We celebrated our 16th birthday last week by sharing how we’re building a better Internet for today’s world. As Matthew and Michelle reflected in this year’s Founders’ Letter, this year saw some of the most consequential changes in the history of the Internet.
For the first time, automated traffic surpassed human activity. AI is empowering people to build like never before, leading the Internet to grow massively in scale and unlocking more ambition and creativity. As we witnessed the influence that agent-driven recommendations have on consumer choices, we identified the need for a new approach that creates space for new businesses to succeed. Each day of Birthday Week explored a different way we are helping to build the future of the Internet. We began on Monday by strengthening our commitment to open source. Tuesday focused on application security and the post-quantum transition. On Wednesday, we explored new economic models for the agentic Internet. Thursday, we expanded the Developer Platform with new tools for data analysis, storage, AI, and agent development. Finally, we closed out the week by launching features that make Cloudflare faster, easier to operate, and more accessible to everyone. As a special Birthday Week follow-up, we shared an update on our intern program, one year after announcing our goal to hire 1,111 interns. Interns directly contributed to many of the projects launched this week, including EmDash, post-quantum visibility, CryptoLabe, and Protected Quick Tunnels.
We shipped 46 announcements this week. In case you missed any, here’s the full list of everything we announced during Birthday Week 2026.
Monday, September 28 - Commitment to open source
With the announcement of our new CLI, which we released alongside the pipeline we use to generate it and our SDKs and docs, we shared how we’re building to support agents and developers as they use Cloudflare — and supporting the projects that you rely on, too.
| What | In a sentence… | | Introducing cf: the agentic CLI for the entire Cloudflare API | The new cf CLI mirrors the Cloudflare API, uses JSON-first output and typed configuration, and gives people and agents one consistent command-line interface. | | Introducing Forge: the open source pipeline for generating SDKs, CLIs, docs, and more | Forge is a pluggable, open-source pipeline that runs in CI to generate SDKs, CLIs, documentation, and other interfaces directly from API definitions. | | Introducing EmDash - the spiritual successor to WordPress that solves plugin security | EmDash is an open-source, Astro-based serverless CMS that runs plugins in isolated Worker sandboxes with explicitly approved capabilities. | | Four months of VoidZero at Cloudflare: making the open-source JavaScript toolchain faster for all humans and agents | Since joining Cloudflare, VoidZero has delivered more than 80 releases across the Vite ecosystem, and its previously commercial Void platform will become fully open source. | | Next.js applications, powered by Vite: introducing Vinext 1.0 | Vinext 1.0 turns an AI-built experiment into a production-ready, portable way to run Next.js applications on Vite. | | The road to the agentic browser: A Kitesurf update | Kitesurf, our Workers-based browser for agents, adds WebMCP support, faster DOM operations, broader web compatibility, and terminal-based rendering. | | How fast is the web? Explore billions of real-user measurements with BEACON | BEACON makes billions of anonymized real-user performance measurements from 10,000 major websites available as a public BigQuery dataset. | | Supporting native Rust in Workers with the new Emscripten target for wasm-bindgen | Experimental Emscripten target support lets developers bring more native Rust libraries and applications, including progress toward Tokio support, to Workers. | | Introducing The Cold Start: pitch your startup live at Cloudflare Connect | The Cold Start gives five early-stage companies the opportunity to pitch live at Cloudflare Connect and compete for resources to help them grow. |
Tuesday, September 29 - Helping secure the agentic Internet
Technological progress is rapidly changing how we think about application security. We announced our intention to become a certificate authority, as well as how we’re preparing foundational Internet cryptography for the post-quantum era and adapting application security to counter AI-driven attacks.
