[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f78cd6qi4oore":3,"$fanuq43nlrv5g":57},{"slug":4,"title":5,"body":6,"summary":7,"tags":8,"author":15,"cover_url":16,"published_at":17,"seo_title":18,"seo_description":19,"reading_minutes":20,"related":21},"agentic-inbox-cloudflare-setup","Self-host an AI email agent on Cloudflare Workers: agentic-inbox set up and costed","\u003Cp>Cloudflare open-sourced \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fcloudflare\u002Fagentic-inbox\">agentic-inbox\u003C\u002Fa>, a complete email client that runs on your own Cloudflare account. Inbound mail arrives through Email Routing, each mailbox is a Durable Object with its own SQLite database, attachments go to R2, and an Agents SDK agent reads new mail and writes a draft reply. It never sends on its own; you review the draft and send it yourself.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6abd987c595e0a740c5d1bf0\">\u003Cvideo src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd987d595e0a740c5d1bf6-0-5467f819.mp4\" autoplay muted loop playsinline preload=\"metadata\">\u003C\u002Fvideo>\u003C\u002Ffigure>\n\n\u003Cp>The Deploy button handles only part of the setup. The README warns that you must also complete the \"After deploying\" steps, and most failed installs skip them. This guide walks through all of the steps, then works out the cost from Cloudflare's published prices.\u003C\u002Fp>\n\n\u003Ch2>What you are deploying\u003C\u002Fh2>\n\n\u003Cp>Everything below comes from the repo's \u003Ccode>wrangler.jsonc\u003C\u002Fcode> and \u003Ccode>workers\u002F\u003C\u002Fcode> source (commit \u003Ccode>48039bb\u003C\u002Fcode>, April 2026):\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6abd88ddc951ea7137fa3791\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88ddc951ea7137fa3796-0-d79685f8.png\" alt=\"A conceptual visualization of an AI-powered email system.\" loading=\"lazy\">\u003Cfigcaption>A conceptual visualization of an AI-powered email system.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\n\u003Cul>\n\u003Cli>\u003Cstrong>One Worker\u003C\u002Fstrong> (\u003Ccode>workers\u002Fapp.ts\u003C\u002Fcode>), built with Hono and React Router. It serves the UI and API, and its \u003Ccode>email()\u003C\u002Fcode> handler receives mail from Email Routing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Three SQLite-backed Durable Object classes\u003C\u002Fstrong>: \u003Ccode>MailboxDO\u003C\u002Fcode> (one per mailbox, stores the emails), \u003Ccode>EmailAgent\u003C\u002Fcode> (one per mailbox, an \u003Ccode>AIChatAgent\u003C\u002Fcode> with 9 email tools) and \u003Ccode>EmailMCP\u003C\u002Fcode> (an MCP server at \u003Ccode>\u002Fmcp\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bindings\u003C\u002Fstrong>: \u003Ccode>BUCKET\u003C\u002Fcode> (R2 bucket \u003Ccode>agentic-inbox\u003C\u002Fcode>), \u003Ccode>AI\u003C\u002Fcode> (Workers AI) and \u003Ccode>EMAIL\u003C\u002Fcode> (a \u003Ccode>send_email\u003C\u002Fcode> binding for outbound mail).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Models\u003C\u002Fstrong>: the agent uses \u003Ccode>@cf\u002Fmoonshotai\u002Fkimi-k2.5\u003C\u002Fcode>. Before any draft is written, a prompt-injection check runs on \u003Ccode>@cf\u002Fmeta\u002Fllama-3.1-8b-instruct-fast\u003C\u002Fcode>. When the model returns the draft as plain text instead of calling the draft tool, \u003Ccode>@cf\u002Fmeta\u002Fllama-4-scout-17b-16e-instruct\u003C\u002Fcode> cleans that text up.\u003C\u002Fli>\n\u003C\u002Ful>\n\n\u003Cp>Prerequisites: a Cloudflare account with a domain on \u003Cstrong>Cloudflare DNS\u003C\u002Fstrong>. Email Routing does not work without it. You also need Node.js and npm for the deploy, a Cloudflare Zero Trust organization (created the first time you open Zero Trust in the dashboard) for Access, and, for the latency check at the end, the \u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fcloudflare-one\u002Fconnections\u002Fconnect-networks\u002Fdownloads\u002F\">cloudflared\u003C\u002Fa> CLI.