August 21, 2026 · By YasKad
cloudflare/moltworker

Moltworker: a personal OpenClaw on Cloudflare's infrastructure

cloudflare/moltworker · 9,957★ · 1,719 forks

Everything worth knowing about cloudflare/moltworker: a proof of concept that packages OpenClaw inside a Sandbox container and exposes it through Cloudflare Workers.


What Moltworker is

Moltworker runs OpenClaw — formerly Moltbot and Clawdbot — as a personal AI assistant inside a Cloudflare Sandbox. It isn’t a new implementation of the agent: it adds an entry Worker, admin routes, and adapted scripts to host OpenClaw’s gateway inside a managed container.

The result keeps OpenClaw’s model: a web control interface, persistent conversations if storage is configured, device pairing, and channels like Telegram, Discord, and Slack. The pitch replaces a personal computer or an administered virtual server with Workers, Sandboxes, and associated Cloudflare services.

The origin: the alternative to the week’s Mac mini for Moltbot

Cloudflare created the repository on January 27, 2026 and published the announcement on January 29, 2026, signed by Celso Martinho, Brian Brunner, Sid Chatterjee, and Andreas Jansson. The launch’s context was the growing number of people buying a Mac mini to run Moltbot in the background; the post explicitly raises the alternative of running the assistant online without buying dedicated hardware.

Conceptual split-screen visual: on the left side, a physical Mac mini computer covered in dust and cobwebs in a dark room; on the right side, a glowing, ethereal Cloudflare Worker server icon radiating neon orange light, replacing the hardware.

The post itself received an editorial note on January 30: Moltbot was renamed OpenClaw. That succession explains why the repository still keeps historical names like MOLTBOT_GATEWAY_TOKEN and configuration routes while the current README already talks about OpenClaw.

Cloudflare’s technical motivation was demonstrating the progress of its Node.js compatibility and development platform. Per the announcement, Sandboxes offers isolated execution, Browser Rendering offers browser automation, and R2 offers persistence; Moltworker ties them together with a Worker acting as a router and proxy toward the container.

Philosophy and principles

The core principle is shifting the operation of a personal assistant to managed infrastructure, while keeping container isolation and multi-layer access control. Even so, the repository defines itself as experimental, a proof of concept, and not officially supported; it may stop working without notice.

Visual representation of a multi-layered digital security gateway: a glowing neon doorway protected by a futuristic force field, with translucent digital tokens and JWT badges floating in the foreground, against a dark, isolated container with a glowing core in the background.

On security, the design doesn’t treat the gateway token as the only control: Cloudflare Access protects admin, API, and debugging surfaces; the token opens the control interface; and each new device must be approved from the admin interface. This layering responds to the fact that the agent can receive messages and handle provider credentials, not to a guarantee of absolute privacy.

How it works

The architecture consists of an entry Worker and a Sandbox container running OpenClaw’s standard gateway. The Worker exposes the admin interface and proxies between Cloudflare’s APIs, Browser Rendering, and the isolated environment; R2 can preserve configuration, paired devices, and history when the container restarts.

Intricate architectural diagram rendered as a 3D cyberpunk cityscape: a central glowing worker node acts as a router, beaming neon light beams toward a massive dark sphere representing an isolated Sandbox container, surrounded by floating platforms for R2, Browser Rendering, and AI Gateway.

The project uses a standard-1 instance with ½ vCPU, 4 GiB of memory, and 8 GB of disk. Backup to R2 runs every five minutes; on startup, the container restores data if it exists.

Glowing, high-tech digital hourglass floating in a dark void, with neon orange data particles flowing from the top half into a translucent storage cube labeled with R2 icons at the bottom; beside the hourglass, a neon crescent moon symbolizes the sleep and wake cycles of a serverless container.

The optional components matter for the flow: AI Gateway can centralize caching, limits, analytics, and costs for model calls; the CDP adapter allows controlling a headless browser; and bot secrets enable Telegram, Discord, or Slack.

Official and semi-official status

The repository belongs to the Cloudflare organization, and its official blog post presents it as a platform demo, making it a first-party Cloudflare initiative. However, it isn’t an officially supported product: the README is explicit about its experimental status and the risk of breakage.

No evidence was retrieved that it’s a package accepted into an official plugin marketplace, or that it holds a formal standard designation. In practice, it’s a semi-official reference for deploying OpenClaw on Cloudflare, not a supported, stable-product distribution of OpenClaw.

The ecosystem

First-party components

  • OpenClaw is the runtime Moltworker packages; the README links its docs and describes the container as running its gateway and integrations.
  • Cloudflare Sandbox / Containers, Workers, Cloudflare Access, R2, Browser Rendering, and AI Gateway are the services the repository integrates with.
  • The included cloudflare-browser skill uses the CDP adapter and contains scripts for screenshots and video inside /root/clawd/skills/cloudflare-browser/.

