Cloudflare just opened the Git layer it has been building for agents. On October 1, 2026, Dina Kozlov, Dillon Mulroy, and Zebulon Piasecki put Artifacts into open beta on the Workers Paid plan and launched a contest, submissions until October 14, 2026, to build the next Git platform on Workers plus Artifacts.
This is not a hosted GitHub clone with a chatbot bolted on. Cloudflare is selling programmable primitives: create and fork repositories from a Worker, hand an agent a real Git remote URL and a scoped token, then react when that agent pushes. If you already run a coding-agent loop or a Claude Code command that needs an isolated workspace, that remote is the missing piece between "the model edited files in a sandbox" and "the change lives on a cloneable, reviewable history."
Docs lag, on purpose: some Artifacts documentation pages still read like a closed beta with a request form. Prefer the October 2026 Cloudflare Blog and the pricing page for access and billing. The April 16, 2026 private-beta post aimed for public beta in early May; the open-beta announcement is arriving in October.
TL;DR — what people are asking
| Question | Answer |
|---|---|
| What shipped today? | Artifacts open beta on Workers Paid (Oct 1, 2026) |
| What is Artifacts? | Versioned filesystem that speaks Git — REST, Workers binding, and smart HTTP |
| Who can use it? | Workers Paid only. Unavailable on Workers Free |
| When does billing start? | Oct 15, 2026 on the launch blog; Oct 14, 2026 on pricing + changelog (flag both) |
| Included usage? | First 10,000 ops/month; first 1 GB-month storage |
| Overage? | $0.15 per extra 1,000 ops; $0.50 per extra GB-month |
| Contest deadline? | October 14, 2026 |
| Contest prize? | Top 3 to Cloudflare Connect in SF (up to 2 people each); 1st place $25,000 credits + VIP dinner |
| Why Git, not a new protocol? | Agents already know git clone / commit / push |
| Do docs still say closed beta? | Some pages might. Treat the Oct 2026 blog + pricing page as canonical for access |
Why a real Git remote beats a bespoke agent protocol

The April engineering post is still the clearest design rationale. Cloudflare could have invented a custom object store protocol. Then every model would need a skill pack, a CLI, or a docs MCP server just to learn the verbs.
Instead Artifacts returns a remote URL and a token. Any Git client that speaks smart HTTP can operate on it. That includes a laptop, a CI job, isomorphic-git in a Worker, or a coding agent that already shells out to git.
Cloudflare's own wording from April:
We could have invented an entirely new, bespoke protocol… but then you have the bootstrap problem. AI models don’t know it… If we can just give agents an authenticated, secure HTTPS Git remote URL and have them operate as if it were a Git repo, though? That turns out to work pretty well.
The October product post is the same idea at platform scale: vibe-coding products storing user projects, per-session repos for agent context, and isolated forks so several agents can start from one baseline and merge later.
That last pattern is the one explainx.ai cares about. A loop that fans out N agents onto one shared checkout will fight itself. A loop that forks N Artifacts repos, lets each agent push, then diffs the remotes, is something you can actually review.
What the Workers binding can do this week
Cloudflare's October post lists capabilities added since the private beta. Keep the official docs as the API authority; this table is the practitioner map.
| Capability | What it is for |
|---|---|
| Create / import / fork | One repo per agent, session, task, or user |
| Read files and commits | Pull AGENTS.md or a specific path without a full clone |
| Repo-scoped Git tokens | Hand a short-lived credential to one agent, not an account token |
| Workers Builds | Production-branch push deploys the Worker |
| Workers Previews | Non-production branch push creates or updates an isolated preview |
| Event subscriptions | Queue a review workflow on cf.artifacts.repo.pushed (and create/import/fork/delete/clone/fetch) |
| Jurisdiction | Set us or eu on the namespace; repos inherit it |
| Dashboard metrics | Ops, pulls, pushes, errors, error rate per repo |
The fork-and-read snippet Cloudflare published is the shape you want in a task dispatcher:
using project = await env.ARTIFACTS.get("my-project");
const { defaultBranch } = await project.info();
const workspace = await project.fork(`task-${crypto.randomUUID()}`);
using repo = await env.ARTIFACTS.get(workspace.name);
const instructions = await repo.readFile({
ref: defaultBranch,
path: "AGENTS.md",
});
const agentTask = {
remote: workspace.remote,
token: workspace.token,
instructions: instructions ? await instructions.text() : null,
};
Then the agent gets remote + token and does ordinary Git:
git clone "https://x:${TOKEN}@artifacts.cloudflare.net/<namespace>/<repo>.git"
# agent edits, commits
git push
Exact host paths have moved between the April sample (*.artifacts.cloudflare.net/git/...) and later changelog examples (artifacts.cloudflare.net/<namespace>/<repo>.git). Copy the remote from create() / import() / the dashboard rather than hard-coding a host from an old blog snippet.
