the starter deployment; Anthropic, OpenAI, or Google optional), with per-user and per-team spend attribution, budgets, and rate limits
  • Mostly deterministic workflows that run on demand, on a schedule, or on events in connected systems
  • Connects to existing MCP servers by URL or through an organization's Cloudflare MCP Server Portal

Limitations

  • Cloudflare describes the current version as an early-access release that still has many rough edges
  • The fully managed version is waitlist-only; today you deploy and operate it yourself in your own Cloudflare account
  • Deploying to Cloudflare requires Dynamic Workers, which are only available on the Workers Paid plan ($5 per month minimum per account), plus usage-based charges for Workers, Workers AI, and any external model providers
  • Most integrations need their own OAuth client credentials, and the README notes that many providers make this hard to set up
  • Running on your own servers with workerd is marked coming soon, and only low-level workerd configuration is documented so far
  • Word (.docx) and PowerPoint (.pptx) export is announced as coming soon, not available yet
  • The included Slack Gatekeeper is read-only, so agents cannot post to Slack through it
  • The project is not seeking outside contributions beyond small, easily verified fixes
  • The hosted deploy flow runs on a workers.dev address; a custom domain or the email Gatekeeper requires deploying from the starter repository

Use cases

  • Preparing for a customer meeting by pulling account context from connected company systems and turning it into a slide deck to review with the team
  • Building a live issue dashboard for a GitHub repository and sharing it with the team in real time
  • Asking the agent to research a Gmail thread and related Drive documents, then draft a reply that is sent only after you approve it
  • Fixing a bug in a connected GitHub repository and opening a pull request without a local development setup
  • Turning a recurring report into a scheduled, mostly deterministic workflow that only calls a model where judgment is needed
  • Giving non-engineering teams a governed place to use agents instead of handing out API keys to company systems

Our take

Cloudflare OS is less a product to sign up for than a starting point for building your company's own agent platform. Its strongest ideas are in governance: agents get only the resources a user hands them, every read is logged, sharing respects what the agent saw, and side effects queue up for later approval instead of forcing a choice between constant interruptions and auto-approve. That makes it worth a close look for security-minded organizations, especially ones already using Cloudflare Access and AI Gateway. The cost is ownership. You configure OAuth apps per integration, operate and upgrade an early-access codebase, and pay usage-based Workers and model costs. Teams that want a ready-made agent today are better served by Claude Cowork or Perplexity Computer until the managed version moves past its waitlist.

Who should use it

IT, security, and platform teams that want a company-wide agent workspace they can customize and govern, organizations already on Cloudflare Access and AI Gateway, and teams that want employees to build and share small internal tools with agents without handing out API keys.

Who should skip it

Individuals and small teams looking for a hosted assistant they can start using immediately, organizations without engineers to configure integrations and maintain the deployment, and buyers who need a generally available managed service with published pricing.

Strengths

  • Open source under Apache-2.0 and deployed in your own Cloudflare account
  • Capability-based access and per-service Gatekeepers keep each agent to the resources it was given
  • Deferred bulk approval lets agents keep working without auto-approving side effects
  • Model choice and per-user spend controls through AI Gateway
  • Agent-built apps are sandboxed, shareable, and copyable as Blueprints

Weaknesses

  • Early-access software with rough edges
  • Managed version is waitlist-only
  • Requires the Workers Paid plan plus usage-based infrastructure and model costs
  • Setting up OAuth apps for each integration takes real effort

Cloudflare OS pricing

Open source (self-deployed)

Free

  • Apache-2.0 license
  • Deploy to your own Cloudflare account with the hosted deploy flow or the starter repository
  • Can run locally with wrangler and workerd for evaluation (not meant for production)
  • Infrastructure and model usage billed to your own accounts

Managed

Waitlist

  • Fully managed deployment launched from the Cloudflare dashboard
  • Customer chooses the custom domain, Access policies, and AI Gateway
  • Pricing not published

Free tier limits: The software itself is free. Deployments to Cloudflare use Dynamic Workers, which require the Workers Paid plan; the local wrangler setup is intended only for trying it out.

