Full-Time
Posted on 7/10/2026
CDN, cybersecurity, and serverless computing platform
No salary listed
Bengaluru, Karnataka, India
In Person
See people who can refer or advise you
Preparing a concise company summary based on the provided Cloudflare description.
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
San Francisco, California
Founded
2009
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Competitive salaries
Take-what-you-need paid vacation policy
Comprehensive health plans and benefits
Paid maternity and paternity leave
Commuter and ride share options
Returnships
Cloudflare automates Bot Rules. Cloudflare's Bot Preference Sync feature automatically updates robots.txt for AI bots, simplifying bot management for site owners. Visual TL;DR. Complex Bot Management addressed by Cloudflare Bot Sync. Cloudflare Bot Sync enables Single Control Point. Single Control Point leads to Streamlined Bot Rules. Cloudflare Bot Sync uses AI Bot Preferences. Complex Bot Management highlights need for Transparency Call. Cloudflare Bot Sync achieves Reduced Confusion. Reduced Confusion contributes to Streamlined Bot Rules. * Complex Bot Management: website operators balance discoverability with protection, managing multiple control layers for bots * Cloudflare Bot Sync: new feature automates robots.txt updates based on AI bot preferences in dashboard * Single Control Point: dictates how various AI bots interact with website content from one location * Streamlined Bot Rules: simplifies managing bot traffic, especially for AI crawlers and data scraping * AI Bot Preferences: configures how AI bots interact with content, including training data usage * Transparency Call: demand for clear communication on bot behavior and data usage from AI companies * Reduced Confusion: prevents discrepancies between stated robots.txt preferences and actual enforcement rules Visual TL;DR Cloudflare is introducing a new feature called Bot Preference Sync designed to streamline how website owners manage bot traffic, particularly concerning AI crawlers. The service automatically updates a site's robots.txt file to reflect the AI bot preferences already configured in the Cloudflare dashboard. This means a single point of control can now dictate how various AI bots interact with a website's content. Simplifying Bot Management. Website operators often face the complex task of balancing discoverability with protection. Some want their content to be easily found and potentially used for AI training, while others prioritize strict security and aim to prevent unauthorized data scraping for model training. Historically, managing these distinct needs involved maintaining multiple layers of control, including robots.txt files and edge-enforcement rules. Discrepancies between stated preferences in robots.txt and actual enforcement could lead to confusion for bots, potentially causing them to ignore preferences or bypass security measures.
Cloudflare OAuth now lets users reject unnecessary app permissions. By IT News AI / Thu, Aug 20 2026 / Cloudflare has introduced optional OAuth scopes, allowing users to approve only the permissions an application needs for a specific task instead of accepting or rejecting the entire request. The change is especially useful for MCP servers and other AI agents that may request broad access but do not need every capability in each session. More control without a permission checklist. OAuth client owners can now mark configured scopes as required or optional. During authorization, users can deselect optional scopes, while required scopes remain part of the grant; applications that do not opt into the feature keep the existing consent behavior. Cloudflare is limiting the choice to scopes requested in the current authorization flow, rather than displaying every permission configured for the client. That keeps the consent screen focused on the operation the user is about to authorize. Permissions follow the current request. For example, a client configured with user-details.read, workers-scripts.write, workers-kv-storage.write, and zone.read could make the last two scopes optional. If all four are requested, users can decline the storage and zone permissions while still granting the required scopes. If a later flow requests only workers-scripts.write and zone.read, only those scopes are evaluated and displayed. Permissions omitted from that request are neither granted nor enforced, even if they remain configured on the OAuth client. Client configuration adds optional scopes. Developers specify optional permissions through the OAuth client configuration by adding an optional_scopes list alongside the normal scopes list. This lets a single client support broad integrations while still allowing users to narrow access at authorization time. The model is particularly relevant to MCP servers, which may advertise many operations to an AI assistant even though an individual user or workflow requires only a subset of them. Applications must handle partial grants. Access tokens now reflect the scopes the user actually approved. After exchanging an authorization code, applications must inspect the granted scope set instead of assuming that every requested permission was included. Agents and integrations that continue working with reduced permissions will provide a safer authorization experience. Cloudflare recommends requesting only task-relevant permissions and marking additional capabilities optional where appropriate. Broader role coverage is planned. Cloudflare says it will expand account- and zone-level roles across nearly all of its products in the coming weeks. The effort is intended to provide more granular API token roles, account membership controls, and OAuth scopes for securing workloads.
