For the complete documentation index, see llms.txt. Prefer markdown by appending.mdto documentation URLs or sendingAccept: text/markdown.
Overview
Type-safe server functions with TanStack Start, plus HTTP endpoints for webhooks, streaming, and files, all running in your Edge Worker.
Server functions let your React app call private server logic without building a separate API client. Edge Kit uses TanStack Start to connect typed calls to the Worker where your database, credentials, and Cloudflare services are available.
The included setup connects:
- Typed calls and validation for application requests.
- Session and plan checks for private or paid operations.
- HTTP handlers for integrations with their own response format.
- Client queries for loading, caching, and refreshing results. You can use the same infrastructure for your own product resources, forms, and integrations while keeping private data and credentials on the server.
Server functions
Server functions connect an application interaction to private backend work. A browser call becomes a request to the Worker, where the handler can read D1, access Cloudflare bindings, or call a provider with server credentials.
Compose the kit's session and plan checks with input validation and the operation's ownership rules. Return the result through the typed boundary so the UI can use it without maintaining a separate request contract.
Existing billing and account calls demonstrate this pattern. Reuse it for resources such as projects, saved content, or customer preferences.
Server-only data
Page loaders and shared components can also run in the browser. Keep database access and credentials inside a server handler, then return only the data the UI needs.
Inputs and results
Treat every call as a request from outside the server. Validate accepted fields and bounds, resolve customer identity from the session, and load the permissions needed for the specific operation. Types help during development; validation checks the actual request. Another caller can still submit invalid input.
Return only the fields the screen needs. A customer list may need a label and status without the complete underlying database record. Keep provider credentials, session details, and internal error messages out of that result.
For failures customers can correct, return useful feedback through the feature's existing error pattern. Keep detailed diagnostics in logs, where they can be connected to the request without exposing them in the interface.
HTTP endpoints
HTTP endpoints handle callers that need a specific URL or response format:
| Integration | Purpose |
|---|---|
| Authentication and Stripe | Provider callbacks and webhooks |
| AI | Streaming model responses |
| Storage | Private file responses |
| Status | Basic availability checks |
These endpoints run in the same Worker as server functions. Private endpoints use the same authorization rules.
Request duration
Keep interactive operations focused on the result the customer is waiting for. Saving a record or checking access usually belongs in the request. Generating a large report or delivering a delayed notification can become a background job.
For asynchronous work, return a meaningful acknowledgement and, when needed, a product record whose status the interface can follow. Finishing the HTTP request does not establish that the queued work has completed.
Client queries
TanStack Query manages loading states, caching, and refreshes for server data. The kit includes query definitions for existing features so the same requests can be reused across screens.
After a change, refresh the relevant query to show the updated result. Customer-specific data should also be cleared when the active session changes.
The guide below covers protected calls, input validation, and customer-owned records. For a complete new feature, follow the feature recipe.
Protected calls
Validate server function inputs, resolve the caller from its session, enforce record ownership, and guard raw HTTP handlers on the Worker.
Data fetching
Page loading, TanStack Query caching, mutations, and UI states, with a clear boundary between customer data in the browser and server operations.
Caching
Cloudflare KV and application caching in Edge Kit, including keys, expiration, invalidation, consistency, and customer-specific data.
How is this guide?
Last updated on
Email delivery
Localized email delivery through Cloudflare, with typed templates, sender configuration, recipient options, and direct or queued application workflows.
Protected calls
Validate server function inputs, resolve the caller from its session, enforce record ownership, and guard raw HTTP handlers on the Worker.