\u003C\u002Fp>\n\n\u003Ch2>Step 1: Deploy\u003C\u002Fh2>\n\n\u003Cp>The simplest route is the Deploy to Cloudflare button in the README. It creates R2, Durable Objects and Workers AI for you and asks for \u003Ccode>DOMAINS\u003C\u002Fcode>, the domain that will receive your mail (for example \u003Ccode>example.com\u003C\u002Fcode>). To deploy from the CLI instead:\u003C\u002Fp>\n\n\u003Cpre>\u003Ccode>git clone https:\u002F\u002Fgithub.com\u002Fcloudflare\u002Fagentic-inbox\ncd agentic-inbox\nnpm install\nnpx wrangler r2 bucket create agentic-inbox\n# edit wrangler.jsonc: \"vars\": { \"DOMAINS\": \"yourdomain.com\", ... }\nnpm run deploy\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cp>\u003Ccode>npm run deploy\u003C\u002Fcode> runs \u003Ccode>npm run build &amp;&amp; wrangler deploy\u003C\u002Fcode>, where \u003Ccode>build\u003C\u002Fcode> is \u003Ccode>react-router build\u003C\u002Fcode>. You can also set \u003Ccode>EMAIL_ADDRESSES\u003C\u002Fcode> in \u003Ccode>vars\u003C\u002Fcode>. When it holds values, the Worker accepts mail only for those addresses and creates mailboxes only for them.\u003C\u002Fp>\n\n\u003Ch2>Step 2: Turn on Cloudflare Access (required)\u003C\u002Fh2>\n\n\u003Cp>This step is required, not optional hardening. Outside local dev, the Worker's middleware fails closed. When \u003Ccode>POLICY_AUD\u003C\u002Fcode> or \u003Ccode>TEAM_DOMAIN\u003C\u002Fcode> is missing, every request gets a 500 with \u003Ccode>Cloudflare Access must be configured in production\u003C\u002Fcode>. When a request has no valid Access JWT, it gets a 403.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6abd88ddc951ea7137fa379b\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88ddc951ea7137fa37a0-0-e0ff4435.png\" alt=\"An illustration representing secure access and authentication layers.\" loading=\"lazy\">\u003Cfigcaption>An illustration representing secure access and authentication layers.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\n\u003Col>\n\u003Cli>In the dashboard, open the Worker and go to \u003Cstrong>Settings &gt; Domains &amp; Routes\u003C\u002Fstrong>. Enable \u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fchangelog\u002Fpost\u002F2025-10-03-one-click-access-for-workers\u002F\">one-click Cloudflare Access\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>The modal shows two values, \u003Ccode>POLICY_AUD\u003C\u002Fcode> and \u003Ccode>TEAM_DOMAIN\u003C\u002Fcode>. Store both as secrets:\u003C\u002Fli>\n\u003C\u002Fol>\n\n\u003Cpre>\u003Ccode>npx wrangler secret put POLICY_AUD\nnpx wrangler secret put TEAM_DOMAIN\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cp>\u003Ccode>TEAM_DOMAIN\u003C\u002Fcode> accepts either the team URL (\u003Ccode>https:\u002F\u002Fyour-team.cloudflareaccess.com\u003C\u002Fcode>) or the full \u003Ccode>...\u002Fcdn-cgi\u002Faccess\u002Fcerts\u003C\u002Fcode> URL. If you later see \u003Ccode>Invalid or expired Access token\u003C\u002Fcode>, the README's fix is to turn Access off and on again, then re-set both secrets from the new modal.\u003C\u002Fp>\n\n\u003Cp>\u003Cstrong>The trust model:\u003C\u002Fstrong> anyone who passes your Access policy can read \u003Cem>every\u003C\u002Fem> mailbox, including through the \u003Ccode>\u002Fmcp\u003C\u002Fcode> endpoint by passing a \u003Ccode>mailboxId\u003C\u002Fcode>. The app has no per-mailbox authorization. Write the Access policy with that in mind.\u003C\u002Fp>\n\n\u003Ch2>Step 3: Enable Email Service for sending\u003C\u002Fh2>\n\n\u003Cp>The Worker sends outbound mail through the \u003Ccode>EMAIL\u003C\u002Fcode> \u003Ccode>send_email\u003C\u002Fcode> binding. In the maintainers' \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fcloudflare\u002Fagentic-inbox\u002Fissues\u002F4#issuecomment-4269118513\">step-by-step guide\u003C\u002Fa>, enabling email sending for your domain is a separate step. Do it for the same domain you entered as \u003Ccode>DOMAINS\u003C\u002Fcode>. According to the \u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Femail-service\u002Fplatform\u002Fpricing\u002F\">Email Service pricing page\u003C\u002Fa>, sending to arbitrary recipients requires the Workers Paid plan.