Pushes into a connected Artifacts repo can now land on the same preview surface explainx.ai covered in September: Worker Previews isolate Durable Objects and Containers per branch. The October Artifacts post says production-branch pushes deploy via Workers Builds, and other branches automatically create or update Workers Previews. That is the close of the loop Cloudflare has been assembling all year: isolate-first compute, a Git remote the agent already knows, and a preview URL a reviewer can open.
Pricing, limits, and the date that does not quite agree
Treat money as a first-class question. Cloudflare published two billing dimensions on the Artifacts pricing page:
| Unit | Workers Free | Workers Paid |
|---|---|---|
| Operations (per 1,000) | Unavailable | First 10,000/month, then $0.15 per extra 1,000 |
| Storage (GB-month) | Unavailable | First 1 GB/month, then $0.50 per extra GB-month |
Storage is GB-month, averaged like Durable Objects SQL storage: peak storage per day, averaged over a 30-day period, across all repositories. Replicas do not add a storage line. Repos stay until you delete them.
Billing start date: the October 1 blog says Cloudflare will begin billing on October 15, 2026. The pricing page and the October 1 changelog entry currently say October 14, 2026. Do not pretend those are the same day. Re-check both pages before you forecast a bill; explainx.ai is not picking a winner between Cloudflare's own tabs.
Included 1 GB is not the same as the per-repo cap. Limits currently list:
| Limit | Value |
|---|---|
| Max storage per repository | 1 GB |
| Max file / blob | 32 MB |
| Max storage per account | 1 TB (raise on request) |
| Repos / namespaces | Unlimited |
| Control-plane rate | 2,000 requests / 10 seconds / namespace |
| Git rate | 2,000 requests / 10 seconds / artifact |
A million tiny session repos can still be cheap on operations if they sit idle — Cloudflare's April pricing thesis was that unused repos should not be a drag — but they still consume storage GB-month until you delete them, and a single repo cannot grow past 1 GB. This is not a dump for multi-gig monorepos unless you live inside ArtifactFS and still respect that cap.
Wrangler already has control-plane commands from the May 18 changelog (wrangler artifacts namespaces list, repos create, repos issue-token, and siblings). Use those for humans; use the binding for agents.
How Artifacts is built (so you know what will bite)
The April post is still the architecture reference. Artifacts sits on Durable Objects. Each repository is a DO. A Worker fronts auth and lookup. Files live in the DO's SQLite. Rows cap at 2 MB, so large Git objects are chunked. DOs have on the order of 128 MB of memory, which is why Cloudflare streams pack traffic instead of buffering a whole repo in RAM.
The Git engine is a Zig implementation compiled to WebAssembly — Cloudflare quoted a ~100 KB WASM binary covering SHA-1, zlib, deltas, pack parsing, and Git smart HTTP, talking to the JS host through a small set of storage callbacks. R2 holds snapshots; KV tracks auth tokens. Protocol support includes v1 and v2, ls-refs, shallow clones, and incremental fetch. git-notes are first-class so agents can attach prompts and attribution without rewriting objects.
That is why "unlimited repos" is a Durable Object claim, not a marketing slogan. It is also why a 2.4 GB framework checkout is the example Cloudflare used for ArtifactFS: a blobless clone that hydrates file contents in the background so an agent can start in tens of seconds instead of waiting minutes. ArtifactFS, per April, works against any Git remote, not only Artifacts. The filesystem does not sync writes back; the agent still commits and pushes.
