Moltworker: a personal OpenClaw on Cloudflare's infrastructure
cloudflare/moltworker · 9,957★ · 1,719 forks
Everything worth knowing about cloudflare/moltworker: a proof of concept that packages OpenClaw inside a Sandbox container and exposes it through Cloudflare Workers.
What Moltworker is
Moltworker runs OpenClaw — formerly Moltbot and Clawdbot — as a personal AI assistant inside a Cloudflare Sandbox. It isn’t a new implementation of the agent: it adds an entry Worker, admin routes, and adapted scripts to host OpenClaw’s gateway inside a managed container.
The result keeps OpenClaw’s model: a web control interface, persistent conversations if storage is configured, device pairing, and channels like Telegram, Discord, and Slack. The pitch replaces a personal computer or an administered virtual server with Workers, Sandboxes, and associated Cloudflare services.
The origin: the alternative to the week’s Mac mini for Moltbot
Cloudflare created the repository on January 27, 2026 and published the announcement on January 29, 2026, signed by Celso Martinho, Brian Brunner, Sid Chatterjee, and Andreas Jansson. The launch’s context was the growing number of people buying a Mac mini to run Moltbot in the background; the post explicitly raises the alternative of running the assistant online without buying dedicated hardware.

The post itself received an editorial note on January 30: Moltbot was renamed OpenClaw. That succession explains why the repository still keeps historical names like MOLTBOT_GATEWAY_TOKEN and configuration routes while the current README already talks about OpenClaw.
Cloudflare’s technical motivation was demonstrating the progress of its Node.js compatibility and development platform. Per the announcement, Sandboxes offers isolated execution, Browser Rendering offers browser automation, and R2 offers persistence; Moltworker ties them together with a Worker acting as a router and proxy toward the container.
Philosophy and principles
The core principle is shifting the operation of a personal assistant to managed infrastructure, while keeping container isolation and multi-layer access control. Even so, the repository defines itself as experimental, a proof of concept, and not officially supported; it may stop working without notice.

On security, the design doesn’t treat the gateway token as the only control: Cloudflare Access protects admin, API, and debugging surfaces; the token opens the control interface; and each new device must be approved from the admin interface. This layering responds to the fact that the agent can receive messages and handle provider credentials, not to a guarantee of absolute privacy.
How it works
The architecture consists of an entry Worker and a Sandbox container running OpenClaw’s standard gateway. The Worker exposes the admin interface and proxies between Cloudflare’s APIs, Browser Rendering, and the isolated environment; R2 can preserve configuration, paired devices, and history when the container restarts.

The project uses a standard-1 instance with ½ vCPU, 4 GiB of memory, and 8 GB of disk. Backup to R2 runs every five minutes; on startup, the container restores data if it exists.

The optional components matter for the flow: AI Gateway can centralize caching, limits, analytics, and costs for model calls; the CDP adapter allows controlling a headless browser; and bot secrets enable Telegram, Discord, or Slack.
Official and semi-official status
The repository belongs to the Cloudflare organization, and its official blog post presents it as a platform demo, making it a first-party Cloudflare initiative. However, it isn’t an officially supported product: the README is explicit about its experimental status and the risk of breakage.
No evidence was retrieved that it’s a package accepted into an official plugin marketplace, or that it holds a formal standard designation. In practice, it’s a semi-official reference for deploying OpenClaw on Cloudflare, not a supported, stable-product distribution of OpenClaw.
The ecosystem
First-party components
- OpenClaw is the runtime Moltworker packages; the README links its docs and describes the container as running its gateway and integrations.
- Cloudflare Sandbox / Containers, Workers, Cloudflare Access, R2, Browser Rendering, and AI Gateway are the services the repository integrates with.
- The included
cloudflare-browserskill uses the CDP adapter and contains scripts for screenshots and video inside/root/clawd/skills/cloudflare-browser/.
Detected forks, ports, and derivatives
The forks API shows many copies with the same description; there’s no basis for describing them as independent ports. Among the most visible are buildwitholga/free-moltworker (10 stars), sugarforever/moltworker (7), and ax-platform/ax-moltworker (4); they should be read as forks, not official support.
The repository search retrieved zeviance/moltworker-zero (41 stars), which declares it runs ZeroClaw on Cloudflare Workers. It’s a related derivative by deployment destination, but it’s neither a fork of OpenClaw nor a Cloudflare component.
No non-English translations with an explicit relationship, nor Cloudflare sibling repositories dedicated specifically to Moltworker, were retrieved. That absence refers to the searches and forks consulted; it doesn’t rule out them appearing later.
Repo numbers
Measured: August 10, 2026, GitHub API.
| Metric | Value |
|---|---|
| Stars | 9,932 |
| Forks | 1,747 |
| Real subscribers | 47 |
| Open issues reported by the API | 95 |
| Primary language | TypeScript |
| License | Apache-2.0 |
| Created | January 27, 2026 |
| Last metadata update | August 11, 2026 |
| Last push to the repository | May 9, 2026 |
| GitHub releases | None retrieved |

