Cloudflare operates a network that protects websites, delivers online content and runs applications closer to their users. Businesses connect websites and internal systems to its services to filter malicious traffic, control access and improve performance, with security and computing running on shared infrastructure. Developers combine application code, object storage and databases with the network used for content delivery and traffic protection. Cloudflare earns revenue from subscriptions and usage charges, with free plans for basic features and negotiated contracts for larger organizations. Cloudflare was founded in 2009 and is headquartered in San Francisco, California.
Company Size
1,001-5,000
Company Stage
IPO
Headquarters
San Francisco, California
Founded
2009
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Competitive salaries
Take-what-you-need paid vacation policy
Comprehensive health plans and benefits
Paid maternity and paternity leave
Commuter and ride share options
Returnships
Cloudflare is acquiring Deno, the startup behind the programming runtime of the same name, it announced Friday. Financial terms were not disclosed. Cloudflare will use the deal to improve its Workers programming model and platform, which lets customers build and run software on its network. Kenton Varda, principal engineer for Cloudflare Workers, said Deno's recently launched open source Workers implementation, celld, "delighted" the team. Varda rejected a "popular theory" that Cloudflare made Workers different to create "lock-in." He said being open source and giving people an escape hatch "is good business." Deno co-founder Ryan Dahl, who also created Node.js, said the team is "joining Cloudflare to make the Workers programming model a mainstream way to build servers." Deno had raised $26 million, including a Series A led by Sequoia.
Cloudflare announces Web Search API integration for AI Gateway in partnership with Ceramic.ai, Exa, and Linkup. 6 hrs ago - 6 October 2026 Siti Muinah OvFile Reporter Cloudflare has announced a major expansion of its artificial intelligence infrastructure, introducing a new Web Search API designed to bridge the gap between static AI models and real-time internet data. By integrating live web search directly into its AI Gateway, the company aims to solve a fundamental inefficiency in how autonomous AI agents interact with the web, while simultaneously setting a new standard for transparent and ethical bot crawling. The initiative launches with foundational support from prominent web search providers Ceramic.ai, Exa, and Linkup. This collaboration is designed to equip developers with the tools necessary to ground AI responses in live information, moving away from outdated knowledge cutoffs and erratic URL-guessing behaviors. Overcoming the inefficiencies of AI web access. To understand the significance of the new Web Search API, industry experts point to a common, albeit inefficient, practice currently employed by many AI agents. When an agent is tasked with retrieving information from a live web page, it typically attempts to guess the target URL before making a tool call to execute a curl command. This speculative approach frequently results in errors, most notably the dreaded 404 Not Found response, triggered when the agent's algorithmic guess misses the mark. Relying on random URL enumeration is not only computationally wasteful but also hinders the reliability of AI applications that require precise, up-to-date data. Recognizing this limitation, Cloudflare's new offering introduces a more deliberate mechanism. By mirroring the human approach to information retrieval - starting with a search engine query - the Web Search API enables agents to query the internet for relevant data systematically. This injects fresh, structured snippets directly into the model's context layer, grounding its responses in real-time information rather than relying solely on pre-trained parameters. Addressing the knowledge cutoff challenge. Artificial intelligence models are traditionally constrained by their training data, which is frozen at a specific point in time. This knowledge cutoff date creates significant barriers for users attempting to engage models in discussions regarding recent events, shifting application programming interfaces, or fast-evolving news cycles. By embedding the Web Search API directly into the inference pipeline, developers can establish a dynamic context layer for their applications. Rather than operating in a historical vacuum, models can access live information seamlessly. For instance, developers building applications utilizing Cloudflare developer tools often encounter challenges keeping pace with rapid product updates and feature rollouts, such as those announced during Cloudflare's annual Birthday Week celebrations. With the new integration, developers and their AI agents can instantly retrieve the latest documentation and release notes, facilitating faster and more accurate application development. Elevating industry standards for responsible web crawling. Beyond technical efficiency, Cloudflare's announcement places a strong emphasis on the ethical dimensions of web crawling and data consumption. The company has long advocated for transparency, honesty, and strict adherence to established bot rules and preferences, asserting that website owners must maintain meaningful control over how their digital content is utilized. In alignment with these principles, all launch partners for the Web Search API have committed to meeting Cloudflare's rigorous bot crawling standards. Under this agreement, the crawlers utilized by search providers must strictly comply with Cloudflare's publicly stated requirements for verified bots, as outlined in the platform's developer documentation. Furthermore, any