| What | In a sentence… | | Building a certificate authority for the whole Internet | Twelve years after launching Universal SSL, Cloudflare announced its intention to become a public certificate authority (CA) and add resilience to free, automated certificate issuance. | | Building a post-quantum certificate authority with Merkle Tree Certificates | Our planned CA will issue free Merkle Tree Certificates designed to make post-quantum authentication practical without imposing large certificate and handshake costs. | | Using AI to chart a course for our post-quantum migration | CryptoLabe uses AI to find and classify cryptography across our codebase as Cloudflare works toward completing its post-quantum migration by 2029. | | Preventing quantum downgrade attacks against IPsec | Cloudflare helped develop an IETF extension that authenticates the full IKEv2 transcript and prevents attackers from downgrading post-quantum IPsec tunnels. | | Is your domain using post-quantum encryption? Now you can see for yourself | HTTP Analytics, Log Explorer, and Logpush now show whether requests negotiated post-quantum key exchange, giving customers evidence they can inspect and report. | | Enforce positive security with Cloudflare Application Profiles | Application Profiles learns the expected structure of HTTP requests so customers can identify deviations and enforce what valid application traffic should look like. | | We tested our own WAF with frontier AI models. Here's what we found | An adaptive AI red-team system found WAF detection gaps across six attack categories, helping us improve normalization and managed rules for customers. | | Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account | Threat Signals turns open-source reporting into structured indicators and connects the context to WAF rules, while the Threat Events Platform expands to every account. | | Adaptive application security for the AI era: how Cloudflare connects code, traffic, and intelligence to stop attacks | Our application-security framework connects discovery, governance, runtime protection, investigation, and response in a continuous learning loop. |
Wednesday, September 30 - Powering the agent economy
With our announcements of Pay Per Use and the release of our Monetization Gateway in beta, we shared how we’re building support for a new economic model that empowers creators to monetize their content and services.
| What | In a sentence… | | The Internet has a second audience | AI agent requests have grown rapidly, and our strategy helps creators see agents, set terms for access, and get paid when agents use their work. | | Cloudflare Containers, rebuilt to scale agent sandboxes | Containers now has faster startup, flexible image and instance selection, new scheduling controls, and filesystem snapshots for persistent agent workspaces. | | Monetization Gateway beta: charge AI agents for consumption with HTTP 402 | Monetization Gateway lets sellers put a price on resources behind Cloudflare and collect agent payments using HTTP 402 and x402. | | Pay Per Use: when AI uses your work, you should get paid | Pay Per Use gives enrolled publishers usage reports, billing, and payouts when verified AI buyers use their content. | | Simplifying domains for people and agents | A new domain-search experience and expanded Registrar APIs make it easier for both people and agents to search, register, transfer, and manage domains. | | Identify AI model overuse with User Insights | AI Gateway User Insights identifies tasks, model fit, and overuse, so teams can understand where a smaller or less expensive model may work. | | Detect and send production issues straight to your agent | Issues groups Workers errors and sends the relevant stack traces, logs, and traces to coding agents or any webhook for faster investigation. | | Cut your AI spend with AI Gateway's Auto Router | Auto Router classifies each request at the edge and sends it to a suitable model, reducing cost while preserving response quality. | | Cloudflare Impact reaches $100 million in donations | Initiatives including Project Galileo, the Athenian Project, and Cloudflare for Campaigns have now delivered more than $100 million in donated services. |
Thursday, October 1 - Bringing more of the developer stack to Cloudflare
We expanded what is possible to achieve on Cloudflare’s platform with the general availability launch of Cloudflare Basin, our data analytics platform, the launch of K2, a durable serverless event stream, and the announcement of our new contest — inviting developers to build a Git platform designed for agentic development.
