Cloudflare open sourced a new version of Cloudflare OS, a platform that provides every employee with an AI agent, a workspace, and tools to build small applications. The company initially deployed the first version internally in May, giving thousands of employees access to draft documents, build presentations, and automate repetitive tasks. The open-source release bundles an agent workspace, a security and governance layer built around service-specific 'Gatekeepers,' and a system for shipping personal apps that run as Cloudflare Workers, addressing the security risks of handing agents broad API keys to internal systems.
Cloudflare OS integrates three components into a unified platform. The first component is an agent workspace that grounds each conversation in company-curated context and skills, with an isolated runtime where agents can write and execute code. The second component is a security and governance framework, new in this version, which sits between agents and systems of record. The third component is a layer for personal, modifiable applications that enables a workspace to transform a chat into a document, workflow, or small full-stack application.
Each app an agent builds operates as a real Cloudflare Worker, utilizing Dynamic Workers and Durable Object Facets the company built for this project. The system communicates with the client over Cap'n Web, Cloudflare's open-source object-capability RPC system. Cloudflare stated in its announcement that "if you can build a tool to do a job yourself, agents can use your tool to do the job when you're not there."
Cloudflare CIO Sam Rhea explained the company's security approach for the agent-powered platform. Traditional API keys pose risks because they provide broad, long-lived access that is difficult to constrain or audit. In Cloudflare OS, agents start with access to nothing. When an agent requests a specific resource, a Gatekeeper — a service-specific Cloudflare Worker — mediates the request. The credential never touches the agent or its code.
This model differs from Model Context Protocol (MCP) alone. MCP tells an agent which tools it can call, but not which underlying resources it has actually seen. Cloudflare OS logs every observation and checks a person's access before they can open a workspace or view what an agent produced. The company stated that "the security had to be part of the platform, not something every person building an app or using an agent has to implement correctly."
Cloudflare open sourced the rebuilt version of Cloudflare OS for organizations to deploy and connect to their own internal systems. CEO Matthew Prince wrote that in May, the company gave every one of its thousands of employees access, and people outside engineering started using the platform.
The open-source release provides the code, but the runtime operates on Cloudflare's edge infrastructure. The agents, apps, and governance components all run on Cloudflare's systems. The company noted in its announcement that this architectural choice means the runtime remains controlled by a central entity, despite the open-source availability of the code.
What did Cloudflare release with Cloudflare OS? Cloudflare open sourced a new version of Cloudflare OS, a platform that provides AI agents, workspaces, and app-building tools. The platform includes an agent workspace with isolated runtime, a Gatekeeper security layer that mediates access to internal systems, and a component for building personal apps that run as Cloudflare Workers.
How does the Gatekeeper security model work in Cloudflare OS? Agents in Cloudflare OS start with no access to resources. When an agent requests a specific resource, a service-specific Cloudflare Worker called a Gatekeeper mediates the request. The credential never touches the agent or its code. Cloudflare OS logs every observation and checks a person's access before they can open a workspace or view agent output.
Where does Cloudflare OS run after the open-source release? The open-source release provides the code for Cloudflare OS, but the runtime operates on Cloudflare's edge infrastructure. The agents, apps, and governance components all run on Cloudflare's systems, meaning the runtime remains controlled by Cloudflare despite the code being open-source.
Related News
Perplexity Wins Appeal Against Amazon in AI Agent Lawsuit
Meta Releases Muse Code AI Coding Agent to Challenge Anthropic and OpenAI
Xylo Introduces AI-Powered Mochi Platform for Simplified Web3 Asset Management
Cloudflare Launches Stablecoin Wallets for AI Agent Payments
Amazon Joins Nvidia-Led Open Secure AI Alliance as SAFE Framework Launches