Agent skill

Cloudflare Workers Runtime APIs

by secondsky in secondsky/claude-skills

Cloudflare Workers Runtime APIs including Fetch, Streams, Crypto, Cache, WebSockets, and Encoding.

MITAuto-check passedBackend & APIs

Install Cloudflare Workers Runtime APIs

skills CLI
$ npx skills add secondsky/claude-skills --skill cloudflare-workers-runtime-apis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/claude-skills cloudflare-workers-runtime-apis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/cloudflare-workers/skills/cloudflare-workers-runtime-apis .claude/skills/cloudflare-workers-runtime-apis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudflare-workers-runtime-apis
GitHub stars
227
Used in
1 other repo
Token cost
~2.3k tokens
SKILL.md length
378 words
Files
11 (incl. references)
Skills in repo
169
Repo updated
First seen
Licence
MIT

At a glance

Cloudflare Workers Runtime APIs including Fetch, Streams, Crypto, Cache, WebSockets, and Encoding.

  • Works in 6 steps: Always set timeouts for external… → Clone responses before reading body -… → Use streaming for large payloads - Don't… → …
  • Real-time connections
  • SKILL.md covers Quick Reference, Quick Start: Fetch API, Critical Rules and Top 10 Errors Prevented, plus 8 more sections
  • Runs TypeScript scripts from its folder; needs API_KEY

What it does

Cloudflare Workers Runtime APIs is an agent skill from secondsky/claude-skills. Cloudflare Workers Runtime APIs including Fetch, Streams, Crypto, Cache, WebSockets, and Encoding. Use for HTTP requests, streaming, encryption, caching, real-time connections, or encountering API compatibility, response handling, stream processing errors.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including reference files (for example `references/cache-api.md`, `references/crypto-api.md` and `references/encoding-api.md`).

It sits in Backend & APIs, covering Realtime and WebSockets and Caching. It works with Cloudflare Workers. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.

When your agent uses it

  • Real-time connections
  • Encountering API compatibility
  • Response handling
  • Stream processing errors

Example prompts

  • “/cloudflare-workers-runtime-apis”

Requirements

  • Node.js
  • A credential in API_KEY

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Always set timeouts for external requests - Workers have a 30s limit, external APIs can hang
  2. Clone responses before reading body - Body can only be read once
  3. Use streaming for large payloads - Don't buffer entire response in memory
  4. Cache external API responses - Reduce latency and API costs
  5. Handle Crypto operations in try/catch - Invalid inputs throw errors
  6. WebSocket hibernation for cost - Use Durable Objects with hibernation

What it can do on your machine

Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudflare Workers Runtime APIs loads about 2.3k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 378 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 378 words, ~2,303 tokens.

Download SKILL.mdSave it as .claude/skills/cloudflare-workers-runtime-apis/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
cloudflare-workers-runtime-apis
description
Cloudflare Workers Runtime APIs including Fetch, Streams, Crypto, Cache, WebSockets, and Encoding. Use for HTTP requests, streaming, encryption, caching, real-time connections, or encountering API compatibility, response handling, stream processing errors.
license
MIT

Cloudflare Workers Runtime APIs

Master the Workers runtime APIs: Fetch, Streams, Crypto, Cache, WebSockets, and text encoding.

Quick Reference

APIPurposeCommon Use
FetchHTTP requestsExternal APIs, proxying
StreamsData streamingLarge files, real-time
CryptoCryptographyHashing, signing, encryption
CacheResponse cachingPerformance optimization
WebSocketsReal-time connectionsChat, live updates
EncodingText encodingUTF-8, Base64

Quick Start: Fetch API

typescript
export default {
  async fetch(request: Request, env: Env): Promise<Response> {
    // Basic fetch
    const response = await fetch('https://api.example.com/data');

    // With options
    const postResponse = await fetch('https://api.example.com/users', {
      method: 'POST',
      headers: {
        'Content-Type': 'application/json',
        'Authorization': `Bearer ${env.API_KEY}`,
      },
      body: JSON.stringify({ name: 'John' }),
    });

    // Clone for multiple reads
    const clone = response.clone();
    const json = await response.json();
    const text = await clone.text();

    return Response.json(json);
  }
};

Critical Rules

  1. Always set timeouts for external requests - Workers have a 30s limit, external APIs can hang
  2. Clone responses before reading body - Body can only be read once
  3. Use streaming for large payloads - Don't buffer entire response in memory
  4. Cache external API responses - Reduce latency and API costs
  5. Handle Crypto operations in try/catch - Invalid inputs throw errors
  6. WebSocket hibernation for cost - Use Durable Objects with hibernation

