{"slug": "talorys-a-self-hosted-personal-ai-agent-on-cloudflare-s-free-tier", "title": "Talorys – A self-hosted personal AI agent on Cloudflare's free tier", "summary": "Talorys launched as a free, open-source personal AI agent that runs entirely inside a user's own Cloudflare account, installed via the command `npx create-talorys@latest`. The agent uses Cloudflare Pages, Workers, SQLite-backed Durable Objects and Workers AI's `@cf/zai-org/glm-4.7-flash` model for streaming chat and tool calling, and provisions no paid services such as R2, D1, KV, Vectorize, AI Search or Workflows. The installer requires Node.js 20.18+, hashes the owner password locally with PBKDF2-SHA256, generates a 256-bit session secret, and deploys a private Worker with `workers_dev: false` and `preview_urls: false` so it has no public URL.", "body_md": "**Your personal AI agent. Your own cloud.**\n\nTalorys is a free, open-source personal AI assistant that runs entirely inside\n**your own Cloudflare account**. It chats with you, remembers what matters,\nmanages tasks, notes and projects, and runs reminders and routines on a\nschedule — without any server, database or account operated by the Talorys\ndevelopers.\n\nOne person. One Cloudflare account. One command. One personal AI agent.\n\n```\nnpx create-talorys@latest\n```\n\n- **A private assistant** — chat with streaming responses, Markdown and tool activity indicators.\n- **Memory** — durable personal facts and preferences you can view, edit and delete. Only the most relevant memories are sent to the model on each turn.\n- **Tasks, notes and projects** — full CRUD in the UI, and from chat (\"Add a task to review my project tomorrow\").\n- **Automations** — one-time and recurring reminders, daily task digests and optional AI routines, delivered to an in-app notification center. They run on Durable Object alarms, so nothing has to stay online.\n- **Single-user by design** — no signup, no accounts, no teams. The installer sets the owner password.\n- **Works without AI** — tasks, notes, memories and reminders keep working if Workers AI is unavailable or your free quota is used up.\n\n| Chat with tool activity | Tasks | \n|---|---|\n| **Memory (dark mode)** | **Automations** | \n\n```\nBrowser ──HTTPS──▶ Cloudflare Pages (React app + /api Pages Function)\n                         │  service binding (no public URL)\n                         ▼\n                   Private Worker (Hono router)\n                         │  getAgentByName(\"personal-agent\")\n                         ▼\n                   TalorysAgent — Cloudflare Agents SDK Durable Object\n                     ├─ SQLite: conversations, memories, tasks, notes, projects,\n                     │          automations, sessions, settings, usage\n                     ├─ Workers AI: @cf/zai-org/glm-4.7-flash (streaming + tool calling)\n                     └─ Alarms: reminders and recurring schedules\n```\n\n- The browser only ever talks to your `*.pages.dev` site.`/api/*` requests run a\nPages Function that forwards them over a**service binding** to the agent Worker.\n- The agent Worker is deployed with `workers_dev: false` and`preview_urls: false` :\nit has**no public URL** .\n- Authentication and authorization happen in the Worker, not the frontend.\n- Chat responses stream as Server-Sent Events end-to-end.\n\nMore detail: [docs/architecture.md](https://github.com/rociiu/talorys/blob/main/docs/architecture.md).\n\n| Service | Used for | Free plan | \n|---|---|---|\n| Cloudflare Pages | Frontend + Pages Function | Yes | \n| Cloudflare Workers | Private API Worker | Yes | \n| Durable Objects (SQLite) | All data, scheduling alarms | Yes | \n| Workers AI | Chat model ( `@cf/zai-org/glm-4.7-flash` ) | Yes, daily allocation | \n\nTalorys does **not** provision R2, D1, KV, Vectorize, AI Search, Workflows or any\npaid service.\n\n```\nnpx create-talorys@latest\n```\n\nThe installer:\n\n1. Checks Node.js (20.18+) and uses its bundled Wrangler CLI (any globally installed `wrangler` /`cf` is detected but not required).\n2. Verifies your Cloudflare login, or **opens Cloudflare's authorization page in your browser** .\n3. Lets you choose an account (if you have several) and an agent name.\n4. Asks for an owner password (hidden input, strength-checked). It is hashed locally with PBKDF2-SHA256 and stored only as a Cloudflare secret.\n5. Generates a 256-bit session secret and unique resource names (`talorys-<id>-agent` ,`talorys-<id>-web` ).\n6. Deploys the private Worker (creating its SQLite Durable Object), stores secrets, creates and deploys the Pages project with the service binding.\n7. Verifies the live deployment (frontend, auth endpoint, unauthenticated rejection, storage health) **without** running any AI inference.\n8. Prints the real `https://….pages.dev` URL reported by Cloudflare.\n\nIt writes a `talorys/` directory containing `talorys.json` (installation id,\naccount id, resource names, URL — **no secrets**) and the deployable artifacts.\nKeep it for updates.\n\n**Interrupted?** Run the same command again in the same place. It reconciles\nwhat already exists: no duplicate resources, no password re-prompt if the\npassword is already configured, and **no data is ever deleted**.\n\nNon-interactive installs: `TALORYS_OWNER_PASSWORD=... npx create-talorys@latest --yes --account-id <id>`\n(with `CLOUDFLARE_API_TOKEN` set if you are not logged in).\n\nBrowser login uses Wrangler's standard OAuth flow — no Global API Key. If you use an API token instead, it needs:\n\n- Account › Workers Scripts › Edit\n- Account › Cloudflare Pages › Edit\n- Account › Workers AI › Read\n- Account › Account Settings › Read\n- User › User Details › Read (optional; shows your email)\n\nSee [docs/deployment.md](https://github.com/rociiu/talorys/blob/main/docs/deployment.md).