| Choose the building blocks for an AI application | AI overview | Compare Cloudflare's AI services before choosing inference, retrieval, or agent tooling | AI docs |
| Choose infrastructure for a customer-facing platform | Cloudflare for Platforms | Compare running customer code with serving an app on customer domains | Platform overview |
| Choose an approach to live audio and video | Realtime | Compare application SDKs, media infrastructure, and connectivity relays | Realtime overview |
| Start a Worker or framework project | C3 | Scaffold a project using the appropriate framework template | C3; wrangler skill |
| Build or deploy a Next.js app on Cloudflare | vinext + Workers | Use vinext rather than OpenNext for new projects | nextjs-on-cloudflare skill; Next.js docs |
| Host a new static site, SPA, or full-stack app | Workers + Workers Static Assets | Serve site files and add server-side logic where needed | Static Assets; workers-best-practices skill |
| Build an API or handle webhooks | Workers | Run request handlers with access to Cloudflare services | workers-best-practices skill; Workers docs |
| Maintain an existing Pages deployment | Pages + Pages Functions | Update an existing site or its server endpoints; use Workers for new projects | Pages; Pages Functions |
| Move a Pages project to Workers | Workers + Workers Static Assets | The task calls for migrating the hosting platform | Pages migration guide |
| Let customers deploy code on your platform | Workers for Platforms | Run and manage customer Workers with per-customer controls | Workers for Platforms |
| Let customers use their own domains with your app | Cloudflare for SaaS | Manage custom hostnames, TLS certificates, and origin routing; check hostname validation and apex-domain plan requirements. Combine with Workers for Platforms when customers also deploy code | SaaS docs |
| Connect a Worker to storage or another service | Bindings | Give the Worker access to configured resources through its environment | Bindings |
| Run containerized services or Linux software | Containers | The workload needs a container image or software outside the Workers runtime | Containers |
| Execute generated or untrusted code, build Code Mode tools, or create on-demand previews | Dynamic Workers | Load code at runtime in isolated Workers; check bindings, egress controls, and resource limits. Choose Sandbox when execution needs Linux or shell tools | Dynamic Workers docs |
| Give an agent a shell, filesystem, or interactive development environment | Sandbox SDK | Code execution needs a Linux environment or container tools; inspect the package line first | sandbox-next for new or preview projects; sandbox-stable for existing stable apps; Sandbox docs |
| Upgrade a stable Sandbox app to the preview API | Sandbox SDK | The user wants the stable-to-next migration | sandbox-migrate-to-next skill; migration guide |
| Coordinate chat rooms, games, collaborative documents, or bookings | Durable Objects | Operations need shared state and coordination per room, document, or entity | durable-objects skill; Durable Objects docs |
| Store and recover state inside a Durable Object | Durable Object storage | Choose storage APIs, transactions, and recovery for coordinated per-entity data | DO storage |
| Store application records and query them with SQL | D1 | Use a managed relational database; use Durable Objects when per-entity coordination is central | D1 |
| Connect to an existing PostgreSQL or MySQL database | Hyperdrive | Keep the existing database and optimize connections from Workers | Hyperdrive |
| Distribute configuration or other key-value data | KV | Read-heavy key-value access fits the workload's consistency requirements | KV |
| Store uploads, downloads, or large objects | R2 | Store files by object key; pair with D1 when searchable metadata needs SQL | R2 |
| Store versioned file trees, agent checkpoints, or repositories | Artifacts | Files need versioning and Git-compatible access; currently closed beta, so confirm access before implementation | Artifacts |
| Ingest event streams into a data lake | Pipelines | Transform and deliver streaming records into R2 | Pipelines |
| Manage Iceberg tables in R2 | R2 Data Catalog | Organize tables for a data lake and compatible query engines | R2 Data Catalog |
| Query a data lake with SQL | R2 SQL | Analyze data in R2 Data Catalog rather than transactional application records | R2 SQL |
| Cache application responses | Workers Cache | Default for application caching; check the patterns and limitations before choosing alternatives | Workers Cache; see caching guidance below |
| Accelerate an existing website and control cached content | Cache/CDN | Configure caching for a proxied origin using Cache Rules, expiration settings, and purging | Cache/CDN docs |