web search responses generated through the API must include a direct link to the original location of the crawled content. Industry observers note that these rules represent a positive step toward maintaining a fair internet ecosystem. By requiring crawlers to identify themselves, respect robots.txt protocols, and properly attribute sources, the partnership ensures that content creators retain visibility and control over their intellectual property while still participating in the growing AI economy. Deep integration with AI Gateway. The new Web Search API is anchored within Cloudflare's AI Gateway, a flagship control plane designed to provide unified billing, observability, security, and access controls for AI applications. By routing web search through this existing infrastructure, developers can manage their AI workflows within a single centralized dashboard. Requests made to the Web Search API are automatically logged alongside standard AI Gateway observability data, and search queries draw directly from the user's existing AI Gateway credit balance. To address data privacy concerns, Cloudflare has committed to identifying partners that support Zero Data Retention policies, ensuring that sensitive information is not stored by search providers. Additionally, the service is offered directly at the partners' list API prices without any added platform markups. The infrastructure also accommodates flexible integration patterns. Organizations utilizing Bring-Your-Own-Key configurations for model inference can similarly apply their existing organizational setups to web search providers. For backend systems, mobile applications, and external services, developers can utilize a standard REST endpoint by passing an AI Gateway authentication token and specifying their preferred provider in the payload. For developers building natively on Cloudflare Workers, the integration requires minimal code through a dedicated worker binding. This allows agents to execute search queries and process results with high performance and low latency. Looking ahead, Cloudflare is developing native Server Tools directly within AI Gateway, which will soon eliminate the need for developers to manually define tools and orchestration harnesses, with web search slated as one of the first built-in offerings. The Web Search API is available now for developers seeking to enhance their AI agents with grounded, real-time intelligence. Interested parties can access implementation details through the official Cloudflare developer documentation or test the capabilities directly within the AI Playground using an active AI Gateway account and key. Related topics.
Cloudflare launches 'Streamline' developer playground to bring custom video Processing pipelines to its platform. 3 hrs ago - 6 October 2026 Nila Kartika Wati OvFile Reporter Cloudflare has announced the release of Streamline, a new developer playground and open-source architecture that demonstrates how developers can build custom, bespoke video processing pipelines directly on Cloudflare's Developer Platform. While Cloudflare Stream has long operated as a powerful, out-of-the-box broadcasting platform for a wide variety of customers, advanced use cases - such as rendering dynamic annotations on live streams or generating alternate video versions with burned-in subtitles - traditionally required external media infrastructure. Streamline bridges this gap by illustrating how developers can leverage Cloudflare Workers, Containers, and modern media protocols to modify video streams in real-time and instantly publish the resulting output as a new livestream or hosted video. Bridging the gap for custom media workflows. Processing video streams efficiently requires a durable, long-running computational environment capable of executing specialized, compiled code with predictable memory and CPU allocations. Because video streams often run continuously for minutes or even hours, the underlying media processes must maintain a lifecycle completely independent of the initial web request that triggered them. Modern web applications require the flexibility to start a processing pipeline, transmit input data, inspect the ongoing process, and eventually shut it down without keeping a single HTTP connection open for the entire duration of the stream. Cloudflare's suite of developer primitives provides the foundational blocks necessary to solve this architectural challenge. Containers offer long-lived runtimes ideally suited for intensive media processing tasks, while Durable Objects facilitate precise session orchestration. Furthermore, Cloudflare Workers act as the central nervous system for control signaling and monitoring. By combining these tools, developers can build robust media engines that operate independently of transient client connections. Core architecture of a Streamline deployment. A standard Streamline deployment is divided into two primary architectural components: the Media Engine, which is responsible for media input, output, and processing, and the controlling Application, which creates, configures, monitors, and terminates media sessions. The Media Engine is hosted inside a container and manages all real-time media ingestion and distribution. It possesses the capability to pull RTMPS playback streams over the network from a Stream Live input and publish the processed RTMPS output back to another Stream Live input. Additionally, it can ingest video-on-demand content by pulling Cloudflare Stream HLS manifests and their corresponding segments, or accept direct video feeds supplied by the controlling application, such as live webcam feeds. To provide real-time feedback, the engine can also publish preview video feeds over an outbound WebSocket connection to a Durable Object relay, allowing monitoring