The updated_at date returned by the API is later than the environment’s measurement date; it’s transcribed as a metadata anomaly, without inferring future activity. The watchers_count field mirrors stars in the general API, which is why subscribers_count is reported as the real subscriber figure; open_issues_count can include open pull requests.
The top five contributors by contributions returned by the API were andreasjansson (151), sidharthachatterjee (18), threepointone (4), elithrar (3), and celso (3). The repository page showed 193 commits, 41 branches, and no tags in the visual query; that page figure can differ from a paginated API count.
How to contribute
CONTRIBUTING.md asks that a non-trivial change start with an issue first, explaining the impact and planned solution, and demonstrating manual, automated, or mixed tests before a pull request.
The project states a specific policy for AI-assisted contributions: the tool and its scope must be disclosed, AI-generated pull requests must reference an accepted issue, and a person must verify them in the relevant environment. It also forbids AI-generated media and warns maintainers may close proposals they don’t want to maintain.
Quick-start guide
Installation and first run
- The Workers Paid plan and an Anthropic key, or AI Gateway’s unified billing, are required.
- In the repository clone, run
npm install, loadANTHROPIC_API_KEYwithnpx wrangler secret put ANTHROPIC_API_KEY, and generate a gateway token with the documented patternopenssl rand -hex 32; save it vianpx wrangler secret put MOLTBOT_GATEWAY_TOKEN. - Deploy with
npm run deployand openhttps://your-worker.workers.dev/?token=YOUR_GATEWAY_TOKEN. The first request can take one or two minutes while the container starts. - Before managing devices, enable Cloudflare Access, configure
CF_ACCESS_TEAM_DOMAINandCF_ACCESS_AUD, redeploy, and visit/_admin/.

Common workflows
- Secure web assistant: open the interface with
?token=..., authenticate against Access for the admin zone, and approve the pending device from/_admin/. - Preserve conversations: create a read/write R2 token and load
R2_ACCESS_KEY_ID,R2_SECRET_ACCESS_KEY, andCF_ACCOUNT_ID; the project restores data on startup and syncs every five minutes. - Reduce spend on sporadic use: set
SANDBOX_SLEEP_AFTERvianpx wrangler secret put SANDBOX_SLEEP_AFTERwith a value like10mor1h; the next access will have a cold start. - Add a channel: load
TELEGRAM_BOT_TOKEN,DISCORD_BOT_TOKEN, or, for Slack,SLACK_BOT_TOKENandSLACK_APP_TOKEN, and runnpm run deploy.
Essential configuration
| Setting or file | Function |
|---|---|
wrangler.jsonc | Worker configuration and its deployment; the README treats it as part of the deployable project. |
MOLTBOT_GATEWAY_TOKEN | Required token for remote access to the control interface. |
CF_ACCESS_TEAM_DOMAIN and CF_ACCESS_AUD | Validate Cloudflare Access JWTs in the admin interface. |
R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY, CF_ACCOUNT_ID | Enable persistence outside the container’s ephemeral lifecycle. |
SANDBOX_SLEEP_AFTER | Decides whether the container stays active or sleeps when idle. |
Common pitfalls and fixes
- If
npm run devfails due to missing authorization, enable Cloudflare Containers in your Containers dashboard. - If R2 doesn’t mount, check the three R2 secrets; the README also notes mounting only works in production, not with
wrangler dev. - In local development, WebSocket can fail due to known limitations of
wrangler dev’s proxy; deploy on Cloudflare to test full connections. - On Windows, exit code 126 can come from CRLF line endings in
start-openclaw.sh; use LF, for example withgit config --global core.autocrlf input. - Retrieved issues show real friction:
blueteampreported a missing or invalid token in issue 58,ClawdMFTquestionedSANDBOX_SLEEP_AFTER’s behavior in 139, andsagarchauhan005reported an R2 mounting failure in 72. These are user reports, not diagnoses confirmed by a maintainer fix.
Integrations and migration
AI Gateway can be used as a proxy for Anthropic, OpenAI, Groq, or Workers AI, with CF_AI_GATEWAY_MODEL in provider/model format; native configuration takes priority over direct keys. For browser automation, set CDP_SECRET and WORKER_URL, redeploy, and use the CDP endpoints under /cdp/.