Note: Cloudflare OS has no license fee. A Cloudflare deployment needs the Workers Paid plan ($5 per month minimum per account), which includes 1,000 unique Dynamic Workers per month, after which each Dynamic Worker created costs $0.002 per day, alongside standard Workers request and CPU charges. Workers AI includes 10,000 Neurons per day and then costs $0.011 per 1,000 Neurons, AI Gateway's core features are free, and Anthropic, OpenAI, or Google models are billed by those providers or through AI Gateway Unified Billing (5% fee on credits). Actual cost depends on usage. Verified on Cloudflare documentation on 2026-10-03.

Technical specs

Available models

Workers AI models through AI Gateway (default)Anthropic, OpenAI, and Google models through AI Gateway (optional)

Where Cloudflare OS excels

Rolling out agents to non-engineering teams

Employees work in a browser workspace with shared company skills, while Cloudflare Access controls who gets in and Gatekeepers limit each agent to the resources it was granted, so IT does not have to hand out API keys.

Customer meeting preparation

The agent can pull account context from connected systems and produce a slide deck to review, and a team can reuse the same skill for every meeting instead of rebuilding the process each time.

Internal tools built by the people who use them

A user can ask the agent for a dashboard or tracker, share it with colleagues for real-time use, or publish it as a Blueprint so others can adapt their own copy with the agent.

Cloudflare OS vs. competitors

Cloudflare OS vs. Claude Cowork

Claude Cowork is built into the Claude app on paid Claude plans and completes multi-step work across your files and connectors with Anthropic's models. Cloudflare OS is open-source software you deploy in your own Cloudflare account, with model choice through AI Gateway, capability-scoped Gatekeepers with deferred approvals, and agent-built apps that can be shared or copied as Blueprints. Cowork is ready to use with a subscription, while Cloudflare OS needs setup and operation by your team.

Cloudflare OS vs. Perplexity Computer

Perplexity Computer is a credit-metered agent built into paid Perplexity plans, strongest on cited research and delivered as reports, decks, and apps. Cloudflare OS is a self-deployed workspace centered on company-curated context, scoped access to internal systems, and governance, with costs on your own Cloudflare and model provider bills rather than a per-seat subscription.

Frequently asked questions

What is Cloudflare OS?

Cloudflare OS is an open-source agent workspace that Cloudflare built for its own employees and released publicly. Each person gets a browser-based workspace with company context and skills, an agent that can research, write documents, slides, and spreadsheets, work in tools like GitHub and Google Workspace, and build small sandboxed apps that can be shared with colleagues.

Is Cloudflare OS open source?

Yes. The cloudflare/cloudflare-os repository is licensed under Apache-2.0, and Cloudflare also publishes a starter repository for customized deployments. Cloudflare is not currently seeking outside contributions beyond small, easily verified fixes.

How much does Cloudflare OS cost?

The software is free. Deploying it to Cloudflare uses your own account: it relies on Dynamic Workers, which require the Workers Paid plan ($5 per month minimum), and Workers, Dynamic Workers, and Workers AI usage beyond included amounts is billed by usage. External model providers such as Anthropic or OpenAI bill separately. Cloudflare has not published pricing for the managed version, which is waitlist-only.

Can I use Cloudflare OS without running it myself?

Not yet. As of October 1, 2026, the fully managed option is a waitlist. Today you can deploy it to your own Cloudflare account with the hosted deploy flow or the starter repository, or run it locally for evaluation.

Can I self-host Cloudflare OS outside Cloudflare?

Not in a documented, production-ready way yet. Cloudflare OS runs on workerd, the open-source Workers runtime, and the local wrangler setup uses it for evaluation, but Cloudflare marks deployment to your own servers with workerd as coming soon. Today, production deployments run in your own Cloudflare account.

What are Gatekeepers in Cloudflare OS?

Gatekeepers are service-specific Workers that sit between agents and external services such as GitHub or Google. They hold the OAuth credentials, limit access to the specific resources a user granted, log every read, and handle actions with side effects. When approval is needed, a Gatekeeper simulates the result so the agent can keep working, and the user approves or rejects the queued actions later.

