Cloudflare open-sources Cloudflare OS, packaging AI agents with built-in security controls

Cloudflare open-sources Cloudflare OS, packaging AI agents with built-in security controls

N
News Editor
2026-08-05 20:46:03
Cloudflare has released an open-source version of Cloudflare OS, the AI agent platform it first built for internal use. CEO Matthew Prince said the company opened the tool to thousands of employees in May, and usage quickly spread beyond engineering into document drafting, slide creation, and repetitive task automation. The rebuilt version is now being positioned as something any organization can deploy and connect to internal systems. Cloudflare says the key feature is not just agent tooling, but the security model around it. The platform combines an agent workspace, a newly added security and governance layer, and a personal app layer that can turn chats into documents, workflows, or small full-stack apps. Rather than handing API keys directly to people or agents, Cloudflare routes access requests through a Gatekeeper service so credentials never reach the agent or its code. The company also contrasts this design with MCP, saying Model Context Protocol can define tool access but does not show which underlying resources an agent has actually seen. Cloudflare OS logs observations and checks user permissions before workspace access or output review. Still, the article notes that while the code is open source, the runtime remains tied to Cloudflare’s edge infrastructure.

Cloudflare has open-sourced Cloudflare OS, its AI agent platform, after first building and using it internally. CEO Matthew Prince wrote that the company gave access to thousands of employees in May, and use quickly spread beyond engineering as staff used it to draft documents, build slide decks, and automate repeatable work. The company is now releasing a rebuilt version that it says any organization can deploy and connect to its own internal systems.

Cloudflare open-sources Cloudflare OS, packaging AI agents with built-in security controls 2

In its announcement, Cloudflare said, "The security had to be part of the platform, not something every person building an app or using an agent has to implement correctly." The company framed that as the real product at the center of the release.

Three parts make up Cloudflare OS

Cloudflare OS is structured around three components. The first is an agent workspace that grounds each conversation in a company’s curated context and skills, while also providing an isolated runtime where the agent can write and execute code. The second is a security and governance framework, introduced in this version, that sits between agents and systems of record. The third is a layer for personal, modifiable apps, allowing a workspace to turn a chat into a document, a workflow, or a small full-stack application.

Gatekeeper sits between agents and sensitive systems

Cloudflare CIO Sam Rhea described how the company approached security in what he called an agent-powered experiment. Handing API keys directly to people or agents is risky and does not scale well, he said, because those keys often grant broad, long-lived access that is difficult to limit or audit. Cloudflare’s alternative starts agents with access to nothing. When an agent needs a specific resource, it requests it, and a Gatekeeper handles the interaction. Cloudflare describes Gatekeeper as a service-specific Cloudflare Worker. The credential never touches the agent or its code.

Cloudflare argues that this is cleaner than relying on MCP alone. Model Context Protocol can tell an agent which tools it may call, but not which underlying resources it has actually seen. Cloudflare OS logs every observation and checks a person’s permissions before they can open a workspace or view what an agent produced.

Apps produced by agents run as Cloudflare Workers

According to the article, each app built by an agent is a real Cloudflare Worker. Those apps run on Dynamic Workers and Durable Object Facets, which Cloudflare built for the project, and communicate with the client through Cap'n Web, the company’s open-source object-capability RPC system. As the post put it, "If you can build a tool to do a job yourself, agents can use your tool to do the job when you're not there."

Open-source code, but a centralized runtime

The article also notes a point that may leave some users unconvinced. Cloudflare OS is still a Cloudflare product, which means the agents, apps, and governance features it offers all run on Cloudflare’s edge. In that sense, the "open" in open source gives users the code, but the runtime remains under the control of a central entity.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
590

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.