interfaces to connect seamlessly. The controlling application, built primarily using Cloudflare Workers, can take the form of a full-stack browser application, an automated agent, or an embedded internet-of-things system. During local development, the architecture simplifies significantly: the container runs as a local Docker instance without requiring Durable Objects, and authentication is bypassed to allow direct local connections. However, when deployed to production on Cloudflare, authorized users or automated agents can interact with the Worker API to spin up isolated container instances, manage their lifecycles automatically, and route media inputs and outputs directly through Cloudflare Stream. Container lifecycle and session management. Managing long-running media sessions on a serverless-adjacent platform requires specialized lifecycle controls. When a controlling Worker application initiates a media processing session, the underlying container continues to execute processing tasks even if the user or application temporarily disconnects and reconnects. To prevent abandoned sessions from running indefinitely, the system enforces a maximum duration limit, ensuring that every session is eventually terminated. While a media session is actively processing, that specific container instance remains dedicated to the task and is unavailable for other workloads. Standard Cloudflare Containers are designed to scale down to zero and enter a sleep state automatically if they do not receive incoming requests within a designated time window. For video pipelines, however, processing must persist even in the complete absence of incoming requests. To achieve this, developers implement custom logic by overriding the activity expiration callback on the container. As long as a session remains valid and active, the container periodically renews its activity timeout; otherwise, it safely destroys itself to free up system resources. Defining and executing video Processing pipelines. Streamline exposes a streamlined, abstract API that shields developers from the low-level complexities of the underlying Go-based media harness and Durable Object storage. Through packages exported by Streamline, applications can instantiate sessions and trigger pipelines using structured JSON configuration objects. These configurations define the precise sequence of operations applied to a video stream. For instance, developers can configure a pipeline to ingest an RTMP broadcast from a live stream feed, apply a semi-transparent overlay image, and re-encode the stream before sending the modified output to another RTMP destination for recording or broadcasting. Similar pipelines can be constructed to ingest video-on-demand content via HTTP Live Streaming (HLS), automatically extract embedded closed caption subtitles, render them as visible text burned directly into the video frames, and broadcast the resulting subtitled video in real time. For rapid prototyping and development, applications can also stream video data directly into Streamline from local sources such as webcams or automated camera feeds. This proves particularly valuable for scenarios involving computer vision analysis or the composition of multiple camera angles into a single unified view. By utilizing WebSockets for low-latency preview delivery, developers can inspect the output of their custom pipelines instantly as fragmented MP4 data is pushed from the container through the Durable Object relay. Security considerations and isolation. Because media infrastructure often handles sensitive broadcast keys and proprietary content, security is integrated into the core design of Streamline rather than treated as an afterthought. The system ensures that only verified and authorized users can create new sessions or take control of existing ones, and that individual sessions remain strictly isolated from one another. Stream RTMPS input and output keys are treated as critical secrets, stored securely as Worker secrets or write-only shared overrides within Durable Object storage, and are never exposed to browser storage or returned through settings APIs. Access to the deployment is strictly gated using Cloudflare Access integration. The Worker verifies the identity of the principal before accepting any control requests, binding the active session exclusively to that verified user. Furthermore, resource consumption is bounded by strict concurrency, media, and session limits, preventing any single user from monopolizing system capacity or interfering with another user's active workflows. Open source release and future directions. Cloudflare has released both the Streamline container runtime and the example Worker application as open-source repositories on GitHub, accompanied by a fully functional public playground deployment. The released example application features an Astro-based web frontend demonstrating common use cases such as visual filters, image overlays, subtitle rendering, and picture-in-picture effects, complete with performance metrics and system tracing tools for debugging. The introduction of Streamline highlights the immense potential of combining managed media services like Cloudflare Stream with low-level developer primitives. While the initial release relies on container CPU capacity for video processing - which can introduce bottlenecks at higher resolutions or frame rates - Cloudflare plans to work alongside the developer community to expand the architecture. Future explorations may include support for computer vision pipelines, hardware-accelerated media processing, ultra-low-latency real-time experiences utilizing next-generation protocols like WebRTC and Media over QUIC (MoQ), and ultimately native video encoding and decoding primitives within Cloudflare Workers. Related topics.