Detected forks, ports, and derivatives

The forks API shows many copies with the same description; there’s no basis for describing them as independent ports. Among the most visible are buildwitholga/free-moltworker (10 stars), sugarforever/moltworker (7), and ax-platform/ax-moltworker (4); they should be read as forks, not official support.

The repository search retrieved zeviance/moltworker-zero (41 stars), which declares it runs ZeroClaw on Cloudflare Workers. It’s a related derivative by deployment destination, but it’s neither a fork of OpenClaw nor a Cloudflare component.

No non-English translations with an explicit relationship, nor Cloudflare sibling repositories dedicated specifically to Moltworker, were retrieved. That absence refers to the searches and forks consulted; it doesn’t rule out them appearing later.

Repo numbers

Measured: August 10, 2026, GitHub API.

MetricValue
Stars9,932
Forks1,747
Real subscribers47
Open issues reported by the API95
Primary languageTypeScript
LicenseApache-2.0
CreatedJanuary 27, 2026
Last metadata updateAugust 11, 2026
Last push to the repositoryMay 9, 2026
GitHub releasesNone retrieved

Massive, glowing GitHub repository interface projected as a holographic 3D dashboard in a dark cyberpunk room, with neon charts and graphs displaying rising star counts and commit histories in electric orange and cyan.

The updated_at date returned by the API is later than the environment’s measurement date; it’s transcribed as a metadata anomaly, without inferring future activity. The watchers_count field mirrors stars in the general API, which is why subscribers_count is reported as the real subscriber figure; open_issues_count can include open pull requests.

The top five contributors by contributions returned by the API were andreasjansson (151), sidharthachatterjee (18), threepointone (4), elithrar (3), and celso (3). The repository page showed 193 commits, 41 branches, and no tags in the visual query; that page figure can differ from a paginated API count.

How to contribute

CONTRIBUTING.md asks that a non-trivial change start with an issue first, explaining the impact and planned solution, and demonstrating manual, automated, or mixed tests before a pull request.

The project states a specific policy for AI-assisted contributions: the tool and its scope must be disclosed, AI-generated pull requests must reference an accepted issue, and a person must verify them in the relevant environment. It also forbids AI-generated media and warns maintainers may close proposals they don’t want to maintain.

Quick-start guide

Installation and first run

  1. The Workers Paid plan and an Anthropic key, or AI Gateway’s unified billing, are required.
  2. In the repository clone, run npm install, load ANTHROPIC_API_KEY with npx wrangler secret put ANTHROPIC_API_KEY, and generate a gateway token with the documented pattern openssl rand -hex 32; save it via npx wrangler secret put MOLTBOT_GATEWAY_TOKEN.
  3. Deploy with npm run deploy and open https://your-worker.workers.dev/?token=YOUR_GATEWAY_TOKEN. The first request can take one or two minutes while the container starts.
  4. Before managing devices, enable Cloudflare Access, configure CF_ACCESS_TEAM_DOMAIN and CF_ACCESS_AUD, redeploy, and visit /_admin/.

Futuristic, dark-themed terminal interface floating in mid-air, displaying the text npm run deploy in bright neon green, surrounded by holographic warning signs and floating neon icons representing Telegram, Discord, and Slack, all orbiting a central glowing Cloudflare hexagon.

Common workflows

  • Secure web assistant: open the interface with ?token=..., authenticate against Access for the admin zone, and approve the pending device from /_admin/.
  • Preserve conversations: create a read/write R2 token and load R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY, and CF_ACCOUNT_ID; the project restores data on startup and syncs every five minutes.
  • Reduce spend on sporadic use: set SANDBOX_SLEEP_AFTER via npx wrangler secret put SANDBOX_SLEEP_AFTER with a value like 10m or 1h; the next access will have a cold start.
  • Add a channel: load TELEGRAM_BOT_TOKEN, DISCORD_BOT_TOKEN, or, for Slack, SLACK_BOT_TOKEN and SLACK_APP_TOKEN, and run npm run deploy.

Essential configuration

Setting or fileFunction
wrangler.jsoncWorker configuration and its deployment; the README treats it as part of the deployable project.
MOLTBOT_GATEWAY_TOKENRequired token for remote access to the control interface.
CF_ACCESS_TEAM_DOMAIN and CF_ACCESS_AUDValidate Cloudflare Access JWTs in the admin interface.
R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY, CF_ACCOUNT_IDEnable persistence outside the container’s ephemeral lifecycle.
SANDBOX_SLEEP_AFTERDecides whether the container stays active or sleeps when idle.