\u003C\u002Fp>\n\n\u003Ch2>Step 4: Route inbound mail to the Worker\u003C\u002Fh2>\n\n\u003Col>\n\u003Cli>Go to \u003Cstrong>Compute &gt; Email Service &gt; Email Routing\u003C\u002Fstrong>, choose \u003Cstrong>Onboard Domain\u003C\u002Fstrong>, pick your domain and accept the DNS records. Cloudflare adds MX, SPF and DKIM records.\u003C\u002Fli>\n\u003Cli>Open \u003Cstrong>Routing Rules\u003C\u002Fstrong>, enable the \u003Cstrong>Catch-all rule\u003C\u002Fstrong>, set the action to \u003Cstrong>Send to a Worker\u003C\u002Fstrong>, choose \u003Ccode>agentic-inbox\u003C\u002Fcode> and save. If you want only some addresses handled by the app, create per-address rules instead of the catch-all.\u003C\u002Fli>\n\n\u003C\u002Fol>\n\u003Cblockquote>\u003Cp>\u003Cstrong>Watch the catch-all.\u003C\u002Fstrong> Every message the Worker receives for an existing mailbox triggers an auto-draft (\u003Ccode>receiveEmail()\u003C\u002Fcode> calls the agent's \u003Ccode>onNewEmail\u003C\u002Fcode> through \u003Ccode>ctx.waitUntil\u003C\u002Fcode>), and each draft is a Workers AI call. A catch-all on a domain that gets a lot of spam turns that spam into AI spend. Prefer per-address rules for the mailboxes you actually use.\u003C\u002Fp>\u003C\u002Fblockquote>\n\n\u003Ch2>Step 5: Create the mailbox before you test\u003C\u002Fh2>\n\n\u003Cp>This is the step people miss most often. \u003Ccode>receiveEmail()\u003C\u002Fcode> looks for \u003Ccode>mailboxes\u002F&lt;address&gt;.json\u003C\u002Fcode> in R2. If that object is missing, the message is dropped and the only trace is this log line:\u003C\u002Fp>\n\n\u003Cpre>\u003Ccode>Ignoring email for hello@yourdomain.com: mailbox does not exist\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cp>The sender gets no bounce, because the handler returns normally. So open the deployed app, create a mailbox (for example \u003Ccode>hello@yourdomain.com\u003C\u002Fcode>), and only then send a test message to it.\u003C\u002Fp>\n\n\u003Ch2>Step 6: Watch it work\u003C\u002Fh2>\n\n\u003Cpre>\u003Ccode>npx wrangler tail agentic-inbox --format pretty\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cp>Send a test message from an outside address. The tail shows the \u003Ccode>email\u003C\u002Fcode> invocation, followed by the \u003Ccode>EmailAgent\u003C\u002Fcode> call to \u003Ccode>\u002FonNewEmail\u003C\u002Fcode>. If the injection scanner flags the message, or the scanner itself fails, you will see \u003Ccode>Skipping auto-draft due to detected prompt injection\u003C\u002Fcode>. The code fails closed here: the email is still saved, but no draft is written.\u003C\u002Fp>\n\n\u003Ch3>Measure draft latency yourself\u003C\u002Fh3>\n\n\u003Cp>Both timestamps are server-side. The inbox copy's \u003Ccode>date\u003C\u002Fcode> is set to \u003Ccode>new Date()\u003C\u002Fcode> when the message is received (the source comments that it \"uses receive time, not the email's Date header\"). The draft's \u003Ccode>date\u003C\u002Fcode> is set to \u003Ccode>new Date()\u003C\u002Fcode> when \u003Ccode>draft_reply\u003C\u002Fcode> saves it. Subtract the first from the second to get the time from arrival to saved draft. The API sits behind Access, so call it with \u003Ccode>cloudflared\u003C\u002Fcode>:\u003C\u002Fp>\n\n\u003Cpre>\u003Ccode>BASE=https:\u002F\u002Fagentic-inbox.&lt;your-subdomain&gt;.workers.dev\nMB=hello@yourdomain.com\ncloudflared access login \"$BASE\"\ncloudflared access curl \"$BASE\u002Fapi\u002Fv1\u002Fmailboxes\u002F$MB\u002Femails?folder=inbox&amp;limit=5\"\ncloudflared access curl \"$BASE\u002Fapi\u002Fv1\u002Fmailboxes\u002F$MB\u002Femails?folder=draft&amp;limit=5\"\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cp>Match the two messages on \u003Ccode>thread_id\u003C\u002Fcode> and compare their \u003Ccode>date\u003C\u002Fcode> fields. We have not deployed this ourselves, so we have no number to report. Run it on your own traffic.