Top 10 Errors Prevented

ErrorSymptomPrevention
Body already readTypeError: Body has already been consumedClone response before reading
Fetch timeoutRequest hangs, worker times outUse AbortController with timeout
Invalid JSONSyntaxError: Unexpected tokenCheck content-type before parsing
Stream lockedTypeError: ReadableStream is lockedDon't read stream multiple times
Crypto key errorDOMException: Invalid keyDataValidate key format and algorithm
Cache missReturns undefined instead of responseCheck cache before returning
WebSocket closeConnection drops unexpectedlyHandle close event, implement reconnect
Encoding errorTypeError: Invalid code pointUse TextEncoder/TextDecoder properly
CORS blockedBrowser rejects responseAdd proper CORS headers
Request size413 Request Entity Too LargeStream large uploads
Show full SKILL.md (135 more words)Show less

Fetch API Patterns

With Timeout
typescript
async function fetchWithTimeout(url: string, timeout: number = 5000): Promise<Response> {
  const controller = new AbortController();
  const timeoutId = setTimeout(() => controller.abort(), timeout);

  try {
    const response = await fetch(url, { signal: controller.signal });
    return response;
  } finally {
    clearTimeout(timeoutId);
  }
}
With Retry
typescript
async function fetchWithRetry(
  url: string,
  options: RequestInit = {},
  retries: number = 3
): Promise<Response> {
  for (let i = 0; i < retries; i++) {
    try {
      const response = await fetch(url, options);
      if (response.ok) return response;

      // Retry on 5xx errors
      if (response.status >= 500 && i < retries - 1) {
        await new Promise(r => setTimeout(r, Math.pow(2, i) * 1000));
        continue;
      }

      return response;
    } catch (error) {
      if (i === retries - 1) throw error;
      await new Promise(r => setTimeout(r, Math.pow(2, i) * 1000));
    }
  }
  throw new Error('Max retries exceeded');
}

Streams API

Transform Stream
typescript
function createUppercaseStream(): TransformStream<string, string> {
  return new TransformStream({
    transform(chunk, controller) {
      controller.enqueue(chunk.toUpperCase());
    }
  });
}

// Usage
const response = await fetch('https://example.com/text');
const transformed = response.body!
  .pipeThrough(new TextDecoderStream())
  .pipeThrough(createUppercaseStream())
  .pipeThrough(new TextEncoderStream());

return new Response(transformed);
Stream Large Response
typescript
async function streamLargeFile(url: string): Promise<Response> {
  const response = await fetch(url);

  // Stream directly without buffering
  return new Response(response.body, {
    headers: {
      'Content-Type': response.headers.get('Content-Type') || 'application/octet-stream',
    },
  });
}

Crypto API

Hashing
typescript
async function sha256(data: string): Promise<string> {
  const encoder = new TextEncoder();
  const dataBuffer = encoder.encode(data);
  const hashBuffer = await crypto.subtle.digest('SHA-256', dataBuffer);
  const hashArray = Array.from(new Uint8Array(hashBuffer));
  return hashArray.map(b => b.toString(16).padStart(2, '0')).join('');
}
HMAC Signing
typescript
async function signHMAC(key: string, data: string): Promise<string> {
  const encoder = new TextEncoder();
  const keyData = encoder.encode(key);
  const dataBuffer = encoder.encode(data);

  const cryptoKey = await crypto.subtle.importKey(
    'raw',
    keyData,
    { name: 'HMAC', hash: 'SHA-256' },
    false,
    ['sign']
  );

  const signature = await crypto.subtle.sign('HMAC', cryptoKey, dataBuffer);
  return btoa(String.fromCharCode(...new Uint8Array(signature)));
}

Cache API

typescript
export default {
  async fetch(request: Request, env: Env, ctx: ExecutionContext): Promise<Response> {
    const cache = caches.default;
    const cacheKey = new Request(request.url, { method: 'GET' });

    // Check cache
    let response = await cache.match(cacheKey);
    if (response) {
      return response;
    }

    // Fetch and cache
    response = await fetch(request);
    response = new Response(response.body, response);
    response.headers.set('Cache-Control', 'public, max-age=3600');

    // Store in cache (don't await)
    ctx.waitUntil(cache.put(cacheKey, response.clone()));

    return response;
  }
};

