AI Gateway's POST /ai/run endpoint now returns HTTP 401 with error code 2009 when an AI provider rejects credentials, replacing provider-specific statuses such as ElevenLabs' 403, Google Vertex's 500, and other providers' 402; Google Vertex requests now fail without retrying the provider. Under Unified Billing, rejected credentials return HTTP 503.
Developer Platform Changelog
npx @buildinternet/releases get cloudflare-developer-platformWeb Search API is now available in beta, letting AI agents search the Internet with a choice of Ceramic.ai, Exa, or Linkup as provider. Requests run through AI Gateway, so they appear in gateway logs, bill to AI Gateway credits at each provider's list API price with no markup, and support bringing your own provider API key.
The Agents SDK now provides a PiHarness class that lets you build long-running agents on Pi 1.0 and Pi Durable, persisting agent work in a Durable Object even if interrupted mid-turn. PiHarness is in beta, and both Pi packages are optional peer dependencies of agents.
D1 databases can now be created with a us jurisdiction so they run and persist data within the United States, for regional data residency requirements. Create one with npx wrangler@latest d1 create <name> --jurisdiction=us.
Workers KV namespaces can be created with a jurisdiction of eu, us, or fedramp that durably stores the namespace's data only within that region, set at creation via the dashboard, Wrangler, the cf CLI, or the REST API and not changeable afterwards. Workers can still access a jurisdiction-restricted namespace from anywhere, and KV data may be cached outside the jurisdiction on Cloudflare's network.
Cloudflare's Workers AI team released Clef and Clef-flash, decision models that read an input state and typed questions and return probabilities for allowed answers rather than free-form text, with weights open-sourced under Apache 2.0. Both are hosted on Workers AI with a 64K context window and drop-in compatibility with the System One API used by Jev, and Cloudflare is also launching an RL fine-tuning service for tuning Clef to specific workloads.
Workers Web Crypto now supports ML-KEM-768, ML-KEM-1024, and ML-DSA-44/65/87, adding key encapsulation and decapsulation methods, getPublicKey(), SubtleCrypto.supports(), and JWKs with the AKP key type. The features are opt-in via the webcrypto_modern_algorithms compatibility flag, and ML-KEM-512 is not supported.
Artifacts, Cloudflare's versioned file system that speaks Git, is now in open beta for Workers Paid customers, letting you deploy repositories to Workers via Workers Builds, manage repos through a Worker binding, subscribe to repository events, store data in the US or EU, and monitor usage. Billing for Artifacts begins October 14, 2026.
@cloudflare/workers-oauth-provider is now v1 with a split API: one Worker acts as the authorization server and your MCP server as the resource server, validating tokens over a Service Binding without crossing the public Internet. It supports the MCP 2026-07-28 authorization spec including Client ID Metadata Documents and issuer identification while still working with older clients using Dynamic Client Registration, and ships a migration skill in the npm package so a coding agent can perform the upgrade.
Basin, formerly the Cloudflare Data Platform, is now generally available, combining Basin Pipelines for ingesting events from Workers, HTTP endpoints, and Logpush; Basin Catalog for managing Apache Iceberg tables; and Basin SQL for querying them serverlessly. Existing Cloudflare Pipelines, R2 Data Catalog, and R2 SQL resources continue to work but will be deprecated over time.
Pending service binding requests, RPC or fetch() calls to other Durable Objects, this.ctx.container.monitor(), waitUntil() promises, and setTimeout/setInterval timers now keep a Durable Object running without a connected client, preventing idle shutdown while work is unfinished. The behavior is default for Workers with a compatibility date of 2026-10-01 or later; earlier dates need the durable_object_io_tasks_prevent_eviction flag, and each pending operation prevents eviction for up to 15 minutes while duration charges continue.
Each Basin Pipelines stream can now ingest up to 1 GB/s, up from 5 MB/s, giving high-volume events, telemetry, and logs more room to grow without splitting ingestion across streams to stay under the previous limit.
AI Search is generally available with usage-based billing beginning November 1, 2026, covering included monthly ingestion, storage, semantic query, and full-text query usage. Workers AI embedding and reranking calls made by AI Search are now included in AI Search pricing and no longer appear on Workers AI bills or AI Gateway logs.
A new durable_object scheduling policy in public beta lets a Durable Object select the Container image and instance size at runtime instead of using one centrally managed application configuration. Wrangler prepares each named image and exposes its immutable reference through ctx.container.images, which is passed with an instance size to container start; Durable Object-managed instances have independent lifecycles and do not participate in application-wide image rollouts.
Sandbox SDK 1.0 lets your own Durable Object class control each sandbox container directly through the Durable Object container API on this.ctx.container, choosing image and instance size per start, saving and restoring workspace snapshots in public beta, deciding when sandboxes stop, streaming command I/O with signals and terminals, serving authenticated previews from sandbox ports, handling outbound requests per hostname in Worker code, and running an agent in the same Durable Object.
Containers now support snapshot APIs that capture a point-in-time view of the full container filesystem via snapshotContainer(), which can be passed back to start() to restore files after sleep, restart, or handoff to another Durable Object. Snapshots are only supported for applications using the durable_object scheduling policy, and are immutable, so persisting later filesystem changes requires a new snapshot.
AI Gateway now supports Machine Payments in beta, letting clients use the x402 protocol to pay for eligible inference requests directly from a stablecoin wallet instead of maintaining a prepaid credit balance. It is available for the /ai/run endpoint with select open models, and currently requires customers based in the United States with a credit card on file.
The WebSocket adapter for Cloudflare's Realtime SFU is generally available, connecting live calls to any WebSocket-accepting server such as a Durable Object and delivering uncompressed PCM audio and JPEG video frames so backends can process media without a WebRTC client. Existing adapter creation requests and media formats are unchanged; WebRTC-to-WebSocket streaming now retries the same endpoint for up to 15 seconds instead of 5, and the close API is idempotent.
Workers Cache now supports invalidate(), which keeps matching cached responses but marks them stale so the cache revalidates them with the Worker via conditional requests such as If-None-Match, with a 304 keeping the stored body and a 200 replacing it. It accepts the same tags, pathPrefixes, or purgeEverything options as purge(), with the same per-entrypoint scoping and result object, callable as ctx.cache.invalidate() or cache.invalidate().
Gateway network logs and Zero Trust Network Session Logs now distinguish Mesh node traffic, Workers VPC sessions, and Cloudflare One Client devices via OnrampType values MESH and WORKERS_VPC, and a new DestinationReplicaID field pinpoints the Mesh or cloudflared replica that served each session. SourceName and SourceID are only populated for Workers deployed after 29 September 2026, so existing Workers must be redeployed with no code changes, and sessions logged before this change are not backfilled.

