What it actually does
Every prompt from any client — a browser, curl, OpenCode, Claude Code, or Cursor — can flow through the same gateway. That is where policy lives.
Inline DLP
Scans prompt content in real time. An SSN, credit card, or secret can be blocked at the edge with HTTP 424 before it reaches the model.
Guardrails
Applies model-safety checks for unsafe categories and prompt attacks according to the gateway policy.
Full logging & audit
Records request status, selected model, usage, and policy actions so operators can prove what passed or was blocked.
Caching & rate limits
Caches eligible responses and applies traffic controls independently of application code. This public demo also enforces a configurable global request limit.
Works on any client
OpenCode, Claude Code, Cursor, curl, or this page receive the same governance when configured to use the gateway.
Provider flexibility
AI Gateway supports multiple providers while governance remains centralized. This public example is intentionally pinned to Workers AI only.
How a request flows
Client sends prompt
The browser or configured client submits a bounded request.
Quota + policy check
The global quota admits the request, then DLP and Guardrails inspect it.
Allow → model
Clean prompts reach the approved Workers AI model and return normally.
Sensitive → 424
Matching sensitive content stops before inference and model spend.
Try it yourself
Public demo: limited to 20 requests per minute globally. This limit is configurable by the operator.
Ask a normal question, then use the fake SSN chip to see the DLP response.
Use it in OpenCode
Point an OpenCode provider at your own Workers AI route through Cloudflare AI Gateway. The placeholders below are intentionally nonfunctional; replace them with your account, gateway, and scoped tokens.
// ~/.config/opencode/opencode.json
{
"$schema": "https://opencode.ai/config.json",
"model": "cf-workers-ai/@cf/moonshotai/kimi-k2.7-code",
"provider": {
"cf-workers-ai": {
"npm": "@ai-sdk/openai-compatible",
"name": "Workers AI via Cloudflare AI Gateway",
"options": {
"baseURL": "https://gateway.ai.cloudflare.com/v1/<your-account-id>/<your-gateway>/workers-ai/v1",
"headers": {
"Authorization": "Bearer ${CLOUDFLARE_API_TOKEN}",
"cf-aig-authorization": "Bearer ${AI_GATEWAY_TOKEN}"
}
},
"models": {
"@cf/moonshotai/kimi-k2.7-code": { "name": "Kimi K2.7 Code" }
}
}
}
}mcp tool-server configuration. Keep both tokens out of source control.