Which AI models does Cloudflare OS use?

Inference goes through Cloudflare AI Gateway. The starter deployment enables Workers AI models by default with no API token, and admins can add Anthropic, OpenAI, or Google models. Cloudflare says the project works with many model providers and self-hosted models.

Cloudflare OS vs Claude Cowork: what is the difference?

Claude Cowork is built into the Claude app on paid Claude plans and runs Anthropic's models on your files and connectors. Cloudflare OS is open-source software a company deploys in its own Cloudflare account, with model choice through AI Gateway, capability-scoped Gatekeepers, and agent-built apps that colleagues can share or copy, at the cost of setting it up and running it yourself.

Integrations & fit

GitHubGoogle Workspace (Gmail, Drive, Docs, Sheets)Slack (read-only)NotionConfluenceLinearSupabaseZoomInfoCloudflare APIEmail WorkersHome AssistantSpotifyMCP serversCloudflare MCP Server PortalsCloudflare AccessCloudflare AI GatewayWorkers AIAnthropicOpenAIGoogle AI models
Good fit forStartup / small team, Enterprise
Pricing modelFree· No cost to start
See pricing on Cloudflare OS →

Alternatives to consider

About Cloudflare OS

Cloudflare built Cloudflare OS for its own staff and open-sourced a rewritten second version on August 5, 2026. Each employee gets a browser-based workspace preloaded with skills and context the company curates, such as its terminology and procedures, so people do not re-explain them to a model for every task. The agent is a Code Mode agent: it does work by writing and running code in an isolated runtime, which lets it search and join data without pulling everything into the model's context. Outputs can be documents, slides, or spreadsheets that stay connected to live data, or full-stack apps (called Gadgets), each running in its own sandboxed Dynamic Worker with its own SQLite storage. Apps can be shared for real-time collaboration, or shared as Blueprints so colleagues get their own copy to modify with the agent. What sets it apart is the security model. Agents and apps start with access to nothing, and users grant specific resources, such as one GitHub repository or one Drive folder. Service-specific Gatekeepers hold the OAuth credentials, log what the agent reads, and handle any action with side effects. Instead of blocking on each approval, a Gatekeeper simulates the action so the agent can keep working, and the user approves or rejects the queued actions later, one by one or in bulk. Cloudflare OS also tracks what an agent has observed, so sharing its output cannot expose data the recipient could not see directly. Model calls go through Cloudflare AI Gateway, where admins choose models (the starter deployment defaults to Workers AI, with Anthropic, OpenAI, or Google optional), attribute spend, and set budgets. Updates announced on October 1, 2026 added GitHub repository work with commits and pull requests, Gmail drafting and sending, and exports to Excel, CSV, PDF, Markdown, and HTML. The tradeoffs: Cloudflare calls this an early-access release with rough edges, someone has to configure OAuth apps for each integration and keep the deployment updated, and costs land on your own Cloudflare and model provider bills. The managed option, where Cloudflare runs it for you, is only open as a waitlist.

Updates from Cloudflare OS

UpdateWaitlist opens for fully managed Cloudflare OS

Cloudflare opened a waitlist for fully managed Cloudflare OS deployments launched from the Cloudflare dashboard, where customers choose a custom domain, Cloudflare Access policies, and an AI Gateway. The open-source version remains available to deploy in your own account.

New FeatureGitHub repositories, Gmail actions, and file exports

Agents can now work in connected GitHub repositories, editing files, creating commits, and opening pull requests. The Google Workspace Gatekeeper can read Gmail threads, create drafts, and send email, and documents, presentations, and spreadsheets export to Excel, CSV, PDF, Markdown, or HTML.

LaunchCloudflare OS open-sourced

Cloudflare open-sourced a rebuilt second version of the agent workspace it uses internally, with Gatekeepers, Gadgets, and Blueprints, along with an example deployment repository.

Are you the founder? Claim this listing →