\u003C\u002Fp>\n\n\u003Ch2>What it costs\u003C\u002Fh2>\n\n\u003Cp>All prices below are copied from Cloudflare's pricing pages as of this writing. Check the linked pages before you budget.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6abd88ddc951ea7137fa37a5\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88dec951ea7137fa37aa-0-b6596a6d.png\" alt=\"A representation of calculating operational costs and resource usage.\" loading=\"lazy\">\u003Cfigcaption>A representation of calculating operational costs and resource usage.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\n\u003Cul>\n\u003Cli>\u003Cstrong>Workers Paid\u003C\u002Fstrong>: \"$5 USD per month\" per account. Includes 10 million requests and 30 million CPU ms per month, then $0.30 per additional million requests and $0.02 per additional million CPU ms. (\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002Fplatform\u002Fpricing\u002F\">Workers pricing\u003C\u002Fa>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Service\u003C\u002Fstrong>: receiving through Email Routing is \"Unlimited\" on both plans. Sending is \"Not available\" on Workers Free. On Workers Paid, 3,000 emails per month are included, then $0.35 per 1,000. Sends to verified destination addresses in your own account are free. (\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Femail-service\u002Fplatform\u002Fpricing\u002F\">Email Service pricing\u003C\u002Fa>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Durable Objects (Paid)\u003C\u002Fstrong>: 1 million requests per month included, then $0.15 per million. 400,000 GB-s included, then $12.50 per million GB-s. SQLite storage: first 25 billion row reads per month included (then $0.001 per million), first 50 million row writes included (then $1.00 per million), and 5 GB-month of stored data (then $0.20 per GB-month). Incoming WebSocket messages, which is how the agent panel communicates, are billed at a 20:1 ratio. (\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fdurable-objects\u002Fplatform\u002Fpricing\u002F\">Durable Objects pricing\u003C\u002Fa>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>R2 Standard\u003C\u002Fstrong>: $0.015 per GB-month, with 10 GB-month free. Class A operations cost $4.50 per million and Class B $0.36 per million, with 1M and 10M free respectively. Egress is free. (\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fr2\u002Fpricing\u002F\">R2 pricing\u003C\u002Fa>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Workers AI\u003C\u002Fstrong>: 10,000 Neurons per day free (one account-wide pool shared by every model, so the Kimi drafts, the Llama 3.1 scanner and the Llama 4 Scout cleanup all draw from it), then $0.011 per 1,000 Neurons. \u003Ccode>kimi-k2.5\u003C\u002Fcode> costs $0.600 per M input tokens, $0.100 per M cached input tokens and $3.000 per M output tokens (54,545 \u002F 9,091 \u002F 272,727 neurons per M). \u003Ccode>llama-4-scout-17b-16e-instruct\u003C\u002Fcode> costs $0.270 per M input and $0.850 per M output. The pricing table does not list the exact \u003Ccode>llama-3.1-8b-instruct-fast\u003C\u002Fcode> ID the scanner calls. The closest entry, \u003Ccode>llama-3.1-8b-instruct-fp8-fast\u003C\u002Fcode>, is $0.045 per M input and $0.384 per M output. (\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers-ai\u002Fplatform\u002Fpricing\u002F\">Workers AI pricing\u003C\u002Fa>)\u003C\u002Fli>\n\u003C\u002Ful>\n\n\u003Ch3>Per-draft AI cost: the formula\u003C\u002Fh3>\n\n\u003Cp>Kimi does the drafting, so it dominates the cost. The auto-draft call can run for up to 5 steps (\u003Ccode>stopWhen: stepCountIs(5)\u003C\u002Fcode>), and each tool round trip sends the context again. That makes a fixed per-email token count impossible to predict. Use this formula instead:\u003C\u002Fp>\n\n\u003Cpre>\u003Ccode>cost ≈ input_tokens × $0.60\u002FM + output_tokens × $3.00\u002FM   (kimi-k2.5, uncached)\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cp>A \u003Cem>hypothetical\u003C\u002Fem> draft that uses 5,000 input tokens and 500 output tokens comes to $0.003 + $0.0015 = \u003Cstrong>$0.0045\u003C\u002Fstrong>. That is about 409 neurons, so the 10,000-neuron daily free allocation would cover at most roughly 24 drafts of that size before you start paying. The injection scan on every incoming message (and any Llama 4 Scout cleanup) comes out of the same pool, so the real number is somewhat lower. These token counts are an illustration, not a measurement. To get your real numbers, check Workers AI usage in the dashboard after a day of real mail.\u003C\u002Fp>\n\n\u003Cp>\u003Cstrong>Bottom line:\u003C\u002Fstrong> because sending requires Workers Paid, the realistic minimum is \u003Cstrong>$5 per month\u003C\u002Fstrong>. A personal inbox is likely to stay inside the included Durable Object, R2 and email allowances. Beyond that, you pay per token for Kimi drafts once the daily free Neurons run out.\u003C\u002Fp>\n\n\u003Ch2>Checklist\u003C\u002Fh2>\n\n\u003Col>\n\u003Cli>Domain on Cloudflare DNS; deploy with \u003Ccode>DOMAINS\u003C\u002Fcode> set.\u003C\u002Fli>\n\u003Cli>One-click Access enabled; \u003Ccode>POLICY_AUD\u003C\u002Fcode> and \u003Ccode>TEAM_DOMAIN\u003C\u002Fcode> set as secrets.\u003C\u002Fli>\n\u003Cli>Email sending enabled for the domain (requires Workers Paid for arbitrary recipients).\u003C\u002Fli>\n\u003Cli>Email Routing onboarded; catch-all or per-address rule set to \u003Cstrong>Send to a Worker\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Mailbox created in the UI \u003Cem>before\u003C\u002Fem> the first test email.\u003C\u002Fli>\n\u003Cli>\u003Ccode>wrangler tail\u003C\u002Fcode> open while you send the test.\u003C\u002Fli>\n\u003C\u002Fol>\n\n\u003Ch2>Sources\u003C\u002Fh2>\n\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fcloudflare\u002Fagentic-inbox\">cloudflare\u002Fagentic-inbox (README, wrangler.jsonc, workers\u002F source)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fcloudflare\u002Fagentic-inbox\u002Fissues\u002F4#issuecomment-4269118513\">Maintainers' step-by-step setup comment (issue #4)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fchangelog\u002Fpost\u002F2025-10-03-one-click-access-for-workers\u002F\">One-click Cloudflare Access for Workers\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Femail-routing\u002Fget-started\u002Fenable-email-routing\u002F\">Enable Email Routing\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Femail-routing\u002Fsetup\u002Femail-routing-addresses\u002F\">Email Routing addresses and catch-all rules\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002Fplatform\u002Fpricing\u002F\">Workers pricing\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Femail-service\u002Fplatform\u002Fpricing\u002F\">Email Service pricing\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fdurable-objects\u002Fplatform\u002Fpricing\u002F\">Durable Objects pricing\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fr2\u002Fpricing\u002F\">R2 pricing\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers-ai\u002Fplatform\u002Fpricing\u002F\">Workers AI pricing\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>","Cloudflare's open-source agentic-inbox runs a full email client on Workers, with one SQLite Durable Object per mailbox and a Kimi K2.5 agent that drafts replies. Covers the post-deploy steps people miss (Access, sending, routing, mailbox first) and the cost.",[9,10,11,12,13,14],"cloudflare","workers","ai-agents","email","self-hosting","ai-assisted","if.codes","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88dac951ea7137fa378b-0-5b0ec96d.png","2026-10-01T08:17:18.646Z","Self-host agentic-inbox on Cloudflare Workers: setup and cost","Deploy Cloudflare's agentic-inbox AI email agent: Access secrets, Email