Cloudflare AI Gateway

One gateway in front of every AI call.

AI Gateway sits between your apps and any AI model. It inspects, governs, logs, and protects every request — without changing a line of client code. Below: what it does, then a live playground you can break.

← Back to itlinux.cc

What it actually does

Every prompt from any client — a browser, curl, OpenCode, Claude Code, or Cursor — can flow through the same gateway. That is where policy lives.

🛡

Inline DLP

Scans prompt content in real time. An SSN, credit card, or secret can be blocked at the edge with HTTP 424 before it reaches the model.

✓

Guardrails

Applies model-safety checks for unsafe categories and prompt attacks according to the gateway policy.

☰

Full logging & audit

Records request status, selected model, usage, and policy actions so operators can prove what passed or was blocked.

⚡

Caching & rate limits

Caches eligible responses and applies traffic controls independently of application code. This public demo also enforces a configurable global request limit.

›_

Works on any client

OpenCode, Claude Code, Cursor, curl, or this page receive the same governance when configured to use the gateway.

◎

Provider flexibility

AI Gateway supports multiple providers while governance remains centralized. This public example is intentionally pinned to Workers AI only.

How a request flows

01

Client sends prompt

The browser or configured client submits a bounded request.

→
02

Quota + policy check

The global quota admits the request, then DLP and Guardrails inspect it.

→
03

Allow → model

Clean prompts reach the approved Workers AI model and return normally.

→
BLOCK

Sensitive → 424

Matching sensitive content stops before inference and model spend.

Try it yourself

Public demo: limited to 20 requests per minute globally. This limit is configurable by the operator.

Ask a normal question, then use the fake SSN chip to see the DLP response.

AI Gateway PlaygroundLive · DLP + Guardrails enabled
Ciao! Ask me a short question, or test the DLP policy with the fake-data chip.

Use it in OpenCode

Point an OpenCode provider at your own Workers AI route through Cloudflare AI Gateway. The placeholders below are intentionally nonfunctional; replace them with your account, gateway, and scoped tokens.

OpenCode config
// ~/.config/opencode/opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "model": "cf-workers-ai/@cf/moonshotai/kimi-k2.7-code",
  "provider": {
    "cf-workers-ai": {
      "npm": "@ai-sdk/openai-compatible",
      "name": "Workers AI via Cloudflare AI Gateway",
      "options": {
        "baseURL": "https://gateway.ai.cloudflare.com/v1/<your-account-id>/<your-gateway>/workers-ai/v1",
        "headers": {
          "Authorization": "Bearer ${CLOUDFLARE_API_TOKEN}",
          "cf-aig-authorization": "Bearer ${AI_GATEWAY_TOKEN}"
        }
      },
      "models": {
        "@cf/moonshotai/kimi-k2.7-code": { "name": "Kimi K2.7 Code" }
      }
    }
  }
}
Note: path shown is for macOS / Linux. This is the model-provider configuration; it is separate from OpenCode's mcp tool-server configuration. Keep both tokens out of source control.