Cloudflare introduces CLI for AI agents, sunsetting Wrangler. * Renato Losio Cloud Expert | AWS Data Hero Follow us on. Cloudflare recently launched the open beta of cf, a new open-source, agent-focused command-line interface for interacting with Cloudflare services through a unified CLI. Written in TypeScript, it provides structured output and command discovery to make Cloudflare's APIs easier for both developers and AI agents. The hyperscaler argues that introducing a new CLI avoids conflicts with LLMs' learned behavior around Wrangler, allowing cf to adopt agent-focused design changes without the compatibility constraints of an established tool. Matt Taylor, senior product manager at Cloudflare, and Samuel Macleod, senior systems engineer at Cloudflare, explain why a new CLI was needed: Wrangler was hand-built with each product team contributing and taking their own approach to their command developer experience. Enforcing patterns across teams was virtually impossible, even across our ~280 command paths. We had inconsistent terminology across d1 info, hyperdrive get, workflows describe as each team came up with their own practices at different times. Released under either the Apache License 2.0 or MIT license, the cf CLI is designed for agent-driven development, with command discovery, JSON output optimized for both humans and agents, and a new TypeScript-based cloudflare.config.ts configuration format. It also makes Vite the default development environment, providing a consistent local development experience and plugin support. Using Cloudflare's OpenAPI schemas as the source, cf can cover more than 3000 API operations, compared with roughly 280 functions built into Wrangler. Taylor and Macleod add: We wanted to both standardize what we had and make a massive expansion, all at once. Forge - Cloudflare's new unified API generation pipeline - enabled us to do this, building on the idea of generating our CLI commands directly from the API schema that powers our API documentation and SDK generation. In a popular Hacker News thread, community reaction has focused in particular on the choice of TypeScript for a CLI, with discussion around startup time, portability, and dependency management. User slowin comments: I don't understand why this is written in TypeScript. This is a great example of how agents can write code (I'm sure they wrote `cf`), yet having fundamental computer science knowledge is still critical. Do not force your users to manage the dependencies of your CLI. Do write your CLI in a compiled language. Cloudflare argues instead that TypeScript makes configuration easier for both humans and agents by providing type safety and LSP support, enabling agents to understand and modify configurations more accurately. The authors contrast this with TOML and JSONC, where schema information is less accessible to agents, and say programmatic configuration can also reduce configuration duplication. Ashish Ganda notes on LinkedIn: Cloudflare's new cf CLI outputs JSON by default. Not a table. You have to ask for the table (...) Tables are for eyes. JSON is for parsers. Cloudflare makes JSON the default output format, allowing agents to filter and transform the output into the format required by human users while avoiding the table output used by default in Wrangler. The company plans to deprecate Wrangler after the cf open beta ends, release a final major Wrangler version directing users to cf, and provide 18 months of maintenance support to allow migration. Renato Losio. Renato has extensive experience as a cloud architect, advisor, and cloud services specialist. Currently, he lives in Berlin and works remotely as a principal cloud architect. His primary areas of interest include cloud services and relational databases. He is an editor at InfoQ and a recognized AWS Data Hero. You can connect with him on LinkedIn.