\n\nOpen the URL the installer prints, enter your owner password, and start chatting.\nSign in from any number of devices — they are all the same owner. Manage\nsessions under **Settings → Security**.\n\nForgot the password? From your `talorys/` directory:\n\n```\nnpx create-talorys@latest reset-password\n```\n\nThis replaces the password secret and signs out every device.\n\nAll data is stored in a single SQLite-backed Durable Object (`personal-agent`)\n**in your Cloudflare account**. Talorys has no telemetry, analytics, tracking or\nadvertising code and sends nothing to its developers.\n\nCloudflare processes your data to provide its services — including running Workers AI inference on your chat messages and the relevant memories included in each prompt. Review Cloudflare's privacy policy and Workers AI terms.\n\nSecurity model and threat mitigations: [docs/security.md](https://github.com/rociiu/talorys/blob/main/docs/security.md).\n\nTalorys is designed to fit the **Cloudflare Workers Free plan** and never enables\npaid features on its own. It is not \"unlimited free\", though:\n\n- Free plans have account-level quotas (requests, Durable Object usage, a daily Workers AI Neuron allocation). Quotas are set by Cloudflare and can change.\n- When the AI allocation is exhausted, chat shows a clear message and resumes after the daily reset. Everything else keeps working, and your data is untouched.\n- If your account is on a paid plan, usage beyond included amounts is billed by Cloudflare under your plan.\n\nBuilt-in guardrails (adjustable in **Settings → AI**): max output tokens, max\ncontext tokens (older history is summarized), max tool calls and reasoning\nsteps per request, max AI requests per day, and max scheduled AI runs per day.\nSimple reminders and task digests never use AI. The Usage panel shows local\n**estimates** and links to the Cloudflare dashboard for exact Neuron usage.\n\nRequirements: Node.js 20.18+.\n\n```\ngit clone https://github.com/rociiu/talorys.git\ncd talorys\nnpm install\nnpm run dev\n```\n\n`npm run dev` starts the agent Worker (`wrangler dev`, port 8787), the Pages\nFunction proxy with its service binding (`wrangler pages dev`, port 8788) and\nthe Vite UI ([http://localhost:5173](http://localhost:5173)) in one terminal. It creates\n`apps/agent/.dev.vars` with a local password (`talorys-dev-password`, override\nwith `TALORYS_DEV_PASSWORD`) and uses the deterministic mock AI provider, so no\nCloudflare login is needed. State persists in `.wrangler/state`.\n\nOther scripts: `npm run build`, `npm test`, `npm run test:e2e`, `npm run test:pack`,\n`npm run typecheck`, `npm run lint`. See [docs/development.md](https://github.com/rociiu/talorys/blob/main/docs/development.md).\n\n**Settings → Privacy → Download backup** produces `talorys-backup.json` with\nconversations, memories, tasks, notes, projects, settings and automations\n(never sessions or credentials). **Import** validates the file and merges it in\none transaction; importing the same backup twice is harmless.\n\nFrom your `talorys/` directory:\n\n```\nnpx create-talorys@latest update\n```\n\nThis redeploys the latest Worker and frontend to the **same** resources. The\nDurable Object namespace is never recreated (migrations are append-only), the\nowner password and sessions are kept, and schema migrations run automatically\nand transactionally on first request. Also available: `status` and `doctor`.\n\n| Problem | Fix | \n|---|---|\n| Installer stopped midway | Re-run the same command; it resumes. | \n| \"did not pass its health checks yet\" | New `pages.dev` sites can take a few minutes. Re-run. | \n| Permission errors | Use an account where you can edit Workers and Pages, or a token with the permissions above. | \n| Chat says the AI allocation is used up | Wait for the daily reset; or enable Demo mode in Settings → AI. | \n| Locked out after failed logins | Wait 15 minutes, or reset the password with the CLI. | \n\n`npx create-talorys@latest doctor` checks everything automatically. More in\n[docs/troubleshooting.md](https://github.com/rociiu/talorys/blob/main/docs/troubleshooting.md).\n\n```\napps/agent              Private Worker: Hono API, TalorysAgent, tools, SQLite repositories\napps/web                React + Vite app, Pages Function (functions/api/[[path]].ts)\npackages/shared         Zod schemas, types, recurrence/DST logic, password hashing\npackages/create-talorys The one-command installer (npm package)\ntests/e2e               Playwright UI tests\ntests/smoke             Optional real-account deployment test\ndocs/                   Architecture, deployment, development, security, troubleshooting\n```\n\n", "url": "https://wpnews.pro/news/talorys-a-self-hosted-personal-ai-agent-on-cloudflare-s-free-tier", "canonical_source": "https://github.com/rociiu/talorys", "published_at": "2026-10-10 10:52:09+00:00", "updated_at": "2026-10-10 11:13:44.807327+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "ai-products", "developer-tools", "ai-infrastructure"], "entities": ["Talorys", "Cloudflare", "Cloudflare Pages", "Cloudflare Workers", "Durable Objects", "Workers AI", "@cf/zai-org/glm-4.7-flash", "Wrangler"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/talorys-a-self-hosted-personal-ai-agent-on-cloudflare-s-free-tier", "markdown": "https://wpnews.pro/news/talorys-a-self-hosted-personal-ai-agent-on-cloudflare-s-free-tier.md", "text": "https://wpnews.pro/news/talorys-a-self-hosted-personal-ai-agent-on-cloudflare-s-free-tier.txt", "jsonld": "https://wpnews.pro/news/talorys-a-self-hosted-personal-ai-agent-on-cloudflare-s-free-tier.jsonld"}}