| Keep origin content in a persistent cache | Cache Reserve | Reduce origin fetches with persistent CDN cache storage | Cache Reserve |
| Process jobs asynchronously or buffer bursts of work | Queues | Decouple producers and consumers; use Workflows for durable multi-step orchestration | Queues |
| Run a job that retries, waits, and resumes across steps | Workflows | Coordinate durable multi-step business processes | Workflows |
| Start a Worker on a recurring schedule | Cron Triggers | Trigger scheduled work; combine with Queues or Workflows for the work itself | Cron Triggers |
| Run language, embedding, image, or speech models | Workers AI | Use managed inference; verify model capabilities, schemas, and pricing | Workers AI |
| Add managed search or answers over your content | AI Search | Use a managed retrieval-augmented generation pipeline | AI Search |
| Build custom semantic search or retrieval | Vectorize + Workers AI | Control embeddings, indexing, and retrieval rather than using a managed pipeline | Vectorize; Workers AI |
| Observe and control requests to AI providers | AI Gateway | Add inference analytics, caching, and request controls | AI Gateway |
| Build stateful agents with tools, scheduling, or chat | Agents SDK | Implement agent behavior on Cloudflare; add Dynamic Workers or Sandbox for the required execution runtime | agents-sdk skill; Agents docs |
| Build durable agents with TypeScript hooks | Flue | Use an open agent framework with Cloudflare and Node.js targets | Flue; getting started; Cloudflare target |
| Expose tools through a remote MCP server | Workers + Agents SDK | Publish tools for MCP clients, with authentication appropriate to the service | agents-sdk skill, its references/mcp.md; MCP docs |
| Automate browsers, take screenshots, or extract rendered pages | Browser Run | The task requires a browser rather than a plain HTTP request | Browser Run |
| Connect a domain, configure DNS records, or troubleshoot resolution | DNS | Manage authoritative records and choose whether traffic is proxied through Cloudflare | DNS docs |
| Configure HTTPS and certificates | SSL/TLS | Secure connections from visitors to Cloudflare and from Cloudflare to the origin | SSL/TLS docs |
| Distribute traffic across origins and fail over unhealthy servers | Load Balancing | Use health checks and traffic steering for multiple origin servers | Load Balancing docs |
| Connect an existing server to Cloudflare | Cloudflare Tunnel | Reach an origin without a publicly routable IP address | Tunnel |
| Connect Workers to private services | Workers VPC | Access services in private networks from a Worker | Workers VPC |
| Require employee login before accessing an internal app | Access | Put identity-based access policies in front of an internal application | cloudflare-one skill; Access docs |
| Protect access to internal applications and networks | Cloudflare One | Apply identity and network access policies | cloudflare-one skill; Cloudflare One docs |
| Migrate existing access and network security configurations | Cloudflare One | The task is a supported migration to Cloudflare One | cloudflare-one-migrations skill; Cloudflare One docs |
| Proxy a TCP or UDP application | Spectrum | Protect and accelerate non-HTTP application traffic | Spectrum |
| Connect a network directly to Cloudflare | Network Interconnect | Dedicated network connectivity is required | Network Interconnect |
| Improve routing across the network | Argo Smart Routing | Optimize traffic paths to the origin | Argo Smart Routing |
| Reduce Worker-to-backend latency | Smart Placement | Place Worker execution closer to the backends it calls | Smart Placement |
| Redirect URLs, rewrite paths or headers, or change origin routing | Rules | Use Redirect, Transform, or Origin Rules when configuration can express the required behavior | Rules docs |
| Make small HTTP request or response changes | Snippets | Lightweight edge logic meets the need | Snippets |
| Protect forms from automated abuse | Turnstile | Add bot challenges and server-side token validation | turnstile-spin skill; Turnstile docs |
| Filter malicious web requests | WAF | Apply application-layer rules and managed protections | WAF |
| Protect services from denial-of-service attacks | DDoS Protection | Mitigate attacks at the relevant network or application layer | DDoS protection |
| Detect and control automated traffic | Bot Management | Make request decisions based on bot detection | Bot Management |
| Discover and protect API endpoints | API Shield | Apply API-specific protections and validation | API Shield |