Cloudflare's Birthday Week 2026: security & developer innovations. This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy Key points * " New Cloudflare features enhance security and developer capabilities across the internet. * " Cloudflare users, developers, and internet infrastructure stand to benefit from these advancements. * " Security professionals should evaluate and integrate Cloudflare's announced security and platform enhancements. Cloudflare's Birthday Week 2026 marked a significant series of announcements, emphasizing the company's commitment to evolving internet infrastructure, security, and developer tools. With automated traffic now surpassing human activity, these initiatives aim to address the challenges and opportunities presented by an agent-driven internet and the advent of quantum computing. The updates range from foundational cryptography and application security enhancements to new open-source projects and developer platform expansions, all detailed in their wrap-up blog post. Advancing internet security with post-quantum & AI. Cloudflare has outlined a strategic vision for securing the future internet, focusing heavily on the post-quantum transition and leveraging artificial intelligence for defense. A major announcement was Cloudflare's intention to become a public certificate authority (CA), aiming to enhance the resilience of automated certificate issuance. Complementing this, the company plans to issue Merkle Tree Certificates, designed to make post-quantum authentication practical by mitigating the large certificate and handshake costs typically associated with such cryptography. Cloudflare post-quantum migration strategy. The company is actively working towards completing its Cloudflare post-quantum migration strategy by 2029. To aid this complex transition, Cloudflare introduced CryptoLabe, an AI-powered tool designed to find and classify cryptography within its extensive codebase. This systematic approach helps identify all cryptographic implementations requiring updates. Furthermore, Cloudflare contributed to developing an IETF extension to prevent quantum downgrade attacks against IPsec, ensuring that attackers cannot force a downgrade to less secure cryptographic protocols during tunnel negotiation. For customers, HTTP Analytics, Log Explorer, and Logpush now provide visibility into whether requests negotiated post-quantum key exchange, offering crucial evidence for security and compliance reporting. Enhancing application security with AI. Recognizing the shifting landscape of application security, Cloudflare unveiled Application Profiles. This feature learns the expected structure of legitimate HTTP requests, enabling customers to enforce positive security models by identifying and blocking deviations from established valid application traffic. To demonstrate and improve their defenses, Cloudflare subjected its Web Application Firewall (WAF) to testing with frontier AI models. This adaptive AI red-team system successfully uncovered WAF detection gaps across six attack categories, directly leading to improvements in normalization and managed rules for customers. These AI-driven WAF improvements Cloudflare has implemented are critical for countering sophisticated, AI-generated attacks. Empowering developers and open source initiatives. Cloudflare also reinforced its commitment to open source and expanded its developer platform, introducing tools aimed at streamlining development for both humans and agents. Streamlining development with new tools. Key among the developer tools is cf, an agentic CLI that mirrors the entire Cloudflare API, offering JSON-first output and typed configuration for consistent command-line interaction. Forge was introduced as an open-source, pluggable pipeline for generating SDKs, CLIs, and documentation directly from API definitions. These tools are designed to improve efficiency for developers working within the Cloudflare ecosystem. Open-Source contributions and EmDash plugin security. Significant open-source contributions include EmDash, an Astro-based serverless CMS presented as a spiritual successor to WordPress. EmDash addresses common EmDash plugin security concerns by running plugins in isolated Worker sandboxes with explicitly approved capabilities, mitigating many traditional plugin-related vulnerabilities. Cloudflare also acquired VoidZero, integrating its team and delivering over 80 releases across the Vite ecosystem, and open-sourcing its previously commercial Void platform. Other initiatives include Vinext 1.0 for running Next.js applications on Vite and enhancements to Kitesurf, a Workers-based browser for agents. Recommendations for security professionals. Security professionals and organizations leveraging Cloudflare's services should: * Evaluate new security features: Investigate and implement Application Profiles to bolster positive security enforcement for web applications. * Monitor post-quantum progress: Stay informed about Cloudflare's post-quantum migration efforts and begin assessing your organization's readiness for quantum-resistant cryptography. * Leverage new observability: Utilize HTTP Analytics, Log Explorer, and Logpush for visibility into post-quantum key exchange negotiation to inform security and compliance reporting. * Explore developer tools: For development teams, assess the cf CLI and Forge for potential efficiencies in managing Cloudflare resources and API interactions.