For the complete documentation index, see llms.txt. Prefer markdown by appending.mdto documentation URLs or sendingAccept: text/markdown.
Security
Session checks, private storage, bot protection, rate limiting, and server-side authorization as a foundation for your Edge product.
Edge Kit includes reusable session checks, Turnstile bot protection, auth rate limiting, a private file-handling pattern, and paid plan authorization. These controls connect your UI, server operations, and Cloudflare services into a security foundation for your product.
As you add product features, connect them to the same server-side rules: who owns the data, who can change it, and which actions require paid or verified access.
Configuration
| Category | Configuration | Scope |
|---|---|---|
| Credentials | Local environment file and production Worker secrets | Server |
| Cloudflare resources | Wrangler bindings | Server |
| Public settings | Build-time VITE_* values | Browser |
Keep API credentials and auth secrets in the server scope. Public values such as the Turnstile site key and analytics beacon token can appear in browser code.
The environment guide covers validation and production secrets. Keep secret values out of source control, screenshots, logs, and returned API data.
Authorization
Dashboard redirects guide visitors through sign-in. Private server functions and HTTP endpoints also check access directly, since callers can invoke them without visiting the page.
For customer-owned data, derive identity from the session and restrict each query to its owner. For paid work, apply the minimum plan at the server operation. Protected calls and plan access cover these patterns.
Anonymous accounts
An anonymous account has a session but does not establish a verified customer identity. Features that need email ownership or a registered customer should require those properties on the server.
Validate input before using it. Input validation and permission checks solve different problems, and both belong in operations that read or change private data.
Abuse protection
| Feature | Included protection |
|---|---|
| Authentication | Turnstile and request rate limiting |
| Contact form | Bot verification |
| File uploads | Validation and an authenticated ownership pattern |
| AI | Authenticated model requests |
| Paid features | Server-side plan checks |
Extend these controls to match your product, especially for costly AI calls, public forms, and resource creation. Plan descriptions do not enforce usage budgets automatically.
Workers rate limiting helps reduce abuse. It is location-based and eventually consistent, so use a separate usage policy for exact quotas or billing. See Cloudflare's rate limiting documentation.
Server boundaries
Keep credentials, database access, and Cloudflare operations in private handlers. Shared components and page loaders can run in the browser; they should call the server boundary and receive only the data they need.
The server functions overview explains this separation.
Verification
Test private operations while signed out, with an anonymous account if enabled, and with a second customer's session. A valid record identifier should still be rejected when it belongs to someone else.
Check malformed input, paid access from a Free account, account deletion during a subscription, and private file access after sign-out. Use request logs to investigate results without exposing customer secrets.
How is this guide?
Last updated on