Common pitfalls and fixes

  • If npm run dev fails due to missing authorization, enable Cloudflare Containers in your Containers dashboard.
  • If R2 doesn’t mount, check the three R2 secrets; the README also notes mounting only works in production, not with wrangler dev.
  • In local development, WebSocket can fail due to known limitations of wrangler dev’s proxy; deploy on Cloudflare to test full connections.
  • On Windows, exit code 126 can come from CRLF line endings in start-openclaw.sh; use LF, for example with git config --global core.autocrlf input.
  • Retrieved issues show real friction: blueteamp reported a missing or invalid token in issue 58, ClawdMFT questioned SANDBOX_SLEEP_AFTER’s behavior in 139, and sagarchauhan005 reported an R2 mounting failure in 72. These are user reports, not diagnoses confirmed by a maintainer fix.

Integrations and migration

AI Gateway can be used as a proxy for Anthropic, OpenAI, Groq, or Workers AI, with CF_AI_GATEWAY_MODEL in provider/model format; native configuration takes priority over direct keys. For browser automation, set CDP_SECRET and WORKER_URL, redeploy, and use the CDP endpoints under /cdp/.

Conceptual digital crossroads: a dark, neon-lit pathway splits in multiple directions, each guarded by a glowing holographic icon — one path features a classic Anthropic AI symbol, another shows OpenAI, another Groq, and another a Cloudflare Workers AI hexagon, with "AI Gateway" text glowing in the sky above the intersection.

The conceptual migration from a Mac mini or a VPS consists of moving OpenClaw’s gateway to Sandbox and enabling R2 so persistence doesn’t depend on ephemeral disk. No official guide for automated migration between OpenClaw installs was retrieved.

How the community received it

The Hacker News thread 46810828, linking Cloudflare’s announcement, logged 246 points and 71 comments in the consulted search. User linkage valued it as easier than maintaining a VPS and possibly cheaper for many, but objected that Cloudflare could read the traffic and attached storage; that’s a privacy warning attributed to that user, not an audit.

In the same thread, JoblessWonder asked for a more concrete monthly cost estimate for a real use case. The README does offer a reference: roughly $34.50/month with standard-1 active the whole time, versus about $5–6/month of compute if it runs four hours a day, plus the $5 plan; the figures are the project’s own estimates and depend on usage.

The search also returned two direct submissions to the repository: 46853852, by zoooey, and 46811854, by rcarmo, both with 3 points and 1 comment. They show distribution, but their size doesn’t allow inferring broad enthusiasm.

Reddit, X, Product Hunt, video, Dev.to, Hashnode, podcasts, and package registries were attempted via searches and public routes during this run, but no verifiable, specific evidence was retrieved to include. The lack of retrieval doesn’t prove posts or packages don’t exist.

Vibrant, cyberpunk-style digital town square: holographic avatars and chat bubbles float in a dark space, illuminated by glowing neon orange and cyan screens, with a central monolith displaying the text "Hacker News" in glowing retro-futuristic typography and streams of comments and upvotes cascading down its surface.

Moltworker versus other approaches

ApproachVerifiable relationshipVerifiable difference
Local OpenClaw install on your own hardwareThe announcement contrasts Moltworker with running Moltbot/OpenClaw on your own Mac mini.Moltworker runs the gateway in a Cloudflare Sandbox and uses R2 for optional persistence; your own hardware avoids that vendor dependency.
A managed VPSAn HN commenter considers the option easier than setting up and maintaining a VPS.The source doesn’t provide an independent technical or economic comparison, so no general superiority is claimed.
zeviance/moltworker-zeroDeploys ZeroClaw on Cloudflare Workers and shares the deployment destination.It uses ZeroClaw, not OpenClaw; the retrieved description doesn’t support a deeper comparison.

Use cases and who this repository can help

  • People who want an OpenClaw assistant reachable from Telegram, Discord, Slack, or a web interface can start from Cloudflare’s deployment without managing a dedicated machine, as long as they accept the experimental status and infrastructure cost.
  • Teams already operating on Cloudflare can combine Access, AI Gateway, R2, Browser Rendering, and Workers to centralize authentication, call observability, and persistence for an OpenClaw install.
  • Developers exploring browser-equipped agents can use the CDP adapter and the cloudflare-browser skill for screenshots, video, and automation, protecting the CDP endpoints with a shared secret.
  • Maintainers who need to evaluate an alternative to a VPS or Mac mini can use the cost table and SANDBOX_SLEEP_AFTER to model an intermittent use case before committing; they should keep cold starts and the community’s privacy observation in mind.

Resources


Note: this article combines official documentation, the GitHub API, and community sources retrieved on August 10, 2026. Figures change over time.

Comments