CIRCL is an experimental, externally visible Go cryptographic library. Consumers include Cloudflare's Go fork, downstream modules, and external researchers. Every change is security-sensitive. The README disclaims API stability — the…
- UserSpan::deferred() creates a stable request root that can be captured by telemetry contexts before activate() makes the sampling decision. - TelemetryContext::withuserspan() attaches an explicit UserSpan without changing ambient scope; the returned context and handle share the same underlying span. - A deferred root is an inactive span in a shared RwLock. Activation replaces it under the write lock; the first active span wins, while inactive results remain retryable. - Recording and children created before activation are inactive. Contexts that…
This document provides essential information for AI coding agents working in the PartyServer monorepo. PartyServer is a monorepo using npm workspaces with multiple packages:
This file provides guidance for AI coding assistants working with this repository. Always consult Cloudflare documentation when working on this repository. Key topics: Use the gh CLI for GitHub interactions.…
This directory contains a deployable Cloudflare Worker that uses @cloudflare/sandbox/bridge to expose the sandbox HTTP API. It is a thin wrapper — all route handling, authentication, pool management, and OpenAPI…
This directory contains a single-file uv script (main.py) that demonstrates the OpenAI Agents SDK with a Cloudflare Sandbox backend. - Single file: everything lives in main.py with inline # ///…
This directory contains a two-process workspace chat demo: a Python backend and a React frontend. - Framework: Starlette (not FastAPI) served with uvicorn. - Dependencies: managed via uv with pyproject.toml.…
Agent-driven QA test harness for the cloudflare-sandbox-bridge Cloudflare Worker. Uses the OpenAI Agents SDK (openai-agents[cloudflare]) to exercise sandbox exec, file I/O, process management, and session persistence against a production deployment.
This directory is the primary home for container-side control API methods used by the Sandbox Durable Object. Add control operations here. Use service methods directly rather than routing through HTTP…
The bridge is the library layer that powers @cloudflare/sandbox/bridge. It provides a bridge() factory that wraps a user's Worker with sandbox API routes, warm pool management, and authentication — all…
This directory is compatibility-only for the HTTP and custom WebSocket route-based API. Do not add transport-layer capabilities here unless the task explicitly requires HTTP/WebSocket compatibility maintenance. DO-to-container control-channel work belongs…
This directory is the primary home for Sandbox Durable Object to container control-channel code. Use role-based names such as ContainerControlClient, ContainerControlConnection, and SandboxControlAPI. Treat capnweb/RPC as an implementation detail unless…
Agent-facing context. If you're picking up work on this site, start here. Astro-based docs site. The nimbus-docs package provides the integration, content schemas, navigation/sidebar/TOC computation, MDX→markdown rendering, build hooks, and the nimbus CLI. Everything you see in src/ is user-owned and yours to edit. For Cloudflare deploys, also: wrangler.jsonc at project root. Frontmatter must validate against docsSchema from nimbus-docs/schemas. Required: title. The schema includes optional fields for description, sidebar overrides, drafts, dates, edit-link suppression — read the schema for the…
cloudflare-mcp is a token-efficient Model Context Protocol (MCP) server that exposes the entire Cloudflare API (~2,500 endpoints) using Cloudflare's Code Mode pattern. Instead of registering thousands of MCP tools, it uses just two tools (search and execute) that let agents write JavaScript to query the OpenAPI spec and call APIs — fitting all 2,500 endpoints into ~1,000 tokens. Production URL: mcp.cloudflare.com When modifying MCP or OAuth functionality, always check the latest published MCP specification: Node 22+ required.
Chanfana is an OpenAPI 3/3.1 schema generator and request validator for Hono and itty-router on Cloudflare Workers. It uses Zod v4 for schemas and provides auto CRUD endpoints with D1 support. Tests run inside @cloudflare/vitest-pool-workers with a real D1 binding. Config: tests/vitest.config.mts. Formatter/Linter: Biome (biome.json). Key settings: - 2-space indent, 120 char line width, double quotes, always semicolons, trailing commas on multiline - noExplicitAny is OFF — any is used deliberately throughout TypeScript (tsconfig.json): strict: true, verbatimModuleSyntax: true (requires import…
A starter Cloudflare Worker using Chanfana (OpenAPI), Hono, D1, and Zod v4. This is a copyable template — users clone it and build on top. Tests use @cloudflare/vitest-pool-workers with a local miniflare D1 binding. Config: vitest.config.mts. Follow the same conventions as the parent chanfana library: - 2-space indent, double quotes, always semicolons - import type for type-only imports (verbatimModuleSyntax: true) - Classes: PascalCase — endpoint classes named after their action (TaskCreate, TaskList) - Named exports everywhere, no default exports (except…
Browser-side TypeScript library (@cloudflare/speedtest) that measures connection quality against Cloudflare's edge. Powers speed.cloudflare.com. Uses Vitest with two test projects: - Unit tests (tests/unit/*/.test.ts) — pure function tests for utils, config, and Results. Run in Node, no browser needed. Fast. - E2E tests (tests/e2e/*.test.ts) — runs a realistic speed test in a real Chromium browser via Vitest Browser Mode + Playwright. Tests the full library integration (fetch, PerformanceResourceTiming, module loading) with multiple measurement phases (latency, download, upload), loaded latency, AIM scoring,…
@cloudflare/telescope is a TypeScript browser performance testing library and CLI built on Playwright. It launches real browsers (Chrome, Chrome Beta, Canary, Firefox, Safari, Edge), collects HAR files, Web Vitals, and…
@cloudflare/telescope is a TypeScript browser performance testing library and CLI built on Playwright. It launches real browsers (Chrome, Chrome Beta, Canary, Firefox, Safari, Edge), collects HAR files, Web Vitals, and…