Routing, sending, the mailbox gotcha, and what Workers, DO, R2 and Workers AI cost.",8,[22,36,47],{"slug":23,"title":24,"type":25,"summary":26,"tags":27,"author":15,"cover_url":33,"published_at":34,"updated_at":35},"audit-ai-agent-public-traces","Nearly a million leaked links: auditing what your AI agents leave on the public web","blog","OpenAI's agent swarm left almost a million public shortener URLs holding credentials. Here's a tested shell + gitleaks audit to find the shortlinks, pastes and webhooks your own agents created, scan them for secrets and close the channels.",[28,29,30,31,32,14],"security","agents","secrets","gitleaks","llm","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaad873e21d5cbd14d4397-0-0f4f51f7.png","2026-10-01T07:43:19.642Z","2026-10-01T08:44:43.041Z",{"slug":37,"title":38,"type":25,"summary":39,"tags":40,"author":15,"cover_url":44,"published_at":45,"updated_at":46},"mikrotrick-check-patch-mikrotik","MikroTrick: check and patch your MikroTik in 15 minutes","Two chained RouterOS bugs give anyone who can reach SSH full admin, no password needed, and attacks started before the patch. Find exposed SSH, check the version, grep for the published IoCs, patch and move management behind WireGuard.",[28,41,42,43,13,14],"mikrotik","routeros","ssh","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c0838b650cb96b3d10-0-6cd107e0.png","2026-10-01T07:02:15.03Z","2026-10-01T08:44:41.391Z",{"slug":48,"title":49,"type":25,"summary":50,"tags":51,"author":15,"cover_url":54,"published_at":55,"updated_at":56},"agent-sandbox-dns-egress-lockdown","Your agent sandbox leaks through DNS: lock down egress in 15 minutes","An OpenAI model escaped its sandbox by tunnelling questions through DNS. Here is a tested Docker Compose setup for coding agents: a DNS allowlist, a logging egress proxy and a kill switch that actually fires.",[28,52,29,53,13,14],"docker","dns","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaca13e21d5cbd14d4306-0-cb93fe1b.png","2026-10-01T03:00:15.943Z","2026-10-01T08:44:43.165Z",[58,61,63,65,67,80,92,101,113,124,133,144],{"slug":4,"title":5,"type":25,"summary":7,"tags":59,"author":15,"cover_url":16,"published_at":17,"updated_at":60,"reading_minutes":20},[9,10,11,12,13,14],"2026-10-01T08:44:42.528Z",{"slug":23,"title":24,"type":25,"summary":26,"tags":62,"author":15,"cover_url":33,"published_at":34,"updated_at":35,"reading_minutes":20},[28,29,30,31,32,14],{"slug":37,"title":38,"type":25,"summary":39,"tags":64,"author":15,"cover_url":44,"published_at":45,"updated_at":46,"reading_minutes":20},[28,41,42,43,13,14],{"slug":48,"title":49,"type":25,"summary":50,"tags":66,"author":15,"cover_url":54,"published_at":55,"updated_at":56,"reading_minutes":20},[28,52,29,53,13,14],{"slug":68,"title":69,"type":25,"summary":70,"tags":71,"author":15,"cover_url":76,"published_at":77,"updated_at":78,"reading_minutes":79},"who-blocks-ai-crawlers-robots-txt","Who blocks AI crawlers? robots.txt vs the network edge, with numbers","I scanned robots.txt on the top 300 sites: 33 of 138 block GPTBot, 14 block training but allow AI search. What each AI bot directive controls, why robots.txt is only a request, and a copy-paste policy plus nginx rule for small SaaS sites.",[72,73,74,9,75,14],"ai","robots-txt","seo","saas","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c1838b650cb96b3d1b-0-11f94198.png","2026-09-30T21:00:20.673Z","2026-10-01T08:44:41.146Z",7,{"slug":81,"title":82,"type":25,"summary":83,"tags":84,"author":15,"cover_url":88,"published_at":89,"updated_at":90,"reading_minutes":91},"bullet-time-with-first-last-frame-video","Bullet time with first\u002Flast-frame video: orbiting a frozen moment from three stills","A freeze-frame camera orbit built from generated stills: one action shot, two camera-move angles, two first\u002Flast-frame clips between them, stitched and ping-ponged. The pipeline, the seams, and where the model re-imagines the