The conceptual migration from a Mac mini or a VPS consists of moving OpenClaw’s gateway to Sandbox and enabling R2 so persistence doesn’t depend on ephemeral disk. No official guide for automated migration between OpenClaw installs was retrieved.
How the community received it
The Hacker News thread 46810828, linking Cloudflare’s announcement, logged 246 points and 71 comments in the consulted search. User linkage valued it as easier than maintaining a VPS and possibly cheaper for many, but objected that Cloudflare could read the traffic and attached storage; that’s a privacy warning attributed to that user, not an audit.
In the same thread, JoblessWonder asked for a more concrete monthly cost estimate for a real use case. The README does offer a reference: roughly $34.50/month with standard-1 active the whole time, versus about $5–6/month of compute if it runs four hours a day, plus the $5 plan; the figures are the project’s own estimates and depend on usage.
The search also returned two direct submissions to the repository: 46853852, by zoooey, and 46811854, by rcarmo, both with 3 points and 1 comment. They show distribution, but their size doesn’t allow inferring broad enthusiasm.
Reddit, X, Product Hunt, video, Dev.to, Hashnode, podcasts, and package registries were attempted via searches and public routes during this run, but no verifiable, specific evidence was retrieved to include. The lack of retrieval doesn’t prove posts or packages don’t exist.

Moltworker versus other approaches
| Approach | Verifiable relationship | Verifiable difference |
|---|---|---|
| Local OpenClaw install on your own hardware | The announcement contrasts Moltworker with running Moltbot/OpenClaw on your own Mac mini. | Moltworker runs the gateway in a Cloudflare Sandbox and uses R2 for optional persistence; your own hardware avoids that vendor dependency. |
| A managed VPS | An HN commenter considers the option easier than setting up and maintaining a VPS. | The source doesn’t provide an independent technical or economic comparison, so no general superiority is claimed. |
zeviance/moltworker-zero | Deploys ZeroClaw on Cloudflare Workers and shares the deployment destination. | It uses ZeroClaw, not OpenClaw; the retrieved description doesn’t support a deeper comparison. |
Use cases and who this repository can help
- People who want an OpenClaw assistant reachable from Telegram, Discord, Slack, or a web interface can start from Cloudflare’s deployment without managing a dedicated machine, as long as they accept the experimental status and infrastructure cost.
- Teams already operating on Cloudflare can combine Access, AI Gateway, R2, Browser Rendering, and Workers to centralize authentication, call observability, and persistence for an OpenClaw install.
- Developers exploring browser-equipped agents can use the CDP adapter and the
cloudflare-browserskill for screenshots, video, and automation, protecting the CDP endpoints with a shared secret. - Maintainers who need to evaluate an alternative to a VPS or Mac mini can use the cost table and
SANDBOX_SLEEP_AFTERto model an intermittent use case before committing; they should keep cold starts and the community’s privacy observation in mind.
Resources
- Repository: https://github.com/cloudflare/moltworker
- Documentation and setup: https://github.com/cloudflare/moltworker#quick-start
- Official announcement and architecture: https://blog.cloudflare.com/moltworker-self-hosted-ai-agent/
- Contribution guide: https://github.com/cloudflare/moltworker/blob/main/CONTRIBUTING.md
- Community and conversation: https://news.ycombinator.com/item?id=46810828
- Related derivative: https://github.com/zeviance/moltworker-zero
- OpenClaw documentation: https://docs.openclaw.ai/
Note: this article combines official documentation, the GitHub API, and community sources retrieved on August 10, 2026. Figures change over time.
Comments