Cloudflare's in a good position to be an agent infra provider. Durable objects and serverless/workers are great agent primitives.
It makes sense that they're leaning into an all-in-one platform play, i.e. if you use DOs, you might as well use our wallet/sandbox/AI gateway/etc. too.
What a stupid move! So, you have a Workers subdomain, a Zero Trust subdomain, and now a Wallet subdomain - one company with random handles! Cloudflare does not get identity!
Cloudflare is certainly making a full court press to provide infra for the agentic web. My own ability to see whats coming also believes we need wallets, agent protocols, cloud services for agents, etc. So, maybe this is the way.
At the same time, something tells me what is coming isn't going to be as recognizable as these products build for.
"This company keeps creating products in the space that they operate in, where there is clear demand, and that people want to use. What's their angle?"
It seems that cloudflare is trying to create an internet-wide agent identity platform in general. I have seem few attempts at “agent identity” but they were all intrinsically limited to a particular system. An identity AWS IAM assigns to an agent isn’t gonna work on rottentomatos.com or techcrunch.com.
This was always a vaguely desired thing, but the implementation details was always a form of OIDC federation which is mind-numbingly complex and not worth the hassle. Just shove an api key or a shared secret of some sort and move on. Only accounts that are very high value targets for attacks (cloud infra accounts, CIs infra, billing, and things they interact with implement OIDC federation. But that awesome Thai recipe blog has no chance of implementing something like that.
With Agents driving internet traffic, there is a desire to have identities for them. And since it’s inherently easy for them to leak these identities (look at the million sandbox solutions that all share the same dumb goal of “protect the API Key or password”), having short lived tokens for everything (AWS IAM or Azure Managed Identity like) simplifies the entire process. Agreeing on the single IdP was the problem, there are like 40 (Google, Apple, Microsoft, Facebook, Twitter, even GitHub, and Amazon have SSO not to mention all the regional specific ones)
There is a legitimate need for that, and it looks like cloudflare figured if they are that “internet agent identity provider”, then there is a lot of power and control over the internet and AI use in general.
- permission-ed system when we’ve got lightning and super low cost blockchains. They could even run their own L2.
- I am typing my name in a cafe and hear some clacking sounds. I was puzzled there for a full minute to where the sound was coming from. Who thought this is a good idea?
- So I finish the reservation and there is actually no product yet?
18 comments
[ 0.81 ms ] story [ 56.0 ms ] threadAlipay and Coinbase already have similar offerings in market.
It makes sense that they're leaning into an all-in-one platform play, i.e. if you use DOs, you might as well use our wallet/sandbox/AI gateway/etc. too.
Web Security is Too Hard
https://news.ycombinator.com/item?id=49172834
Without domain validation, what is this user's intention other than fraud/impersonation?
I've already got an active impersonator running a website under my brand name and confusing my customers.
At the same time, something tells me what is coming isn't going to be as recognizable as these products build for.
If so, why not interact with an exchange?
Also, not sure how many merchants out there accept stablecoins. Probably not many.
This was always a vaguely desired thing, but the implementation details was always a form of OIDC federation which is mind-numbingly complex and not worth the hassle. Just shove an api key or a shared secret of some sort and move on. Only accounts that are very high value targets for attacks (cloud infra accounts, CIs infra, billing, and things they interact with implement OIDC federation. But that awesome Thai recipe blog has no chance of implementing something like that.
With Agents driving internet traffic, there is a desire to have identities for them. And since it’s inherently easy for them to leak these identities (look at the million sandbox solutions that all share the same dumb goal of “protect the API Key or password”), having short lived tokens for everything (AWS IAM or Azure Managed Identity like) simplifies the entire process. Agreeing on the single IdP was the problem, there are like 40 (Google, Apple, Microsoft, Facebook, Twitter, even GitHub, and Amazon have SSO not to mention all the regional specific ones)
There is a legitimate need for that, and it looks like cloudflare figured if they are that “internet agent identity provider”, then there is a lot of power and control over the internet and AI use in general.
- permission-ed system when we’ve got lightning and super low cost blockchains. They could even run their own L2.
- I am typing my name in a cafe and hear some clacking sounds. I was puzzled there for a full minute to where the sound was coming from. Who thought this is a good idea?
- So I finish the reservation and there is actually no product yet?
How is https://cloudflare.pay resolving?