| What | In a sentence… | | Introducing Cloudflare Basin: an open, serverless data platform, now generally available | Basin is now generally available, giving developers a serverless platform built on Apache Iceberg and R2 for ingesting, managing, and querying large datasets. | | Support for modern cryptographic algorithms in Workers | Workers adds opt-in native Web Crypto support for ML-KEM and ML-DSA, giving developers post-quantum primitives without bundling their own implementations. | | AI Search is now generally available | AI Search reaches general availability with visual search, OCR for scanned PDFs, larger files, and support for any chat model. | | We want you to build the next Git platform on Cloudflare | Artifacts enters open beta and a new competition invites developers to build a Git platform designed for the era of AI agents. | | Announcing Cloudflare K2: serverless event streams | K2 provides durable, ordered event streams on R2, separating producers and consumers without the operational overhead of managing broker clusters. | | Cloudflare OS: your company's agent workspace, managed for you | Cloudflare OS provides an agent workspace connected to an organization’s data and systems, with a waitlist open for fully managed deployments. | | Introducing Workers KV Instant - powered by Quicksilver | Workers KV Instant delivers sub-two-millisecond p99 reads and fast global replication across more than 300 locations using the familiar Workers KV API. | | One year later: Sovereign AI and the fight for choice | We are expanding local open-source model choice and model-agnostic security tools, so nations can pursue AI sovereignty without isolation. | | Introducing Clef: our open-source decision models, and new RL fine-tuning platform | Clef and Clef-flash are open-source decision models for fast classification and agent workflows, accompanied by a platform for reinforcement-learning fine-tuning. |
Friday, October 2 - Delivering a faster, simpler Internet for everyone
We wrapped up the week with major updates to Cloudflare Observability, alongside adding Cloudflare Traces, network performance improvements that make Cloudflare faster, and an announcement on how we’re supporting civil society organizations.
| What | In a sentence… | | 8 major updates to Cloudflare Observability | Eight updates bring logs, traces, analytics, alerts, dashboards, querying, and telemetry export into one observability platform with simpler pricing. | | Introducing Cloudflare Traces: follow requests through our entire platform | Cloudflare Traces provides request-level visibility across security rules, transformations, cache, Workers, services, and origins without requiring an agent or SDK. | | Updates on our pledge to make Cloudflare features accessible to everyone | One year after our pledge, Logpush, multi-account governance, higher platform limits, and other capabilities are available to more customers across plans. | | Announcing Cloudflare OHTTP Gateway - expanding access to Cloudflare's privacy-preserving infrastructure | A self-serve OHTTP Gateway enters closed beta, while Privacy Gateway becomes Cloudflare OHTTP Relay to distinguish the two roles. | | Follow the thread: a new dashboard to investigate account abuse | Account Abuse Protection uses stateful analysis and privacy-preserving Hashed User IDs to help teams investigate credential stuffing and fake-account creation. | | Protected Quick Tunnels: simple accountless authentication for your next dev project | Quick Tunnels now support email authentication, letting developers share a local application with selected people or domains without requiring Cloudflare accounts. | | Building for good: How civil society organizations are automating on Cloudflare | Civil society organizations are using Cloudflare’s developer platform to automate and scale work that protects human rights and the public interest. | | 2026 Birthday week: network performance update | Using an expanded real-user measurement methodology, Cloudflare now ranks as the fastest provider across 74% of the top 1,000 networks. | | Introducing Web Search API via AI Gateway | AI Gateway’s Web Search API brings current web context from multiple providers into model calls through REST APIs, Workers bindings, or customer-managed keys. | | Streamline: custom video pipelines with Cloudflare Stream and Workers | Streamline is an open-source example for building continuous video pipelines by combining Workers, Durable Objects, and a containerized media engine. |
Building the Internet’s next chapter together
Across this week’s announcements, we kept returning to a consistent theme: the Internet should continue to open up more opportunities for people to create, contribute, and succeed. That means open tools developers can shape, security that keeps pace with new threats, a fairer exchange between agents and the people whose work they use, and infrastructure designed for the agentic Internet.
For 16 years, we have been building alongside developers, creators, researchers, customers, partners, and open-source communities. Your ideas, feedback, and willingness to challenge us have shaped Cloudflare, and that collaboration matters now more than ever.