WebSockets (Durable Objects)

typescript
// Durable Object with WebSocket hibernation
export class WebSocketRoom {
  state: DurableObjectState;

  constructor(state: DurableObjectState) {
    this.state = state;
  }

  async fetch(request: Request): Promise<Response> {
    const upgradeHeader = request.headers.get('Upgrade');
    if (upgradeHeader !== 'websocket') {
      return new Response('Expected websocket', { status: 426 });
    }

    const pair = new WebSocketPair();
    const [client, server] = Object.values(pair);

    // Accept with hibernation
    this.state.acceptWebSocket(server);

    return new Response(null, { status: 101, webSocket: client });
  }

  async webSocketMessage(ws: WebSocket, message: string | ArrayBuffer) {
    // Handle incoming message
    const data = typeof message === 'string' ? message : new TextDecoder().decode(message);

    // Broadcast to all connected clients
    for (const client of this.state.getWebSockets()) {
      client.send(data);
    }
  }

  async webSocketClose(ws: WebSocket, code: number, reason: string) {
    ws.close(code, reason);
  }
}

When to Load References

Load specific references based on the task:

  • Making HTTP requests? → Load references/fetch-api.md for timeout, retry, proxy patterns
  • Processing large data? → Load references/streams-api.md for TransformStream, chunking
  • Encryption/signing? → Load references/crypto-api.md for AES, RSA, JWT verification
  • Caching responses? → Load references/cache-api.md for Cache API patterns, TTL strategies
  • Real-time features? → Load references/websockets.md for WebSocket patterns, Durable Objects
  • Text encoding? → Load references/encoding-api.md for TextEncoder, Base64, Unicode

Templates

TemplatePurposeUse When
templates/fetch-patterns.tsHTTP request utilitiesBuilding API clients
templates/stream-processing.tsStream transformationProcessing large files
templates/crypto-operations.tsCrypto utilitiesSigning, hashing, encryption
templates/websocket-handler.tsWebSocket DOReal-time applications

Resources

© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (references) in plugins/cloudflare-workers/skills/cloudflare-workers-runtime-apis of secondsky/claude-skills.

  • SKILL.md
  • references/cache-api.md
  • references/crypto-api.md
  • references/encoding-api.md
  • references/fetch-api.md
  • references/streams-api.md
  • references/websockets.md
  • templates/crypto-operations.ts
  • templates/fetch-patterns.ts
  • templates/stream-processing.ts
  • templates/websocket-handler.ts

Open the folder on GitHubat commit 8837836

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in secondsky/claude-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cloudflare Workers Runtime APIs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudflare Workers Runtime APIs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudflare Workers Runtime APIs this skillsecondsky/claude-skills2271 repos~2.3kAutomated safety check: PassMIT
Durable Objectshodgef/apiker1274 repos~1.5kAutomated safety check: PassMIT
Nitro Server Toolkitantfu/skills5.9k—~948Automated safety check: PassMIT
Agents SDKhodgef/apiker1273 repos~3kAutomated safety check: PassMIT
Cloudflare WorkersEpicenterHQ/epicenter4.8k—~576Automated safety check: PassCustom licence
HonoEpicenterHQ/epicenter4.8k—~513Automated safety check: PassCustom licence

Similar skills

  • Durable Objects

    hodgef/apiker

    Create and review Cloudflare Durable Objects. An agent skill from hodgef/apiker.

    127 GitHub starsUsed in 4 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Reference for Nitro v3, the server toolkit behind Nuxt: file routing, route rules, caching, storage, tasks, websockets and deployment presets.

    5.9k GitHub stars~948 tokensUpdated 8 days ago
    Backend & APIsAuto-check passed
  • Agents SDK

    hodgef/apiker

    Build AI agents on Cloudflare Workers using the Agents SDK. An agent skill from hodgef/apiker.

    127 GitHub starsUsed in 3 repos~3k tokens
    Backend & APIsAuto-check passed
  • Cloudflare Workers

    EpicenterHQ/epicenter

    Cloudflare Workers patterns for Worker runtime APIs, Durable Objects, KV, R2, D1, Queues, WebSockets, streaming responses, bindings, wrangler configuration, and deployment limits.

    4.8k GitHub stars~576 tokensUpdated today
    Backend & APIsAuto-check passed
  • Hono

    EpicenterHQ/epicenter

    Hono patterns for TypeScript API routes, middleware, request and response typing, streaming, WebSockets, and Cloudflare Workers deployment.

