Integration

Cloudflare Workers AI through the Vigil proxy

Cloudflare Workers AI, reached through api.cloudflare.com, with an OpenAI-compatible endpoint. Point your SDK's base URL at Vigil, add one header, and every Cloudflare Workers AI call is logged with its cost, tokens, latency, errors and agent, then forwarded to https://api.cloudflare.com unchanged.

What Vigil records per Cloudflare Workers AI call

One row per call: the model id as Cloudflare Workers AI returned it, input and output tokens, cache reads and writes where the response reports them, latency, the HTTP status and the provider's error code when it fails, and the agent named in the X-Vigil-Agent header. Likely prompt injections and personal data in prompts are flagged on the Errors page. A cost spike is flagged when a call costs over three times the agent's seven-day median.

Cost is left empty for this provider. Cloudflare Workers AI model slugs are an open gap — no `@cf/…` id has been read, so no rate row can be keyed to one. These calls are logged and monitored; their cost column stays empty rather than showing a made-up figure.

Setup

Every route has the shape https://api.vigil.tools/{user_id}/{provider}/{path}. For Cloudflare Workers AI the provider segment is cloudflare, so the base URL is https://api.vigil.tools/{user_id}/cloudflare and a request path such as /v1/chat/completions is forwarded unchanged. The proxy stores the origin only, so the path after the segment is whatever your client already uses, /v1 for most OpenAI-compatible APIs.

Two headers: X-Vigil-Key, your Vigil key from the dashboard, and X-Vigil-Agent, the name the dashboard groups this traffic under. Your Cloudflare Workers AI key stays where it was, in CLOUDFLARE_API_TOKEN.

your Cloudflare Workers AI client
import OpenAI from "openai";

const client = new OpenAI({
  apiKey: process.env.CLOUDFLARE_API_TOKEN,   // unchanged
  baseURL: "https://api.vigil.tools/{user_id}/cloudflare/v1",
  defaultHeaders: {
    // MUST be X-Vigil-Key: Authorization already carries your Cloudflare Workers AI key.
    "X-Vigil-Key": "vk_your_vigil_key",
    "X-Vigil-Agent": "my-agent",
  },
});

const completion = await client.chat.completions.create({
  model: "<your model id>",
  messages: [{ role: "user", content: "Hello!" }],
});

Vigil forwards everything after /cloudflare unchanged to https://api.cloudflare.com. The path above is whatever your client already uses — /v1 is the OpenAI-compatible default and is right for most, but some providers prefix it with a product segment. If you get a 404, compare it against the base URL in your Cloudflare Workers AI config: the part after https://api.cloudflare.com is exactly what belongs here. Cloudflare Workers AI model slugs are an open gap — no `@cf/…` id has been read, so no rate row can be keyed to one. These calls are logged and monitored; their cost column stays empty rather than showing a made-up figure.

your Cloudflare Workers AI client
from openai import OpenAI

client = OpenAI(
    api_key=os.environ["CLOUDFLARE_API_TOKEN"],  # unchanged
    base_url="https://api.vigil.tools/{user_id}/cloudflare/v1",
    default_headers={
        "X-Vigil-Key": "vk_your_vigil_key",
        "X-Vigil-Agent": "my-agent",
    },
)

completion = client.chat.completions.create(
    model="<your model id>",
    messages=[{"role": "user", "content": "Hello!"}],
)

Vigil forwards everything after /cloudflare unchanged to https://api.cloudflare.com. The path above is whatever your client already uses — /v1 is the OpenAI-compatible default and is right for most, but some providers prefix it with a product segment. If you get a 404, compare it against the base URL in your Cloudflare Workers AI config: the part after https://api.cloudflare.com is exactly what belongs here. Cloudflare Workers AI model slugs are an open gap — no `@cf/…` id has been read, so no rate row can be keyed to one. These calls are logged and monitored; their cost column stays empty rather than showing a made-up figure.

terminal
curl https://api.vigil.tools/{user_id}/cloudflare/v1/chat/completions \
  -H "content-type: application/json" \
  -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  -H "X-Vigil-Key: vk_your_vigil_key" \
  -H "X-Vigil-Agent: my-agent" \
  -d '{
    "model": "<your model id>",
    "messages": [{ "role": "user", "content": "Hello!" }]
  }'

Vigil forwards everything after /cloudflare unchanged to https://api.cloudflare.com. The path above is whatever your client already uses — /v1 is the OpenAI-compatible default and is right for most, but some providers prefix it with a product segment. If you get a 404, compare it against the base URL in your Cloudflare Workers AI config: the part after https://api.cloudflare.com is exactly what belongs here. Cloudflare Workers AI model slugs are an open gap — no `@cf/…` id has been read, so no rate row can be keyed to one. These calls are logged and monitored; their cost column stays empty rather than showing a made-up figure.

Replace {user_id} and vk_your_vigil_key with the values on your Connect page. The snippets above are generated by the same code as that page.

Prompt caching on Cloudflare Workers AI

Vigil adds a routing hint so repeat calls are more likely to land on a machine that already holds your prompt. That raises the hit rate; it cannot mark a cache breakpoint, so there is no guaranteed saving and nothing here is reported as one.

With optimisation On: Vigil adds a cache-affinity hint, which can raise the hit rate but cannot place a cache marker. In Shadow, Vigil measures what caching would have saved and changes nothing. Off records the call and nothing more.

Questions

Does Vigil see or store my Cloudflare Workers AI API key?
No, not the key itself. Your Cloudflare Workers AI key passes through the proxy with the request and is never written to disk. A call record can keep a short one-way digest of the credential, so that one key’s cache is kept apart from another’s; it cannot be turned back into the key. Vigil identifies you by the X-Vigil-Key header and your user id in the URL.
Does routing Cloudflare Workers AI through Vigil add latency?
Some. The proxy runs on Cloudflare’s edge, so the added hop is short, but reading the request body to place cache markers takes time, and there is a bounded lookup for your account state. The dashboard shows total latency per call. For long calls, stream: Cloudflare’s edge closes non-streaming connections after roughly 125 seconds.
Which Cloudflare Workers AI models does Vigil price?
None yet. Cloudflare Workers AI model slugs are an open gap — no `@cf/…` id has been read, so no rate row can be keyed to one. These calls are logged and monitored; their cost column stays empty rather than showing a made-up figure.

Other providers: Anthropic · AWS Bedrock · Google Vertex · OpenAI · Google Gemini · Mistral · xAI Grok · DeepSeek · Together AI · Fireworks AI · Groq · Cerebras · Baseten · Moonshot · Z.ai · OpenRouter