water.",[72,85,86,87],"comfyui","video-generation","flowdsl","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abae46c45201648bfd477a7-0-6f4d036e.png","2026-09-28T22:42:41Z","2026-09-28T22:42:41.6Z",4,{"slug":93,"title":94,"type":25,"summary":95,"tags":96,"author":15,"cover_url":98,"published_at":99,"updated_at":100,"reading_minutes":79},"an-ai-media-pipeline-that-shows-its-work","An AI media pipeline that shows its work: ComfyUI presets, FlowDSL routing and the misses","How the images on my sites are generated: four ComfyUI presets behind one Go module, job rows as state, FlowDSL flows for routing, per-post media in the admin — and the bugs and model misses I hit shipping it. This post's own images were made the same way.",[72,87,85,97],"image-generation","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6aba8ba317ceba3543925be4-0-2f6b8a5c.png","2026-09-28T15:57:50Z","2026-09-28T15:57:50.784Z",{"slug":102,"title":103,"type":25,"summary":104,"tags":105,"author":15,"cover_url":109,"published_at":110,"updated_at":111,"reading_minutes":112},"openai-embeddings-python-mongodb","Transforming Text into Vectors: OpenAI Embeddings in Python","Learn how to generate text embeddings with the OpenAI API in Python to power semantic search, recommendations, and more. Includes practical examples with MongoDB integration and cost analysis.",[106,72,107,108],"openai","python","mongodb","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c2d-0-2e60b732.png","2024-11-23T00:00:00Z","2026-09-28T22:31:01.385Z",3,{"slug":114,"title":115,"type":25,"summary":116,"tags":117,"author":15,"cover_url":120,"published_at":121,"updated_at":122,"reading_minutes":123},"check-pricing-availability-ing-domains","Last Chance to Grab Short .ING Domains: The Extended List Part II","Welcome back to the second part of our exciting exploration into the .ING domain zone! This time, I've expanded our horizons to bring you an even larger selection of .ING domain names. List of over 24,000 domain names inside.",[118,119],"domains","business","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c38-0-c55f4c8d.png","2023-12-14T00:00:00Z","2026-09-28T22:31:01.453Z",1,{"slug":125,"title":126,"type":25,"summary":127,"tags":128,"author":15,"cover_url":129,"published_at":130,"updated_at":131,"reading_minutes":132},"impressive-ing-domains","Unveiling the Impressive .ING Domains","Discover the vast potential of the new .ING domain zone in my latest blog post! I've used AI and a Python script to unearth a treasure trove of available domain names. From budget-friendly picks to exclusive premium domains, there's something for every ambition. Plus, a special list of unique, lesser-known domains awaits.",[118,119],"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c43-0-03be24b7.png","2023-12-11T00:00:00Z","2026-09-28T22:31:01.527Z",2,{"slug":134,"title":135,"type":25,"summary":136,"tags":137,"author":15,"cover_url":141,"published_at":142,"updated_at":143,"reading_minutes":112},"secured-web-server-in-5-minutes","Fortify Web Server Security in 5 Minutes with Tailscale","Tailscale revolutionizes secure networking with its user-friendly approach, effortlessly connecting devices across diverse networks.",[138,139,140],"firewall","tailscale","webserver","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c4e-0-eae6f62d.png","2023-11-03T00:00:00Z","2026-09-28T22:31:01.597Z",{"slug":145,"title":146,"type":25,"summary":147,"tags":148,"author":15,"cover_url":151,"published_at":152,"updated_at":153,"reading_minutes":154},"lets-encrypt-free-ssl","How to Secure Your Website with Free SSL Certificates for a Lifetime","Let’s Encrypt certificates have revolutionized internet security by providing free, automated, and widely trusted SSL\u002FTLS certificates. The non-profit Certificate Authority (CA) has significantly contributed to a more secure web environment by simplifying the process of securing websites with HTTPS.",[149,150,140],"ssl","https","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c59-0-bf2a9a0a.png","2023-11-01T00:00:00Z","2026-09-28T22:39:13.555Z",6]