Back to Data, Analytics & Infrastructure

InfrastructureCloudflare Workers

Two live apps at the edge, on Cloudflare Workers.

A Cloudflare Worker is a small program that runs inside Cloudflare's network, close to whoever calls it, with no server of mine to keep running. I run two. Omniscope is the way in for AI agents such as Claude Code when they ask questions of the order platform. CyprusCalc is a site of thirteen calculators, served as plain files.

Workers
Two, both live
Runs in
Cloudflare's network
Storage
KV and D1
Live since
August 2026
01

Every call is checked before it gets in

Omniscope lets an AI agent read the order platform. The Worker is the only way in, and it checks each call where it lands. Below, the same call arrives from three callers. One gets through. Two are stopped at the edge, and the systems behind the Worker never hear about them.

One call, three callers

Who is calling

How far the call gets

  1. Signed in?OAuth · KVThe token is checked first
  2. Within the limit?KVCalls are counted per caller
  3. Written downD1An audit row, before any read
  4. Handed overControl TowerThe gateway makes the read

Claude Code: Through all three checks. The call is written down, then handed to the gateway, which makes the read and sends the answer back.

The callers are illustrative. The order of the checks is the real one. Because every check runs in the Worker, a call that fails one costs the systems behind it nothing.
02

What I built, in six pieces

Four belong to Omniscope, one to CyprusCalc, and one to both.

  • Omniscope

    Sign in before the first question

    Agents sign in with OAuth. The sign in state waits in KV while the handshake finishes, so whichever copy of the Worker answers next can pick it up.

  • Omniscope

    A limit for every caller

    Each caller's calls are counted in KV. Past the limit, a call stops at the edge instead of landing on the order platform.

  • Omniscope

    A record of every call

    An audit row goes into D1 before anything is read, so every answer an agent gives can be traced to the call behind it.

  • Omniscope

    No platform keys at the edge

    The Worker talks to one thing, the Control Tower gateway. Credentials for the order platform stay behind the gateway, never in the Worker.

  • CyprusCalc

    A whole site with no server

    Next.js builds CyprusCalc into plain files and a Worker serves them. There is no database and nothing running between visits.

  • Both

    Shipped from the command line

    Both Workers are deployed with Wrangler. Secrets are set with Wrangler too, so none of them sits in the code.

03

Two Workers, side by side

A Worker keeps nothing between calls. What it remembers, and what it can reach, is given to it when it is deployed.

What each Worker is given

GivenOmniscopeMCP serverCyprusCalcStatic site
Sign in stateKVYesNo
Call counts for the rate limitKVYesNo
Audit log, one row per callD1YesNo
Secret keysSecretsYesNo
The site itself, built by Next.jsFilesNoYes

Hands over to

  • Omniscope → The Control Tower gateway
  • CyprusCalc → Nothing, it all runs in the browser
The checkpoint needs three stores and a way through. The calculator site needs a folder of files.
04

My role

Both Workers are mine end to end. Three decisions shaped them.

  • Built both, end to end

    Omniscope's Worker in TypeScript, and CyprusCalc's build and release, from first commit to production.

  • Refuse cheaply, record first

    The token is checked before anything is counted, and the audit row is written before the gateway is asked, so no answer exists without its record.

  • State by what it is for

    KV for what is looked up by a key and can expire. D1 for what someone will need to search later.

05

What changed

3

Checks before a call is handed over

An agent can ask the order platform a question without holding a key to it, and every question it asks is written down first. A calculator site stays up with nothing to patch and no server to pay for.

0

Order platform credentials at the edge

0

Servers kept running for CyprusCalc

06

Built with

  • Cloudflare Workers
  • Workers KV
  • Cloudflare D1
  • TypeScript
  • OAuth
  • Next.js
  • Model Context Protocol