cloudflare.com leads panel at 100/100 - perfect probe. On 2026-08-20, cloudflare.com achieved a perfect score of 100/100 in its GEO Pulse probe, ranking first among a panel of ten well-known sites. This strong performance highlights its robust setup for AI visibility, with all five core signals passing. How did cloudflare.com achieve a perfect score? Cloudflare.com stands out with a flawless setup for AI engines to read and cite its content. The homepage is fully accessible, returning an HTTP 200 status with approximately 3,704 characters of server-rendered text. This ensures that retrieval bots can effectively read the site. Additionally, there are no blanket disallow rules for major AI crawlers like GPTBot, ClaudeBot, and PerplexityBot, allowing them to fetch key pages without restriction. Moreover, cloudflare.com includes a well-formed /llms.txt file, sized at 16,879 bytes, providing a clear map to its content for AI engines. The presence of valid JSON-LD schema further classifies the site as an entity, enhancing its discoverability. The site's structure is also optimized for AI-generated answers, featuring a clear H1, three sections with short, extractable answers, and question-shaped headings. How does cloudflare.com compare within the panel? In this probe, cloudflare.com ranks first out of ten sites, with a perfect score of 100/100. The panel's average score is 76.6, with a median of 90. Notably, cloudflare.com is one of only two sites to achieve a perfect score, alongside stripe.com. The panel reveals that many sites struggle with AI-crawler reachability, GPTBot/ClaudeBot access, and the presence of a /llms.txt file, as all ten sites in the panel fail these signals most often. 100/100 cloudflare.com score 76.6 panel average score 1 of 10 cloudflare.com rank What does this mean for other business sites? The results from cloudflare.com underscore the importance of optimizing for AI visibility. A well-structured site with accessible content and clear guidance for AI crawlers is crucial. Business sites should ensure their homepages are easily readable by retrieval bots, avoid unnecessary restrictions on AI crawlers, and provide a comprehensive /llms.txt file. Additionally, implementing a valid JSON-LD schema can significantly enhance a site's classification as an entity. For sites looking to improve their AI visibility, focusing on these key areas can lead to better performance in AI-generated answers. The AI crawler playbook and llms.txt guide offer valuable insights into optimizing these elements. Is there a trend in cloudflare.com's performance? This is the first recorded probe for cloudflare.com, providing a baseline for future assessments. Without historical data, GEO/AEO Playbooks cannot comment on trends or changes over time. However, the current perfect score sets a high standard for future evaluations, and it will be interesting to see if cloudflare.com maintains this level of performance in subsequent probes. Overall, cloudflare.com's perfect score reflects a strong foundation for AI visibility, setting an example for other business sites aiming to enhance their online presence in AI-generated contexts. Run the same 5-signal probe on your own domain This note came out of the hourly GEO Pulse board. The free checker runs the identical probe on any site, and Monitor re-runs it every month.