    4.8k GitHub stars~513 tokensUpdated today
    Backend & APIsAuto-check passed
  • iOS Networking

    dpearson2699/swift-ios-skills

    Build, review, or improve networking code in iOS/macOS apps using URLSession with async/await, structured concurrency, and modern Swift patterns.

    1.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed

More from secondsky/claude-skills

All 169 skills in this repo
  • Tanstack AI

    secondsky/claude-skills

    TanStack AI (alpha) provider-agnostic type-safe chat with streaming for OpenAI, Anthropic, Gemini, Ollama.

    227 GitHub starsUsed in 1 repo~3.6k tokens
    Auto-check: notes
  • Auto Animate

    secondsky/claude-skills

    AutoAnimate (@formkit/auto-animate) zero-config animations for React.

    227 GitHub stars~2.9k tokensUpdated 9 days ago
    Auto-check passed
  • Base UI React

    secondsky/claude-skills

    MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.

    227 GitHub stars~1.9k tokensUpdated 9 days ago
    Auto-check passed
  • Cloudflare Images

    secondsky/claude-skills

    This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…

    227 GitHub stars~3.6k tokensUpdated 9 days ago
    Auto-check: notes
  • Cloudflare Nextjs

    secondsky/claude-skills

    Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).

    227 GitHub stars~5.3k tokensUpdated 9 days ago
    Auto-check: notes
  • Cloudflare Sandbox

    secondsky/claude-skills

    Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.

    227 GitHub stars~4.5k tokensUpdated 9 days ago
    Auto-check passed

Categories

Questions about Cloudflare Workers Runtime APIs

What does Cloudflare Workers Runtime APIs do?

Cloudflare Workers Runtime APIs including Fetch, Streams, Crypto, Cache, WebSockets, and Encoding. Cloudflare Workers Runtime APIs is an agent skill from secondsky/claude-skills. Cloudflare Workers Runtime APIs including Fetch, Streams, Crypto, Cache, WebSockets, and Encoding.

When should I use Cloudflare Workers Runtime APIs?

Cloudflare Workers Runtime APIs fits situations like: real-time connections; encountering API compatibility; response handling; stream processing errors.

How do I install Cloudflare Workers Runtime APIs in Claude Code?

Run `npx skills add secondsky/claude-skills --skill cloudflare-workers-runtime-apis -a claude-code`. Or copy the skill folder (plugins/cloudflare-workers/skills/cloudflare-workers-runtime-apis in secondsky/claude-skills) into .claude/skills/cloudflare-workers-runtime-apis in your project. Claude Code loads it when a task matches its description.

How do I install Cloudflare Workers Runtime APIs in Codex?

Run `npx skills add secondsky/claude-skills --skill cloudflare-workers-runtime-apis -a codex`. Or copy the skill folder (plugins/cloudflare-workers/skills/cloudflare-workers-runtime-apis in secondsky/claude-skills) into .agents/skills/cloudflare-workers-runtime-apis in your project. Codex loads it when a task matches its description.

Can I use Cloudflare Workers Runtime APIs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill cloudflare-workers-runtime-apis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare-workers-runtime-apis, .gemini/skills/cloudflare-workers-runtime-apis, .github/skills/cloudflare-workers-runtime-apis and .opencode/skills/cloudflare-workers-runtime-apis in your project.

What does Cloudflare Workers Runtime APIs need to run?

Going by SKILL.md and its folder, Cloudflare Workers Runtime APIs needs TypeScript for the scripts in its folder and credentials named API_KEY. Our summary lists: Node.js; A credential in API_KEY.

Does Cloudflare Workers Runtime APIs access the network?

SKILL.md names 1 domain. As links in the text: developers.cloudflare.com. This is read from the text; nothing was executed.

Is Cloudflare Workers Runtime APIs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloudflare Workers Runtime APIs use?

Cloudflare Workers Runtime APIs is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudflare Workers Runtime APIs use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Cloudflare Workers Runtime APIs?

Skills that share tags, products or a category with Cloudflare Workers Runtime APIs: Durable Objects (hodgef/apiker, 127 stars), Nitro Server Toolkit (antfu/skills, 5.9k stars), Agents SDK (hodgef/apiker, 127 stars) and Cloudflare Workers (EpicenterHQ/epicenter, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudflare Workers Runtime APIs?

secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 169 skills in this directory. The repository was last updated on September 28, 2026.

Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.