For the complete documentation index, see llms.txt. Prefer markdown by appending .md to documentation URLs or sending Accept: text/markdown.

Security

Session checks, private storage, bot protection, rate limiting, and server-side authorization as a foundation for your Edge product.

Edge Kit includes reusable session checks, Turnstile bot protection, auth rate limiting, a private file-handling pattern, and paid plan authorization. These controls connect your UI, server operations, and Cloudflare services into a security foundation for your product.

As you add product features, connect them to the same server-side rules: who owns the data, who can change it, and which actions require paid or verified access.

Configuration

CategoryConfigurationScope
CredentialsLocal environment file and production Worker secretsServer
Cloudflare resourcesWrangler bindingsServer
Public settingsBuild-time VITE_* valuesBrowser

Keep API credentials and auth secrets in the server scope. Public values such as the Turnstile site key and analytics beacon token can appear in browser code.

The environment guide covers validation and production secrets. Keep secret values out of source control, screenshots, logs, and returned API data.

Authorization

Dashboard redirects guide visitors through sign-in. Private server functions and HTTP endpoints also check access directly, since callers can invoke them without visiting the page.

For customer-owned data, derive identity from the session and restrict each query to its owner. For paid work, apply the minimum plan at the server operation. Protected calls and plan access cover these patterns.

Anonymous accounts

An anonymous account has a session but does not establish a verified customer identity. Features that need email ownership or a registered customer should require those properties on the server.

Validate input before using it. Input validation and permission checks solve different problems, and both belong in operations that read or change private data.

Abuse protection

FeatureIncluded protection
AuthenticationTurnstile and request rate limiting
Contact formBot verification
File uploadsValidation and an authenticated ownership pattern
AIAuthenticated model requests
Paid featuresServer-side plan checks

Extend these controls to match your product, especially for costly AI calls, public forms, and resource creation. Plan descriptions do not enforce usage budgets automatically.

Workers rate limiting helps reduce abuse. It is location-based and eventually consistent, so use a separate usage policy for exact quotas or billing. See Cloudflare's rate limiting documentation.

Server boundaries

Keep credentials, database access, and Cloudflare operations in private handlers. Shared components and page loaders can run in the browser; they should call the server boundary and receive only the data they need.

The server functions overview explains this separation.

Verification

Test private operations while signed out, with an anonymous account if enabled, and with a second customer's session. A valid record identifier should still be rejected when it belongs to someone else.

Check malformed input, paid access from a Free account, account deletion during a subscription, and private file access after sign-out. Use request logs to investigate results without exposing customer secrets.

How is this guide?

Last updated on

On this page

Ship globally on the edge. In minutes.Try Edge Kit