DeepSeek V4 on Cloudflare Workers AI: 1M context window is live. 2 hours ago 0 DeepSeek V4 Flash and Pro arrive on Workers AI with the first 1M-token context window on the platform On August 14, Cloudflare added DeepSeek V4 Pro and DeepSeek V4 Flash to Workers AI - both with a 1,048,576-token context window. That is the first time any model on Workers AI has shipped with a 1 million token context. If you have been routing long-context inference tasks out of your Workers to external APIs because the old ceiling broke your architecture, you no longer need to. What shipped. Two model IDs are live: @cf/deepseek-ai/deepseek-v4-pro-0813 and @cf/deepseek-ai/deepseek-v4-flash-0731. Both run on Cloudflare's managed GPU network and support the same three access paths: the Workers AI binding (env.AI.run, the REST API, and the OpenAI-compatible chat completions endpoint. Both also support thinking mode and function calling. Workers AI's previous context ceiling was 128K tokens on the best available models. V4 Flash and Pro represent an 8x jump minimum - and the official Cloudflare changelog confirms these are the first models on the platform to cross the 1M mark. That is not an incremental upgrade. It changes what you can fit into a single inference call. Flash vs Pro: pick Flash first. The two models are not equals, but the gap is narrower than the naming implies. Flash (284B total parameters, 13B active) outputs at 103.2 tokens per second and scores 47 on the Artificial Analysis Intelligence Index. Pro (1.6T total, 49B active) scores 52 - a 5-point gap. Pro also costs roughly 3.1x more per output token. In most production workloads, that 5-point intelligence difference does not show up. Use Flash as your default. Reserve Pro for workflows with 10+ tool call chains, multi-agent planning where the coordinator needs to track complex state, or explicitly hallucination-sensitive pipelines where the quality gap actually matters. Paying 3x for the Pro label on a straightforward RAG pipeline is a waste. How to wire it up. The Workers binding requires two things: add [ai] binding = "AI" to your wrangler.toml, then call the model in your handler. The Workers Wrangler setup guide covers the full configuration. export default {async fetch(request: Request, env: { AI: Ai}): Promise<Response> {const messages = [ { role: "user", content: "Your prompt here..."}]; const response = await env.AI.run( "@cf/deepseek-ai/deepseek-v4-flash-0731", {messages}); return Response.json(response);}}; For streaming, add stream: true to the options object and pipe the resulting ReadableStream directly to the response. If you are already using the OpenAI SDK elsewhere, you can point its baseURL at Cloudflare's OpenAI-compatible endpoint - no code rewrite required. The 1M token context is for input plus output combined. The maximum generated output is 384,000 tokens, but that output must fit within the same 1M window alongside your prompt. Feed in 800K tokens of context and your maximum output drops to roughly 248K tokens. This is not a surprise gotcha - it is how transformer architectures work - but it is worth planning around before you design a workflow that assumes 384K output tokens regardless of input size. Also worth noting: thinking mode tokens count against your context and your billing even when they are not surfaced to the user. If you enable reasoning mode for a simple classification task, you are burning tokens you did not need to burn. Pricing and access. Both models require either the Workers Paid plan or prepaid AI Gateway credits. The free tier gets nothing here. Standard Workers Paid billing gives you a 20-request-per-minute rate limit. If you route through AI Gateway using Unified Billing - which launched August 7, a week before these models dropped - the rate limit jumps to 50 RPM. Cloudflare passes through inference pricing at cost with no markup. The Unified Billing credits carry a 5% fee on purchase, but the per-token rates are identical to calling DeepSeek directly. The architecture unlock. Before V4, building a long-context agentic workflow on Workers meant one of two things: artificially chunk your context and accept worse results, or break out to an external API and accept egress costs and latency spikes. Neither is a clean solution. With V4, the coordinator-worker pattern becomes practical entirely within Workers AI. A single V4 Pro coordinator holds the full task plan in its 1M context, delegates subtasks to multiple V4 Flash workers for high-speed execution, and reviews combined output - without a single external inference call. The entire loop stays on Cloudflare's network. This is the change that matters. The 1M token number is headline material, but the real value is removing the architectural compromise that forced developers off the platform for long-context workloads. Check the Flash model docs and the Pro model docs for the full parameter reference. Start with Flash, measure whether the Pro intelligence gap matters for your specific pipeline, and keep the inference on the edge where it belongs. I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.
Cloudflare adds MCP traffic detection and Portal controls. 1h ago DevOps Tl;dr. Cloudflare One now detects Model Context Protocol traffic, identifies shadow MCP servers, and enforces approved-path access through new Gateway policies and dashboards. Key points. * MCP-Protocol-Version header detection identifies MCP traffic on TLS-inspected requests without maintaining domain allowlists * New MCP traffic dashboard shows which servers are accessed, which users access them, and whether requests bypass Portals * Gateway Traffic Source selectors distinguish Portal-proxied MCP requests from direct device connections for policy enforcement * Server-side controls (WriteGuard pattern) can block unauthorized tool calls before execution; network layer catches shadow MCP on managed paths Why it matters. AI agents can execute thousands of tool calls at inhuman speed with nondeterministic decisions, creating security risks traditional permission models weren't designed for. These controls let security teams detect unauthorized MCP servers (shadow MCP), prevent Portal bypasses, and block dangerous tool invocations before they execute - critical for organizations deploying Claude, Cursor, and other AI clients with MCP server access.