| Queue visitors during traffic spikes | Waiting Room | Control admission when application capacity is limited | Waiting Room docs |
| Store a Worker's API keys and credentials | Workers secrets | Bind secrets to a Worker without committing values to source | wrangler skill; secrets docs |
| Share managed secrets across services | Secrets Store | Manage reusable account-level secrets | Secrets Store |
| Control where data is processed and stored | Data Localization Suite | Evaluate regional processing and storage controls against the actual requirements | Data Localization docs |
| Prove a claim without identifying or tracking the user | Privacy Pass | Use privacy-preserving tokens in a supported integration | Privacy Pass docs |
| Store, resize, transform, and deliver images | Cloudflare Images | Use managed image processing and delivery | Images |
| Encode, store, and deliver live or on-demand video | Stream | Use managed video infrastructure | Stream |
| Build an audio/video calling application with SDKs | RealtimeKit | Use application-level SDKs for calls and meetings | RealtimeKit |
| Build custom real-time media infrastructure | Realtime SFU | Control the application while using a selective forwarding unit for media | Realtime SFU |
| Relay WebRTC connections through restrictive networks | TURN Service | Clients need a connectivity relay | TURN |
| Deliver live media over QUIC | MoQ | Use the Media over QUIC protocol; check current compatibility and availability | MoQ docs |
| Send transactional email | Email Service | Send application-generated messages | cloudflare-email-service skill; Email Service docs |
| Forward incoming email | Email Routing | Route addresses on a domain to destination mailboxes | Email Routing |
| Process incoming email in code | Email Workers | Apply custom logic to inbound messages | Email Workers |
| Manage third-party tags and scripts | Zaraz | Load and manage third-party tools through Cloudflare | Zaraz |
| Run locally and manage resources from the CLI | Wrangler | Develop, configure, deploy, and inspect the intended account and environment | wrangler skill; Wrangler docs |
| Test Worker behavior before deployment | Workers testing tools | Choose runtime tests or integration tests for the affected behavior | Testing docs; durable-objects skill for DO tests |
| Embed local Worker simulation in tooling | Miniflare | A programmatic emulator is needed for a custom development or test harness | Miniflare |
| Run or investigate the underlying Workers runtime | workerd | Work directly with the runtime outside normal managed deployment | workerd |
| Try a small Worker in the browser | Workers Playground | Explore or share a minimal example without local setup | Workers Playground |
| Build and deploy whenever code is pushed | Workers Builds | Connect a Git repository to automated builds and deployments | Builds docs |
| Preview a version, release it gradually, or roll back code | Workers versions and deployments | Manage application releases; rollback does not restore connected resource data | Deployment docs; wrangler skill |
| Release a feature gradually or target user groups | Flagship | Change feature availability with targeting and percentage rollouts | Flagship |
| Manage infrastructure as code | Terraform or Pulumi | Use Terraform for declarative configuration or Pulumi for infrastructure in programming languages | Terraform; Pulumi |
| Automate account or product configuration through an API | Cloudflare REST API | Manage resources programmatically; prefer bindings for supported operations inside Workers | REST API |
| Debug failures and trace application requests | Workers Logs and Traces | Investigate runtime errors and execution paths | Observability |
| Process Worker execution events in code | Tail Workers | Build custom log or exception processing | Tail Workers |
| Export Worker logs to another system | Workers Logpush | Deliver logs to a supported external destination | Logpush docs |
| Measure custom application events | Workers Analytics Engine | Analyze high-cardinality event data written from Workers | Analytics Engine |
| Measure website usage and visitor performance | Cloudflare Web Analytics | Add website analytics and real-user measurements | Web Analytics |
| Query metrics across Cloudflare products | GraphQL Analytics API | Retrieve product analytics programmatically | GraphQL Analytics API |
| Audit page speed and find loading bottlenecks | Web performance tools | Measure and improve the site's actual browser performance | web-perf skill; Web Analytics |
| Ask questions about an account or diagnose its configuration in the dashboard | Agent Lee | Use the dashboard's AI assistant; check current account eligibility | Agent Lee docs |