# Cloudflare Workers AI

Connect your Cloudflare Workers AI API token and account ID to run Suger's AI features on Workers AI models.

---

## Overview

Cloudflare Workers AI is an AI model provider (category: AI). When you connect your own Workers AI API token (bring-your-own-key), the Workers AI chat models Suger supports become available to Suger's AI features — for example, you can choose one as an agent's **Default model**. Cloudflare bills the model usage to your Cloudflare account; for how Suger meters AI requests that run on your own key, see [What is metered](/insulin/billing/metering/#using-your-own-provider-keys-byok).

Suger offers a fixed set of Workers AI chat models, not Cloudflare's whole catalog:

| Model | Workers AI model ID |
| --- | --- |
| Llama 3.3 70B Instruct (fast) | `@cf/meta/llama-3.3-70b-instruct-fp8-fast` |
| Llama 3.1 8B Instruct (fp8) | `@cf/meta/llama-3.1-8b-instruct-fp8` |
| GPT-OSS 120B | `@cf/openai/gpt-oss-120b` |
| Qwen2.5 Coder 32B Instruct | `@cf/qwen/qwen2.5-coder-32b-instruct` |
| Mistral Small 3.1 24B Instruct | `@cf/mistralai/mistral-small-3.1-24b-instruct` |

### Org-Level vs User-Level

- **Org-Level**: one token shared by your organization. Organization agents draw on it. Only an organization **Admin** can connect or disconnect it.
- **User-Level**: your own token. Your Personal agents draw on it; it never serves anyone else in your organization.

---

## Create Integration

### Prerequisites

- A **Workers AI API token**. In the Cloudflare dashboard, go to **Workers AI**, select **Use REST API**, then **Create a Workers AI API Token** and **Create API Token**. If you build a custom token instead, it needs both the **Workers AI - Read** and **Workers AI - Edit** permissions — see Cloudflare's [REST API](https://developers.cloudflare.com/workers-ai/get-started/rest-api/) guide. A read-only token passes Suger's connect check but cannot run models.
- Your Cloudflare **Account ID**, shown under **Get Account ID** on the same **Use REST API** page (or see Cloudflare's [Find account and zone IDs](https://developers.cloudflare.com/fundamentals/account/find-account-and-zone-ids/)). Suger accepts it only as a 32-character hexadecimal value.

### Connect

1. Open [Settings → Integrations](https://console.suger.io/settings?tab=integrations) in the Suger console.
2. Find the **Cloudflare Workers AI** card — in the **Integrations** grid to connect it for your organization, or under **User Integrations** to connect it for yourself — and click **Connect**.
3. In the **Connect Cloudflare Workers AI** dialog, click **Start connection**.
4. Enter your Workers AI API token and your Account ID — the organization form labels them **API Token** and **Account ID** — and click **Save credentials**.

Before storing your credentials, Suger checks the Account ID's shape and then uses your token to list Workers AI models in that account:

```d2
direction: down

save: "Save credentials\nAPI token + Account ID"
shape_check: "Account ID is 32\nhexadecimal characters?" { shape: diamond }
probe: "Suger asks Cloudflare for your\naccount's Workers AI model list,\nusing your token"
answer: "Cloudflare's answer" { shape: diamond }
connected: "Connected\ntoken and Account ID stored"
fix_id: "Rejected: fix the Account ID\nnothing stored"
fix_token: "Rejected: fix the token\nnothing stored"
retry: "Not confirmed: try again later\nnothing stored"

save -> shape_check
shape_check -> fix_id: "no"
shape_check -> probe: "yes"
probe -> answer
answer -> connected: "200 OK"
answer -> fix_token: "401 / 403"
answer -> retry: "anything else\n(timeout, 404, 429, 5xx)"
```

| What the form shows | What it means |
| --- | --- |
| `Invalid connection config field "accountId": must be a 32-character hexadecimal Cloudflare account id` | The Account ID is not 32 hexadecimal characters. Copy it again from Cloudflare. |
| `Cloudflare Workers AI rejected the supplied API key` | Cloudflare refused the token. Check that you pasted the whole token and that it has not been revoked. |
| `Cloudflare Workers AI could not confirm the key right now (status …)` or `Could not reach Cloudflare Workers AI to verify the key` | Suger got no usable answer — a timeout, a rate limit, an outage, or an account Cloudflare does not recognise. The token was **not** judged invalid; check the Account ID and try again. |

:::info
Once connected, the models in the table above appear in Suger's model pickers — for example an agent's **Default model** (see [Agents](/insulin/agents/)). If your organization limits AI providers under **Settings → Organization → AI Model Policy**, add **Cloudflare Workers AI** to its **Allowed AI integrations** list — otherwise requests on these models are refused, whichever key they would use. See [AI Model Policy](/insulin/getting-started/#ai-model-policy).
:::

## Edit Integration

There is no **Edit** option. To replace the token or the Account ID — for example after rotating the token in Cloudflare — reconnect the integration:

1. Open the **⋯** menu on the Cloudflare Workers AI card and choose **Details**.
2. Click **Reconnect**, then **Start connection**, enter the new values, and click **Save credentials**.

Suger checks the new values exactly as it does on first connect, and replaces the stored credential only when they pass — a rejected token leaves the previous one in place. For an organization connection, reconnecting also requires the **Admin** role.

Suger checks the token only when you connect or reconnect, so reconnect whenever you revoke or replace it on the Cloudflare side.

## Delete Integration

Open the **⋯** menu on the Cloudflare Workers AI card and choose **Disconnect**. This removes the connection from Suger, so its models can no longer run on that credential. An agent whose **Default model** is a Workers AI model then shows it as **unavailable** in its model picker, with a hint to reconnect the provider or choose another model.

:::info
Cloudflare Workers AI serves chat models only in Suger. Suger registers no Workers AI embedding model, so connecting it adds nothing to the knowledge-base embedding chooser — see [Choosing an embedding model](/insulin/knowledge-base/#choosing-an-embedding-model).
:::