Cloudflare Computer already grew an examples/artifacts path that publishes a Worker project as a clone-ready Artifacts repo. If you are on that runtime, open beta is the moment that example stops being a private-beta toy.
The contest: what Cloudflare will actually look at
Cloudflare is explicit about what it does not want: "GitHub as it exists today with agents added on top." Minimum bar: multiple agents working on changes concurrently. The rest is open — new review UX, worktree semantics, conflict models, agent-context preservation.
Submit by October 14, 2026:
- A 5–10 minute video of what you built and how it works
- Source under MIT, Apache, or BSD
- Instructions to run it
Top three teams: Cloudflare flies up to two people each to San Francisco for Cloudflare Connect. First place: $25,000 in Cloudflare credits plus the Monday-night VIP speaker dinner.
That deadline is one day before the blog's billing date and the same day as the pricing page's billing date. If you are entering, you can still build during the unbilled window; if you are not, do not assume the product stays free after mid-October.
What people are asking (and the honest gaps)
"Is this a GitHub replacement?" No. It is storage and Git protocol plus hooks into Workers. Issues, org IAM, CODEOWNERS, and the social layer of a Git host are the contest, not the SKU.
"Can I keep using GitHub as origin and Artifacts as agent scratch?" Yes in spirit: import() from an existing Git URL, fork read-only or read-write copies, let agents push to the fork, then you decide what merges back. Cloudflare's samples literally import cloudflare/workers-sdk. Do not confuse that with a bidirectional sync product; you still own the merge policy.
"Will this show up in ChatGPT / Claude without a Git CLI?" Only if your harness exposes Git or you call the REST / Workers API yourself. Hosting an MCP server on ChatGPT Sites does not give you Artifacts. You would still wrap clone/push as tools, or teach the agent the remote URL. Artifacts is the store, not the chat plugin.
"Why are the docs still saying closed beta?" Because Cloudflare shipped the open-beta blog and changelog on October 1 while some developer-docs shells still show a May-era "request access" note. That is a documentation race, not a second product. If the dashboard lets a Workers Paid account create a namespace today, you are in.
"When did public beta actually happen?" April promised early May 2026. Changelog milestones after that: Wrangler commands (May 18), dashboard (June 17, still talking about a beta form), EU/US jurisdiction (August 13), open beta (October 1). The May target slipped. Say so.
"Is 1 GB per repo enough?" For agent session trees, generated apps, and config history, usually. For a giant monorepo with LFS binaries, no — and 32 MB blob limits make that explicit. ArtifactFS helps cold-start; it does not raise the cap.
"What about Free plan?" Still unavailable. April said Free would arrive later in the beta with fair limits. October's pricing table still says Unavailable.
A practical agent wiring (copy the shape, not a fake SKU)
You do not need the contest to get value this week. A small dispatcher Worker is enough:
On new ticket
1. ARTIFACTS.get(baseline).fork(ticket-id)
2. Issue a write token with a short TTL
3. Pass remote + token + AGENTS.md into the harness
4. Agent: clone, branch, commit, push
5. Queue worker on cf.artifacts.repo.pushed
6. Review agent diffs against baseline
7. Human or policy merges; delete or freeze the fork
Pair that with Worker Previews so the pushed branch is not only a Git object but a URL with isolated Durable Object state. Keep secrets out of the repo; the token is the credential, and it should expire.
If your harness is Claude Code, a slash command that receives remote and token is more reliable than hoping the model invents Cloudflare's REST paths. That is the same discipline as the rest of Claude Code's command surface: named, reviewable, repeatable.
Honest limitations
- Workers Paid only. No Free-plan trial in the published table.
- Billing starts mid-October 2026, with a one-day disagreement between blog (15th) and pricing/changelog (14th).
- 1 GB per repo and 32 MB per blob are hard product limits, not "soft until you ask."
- 1 GB-month included is account-wide storage, not 1 GB free per repo.
- Open beta means APIs, remote URL formats, and dashboard copy can still move. The April WASM Git server and DO layout are implementation detail, not a customer SLA.
- Not a GitHub/GitLab feature-complete host. Collaboration UX is the competition brief.
- Jurisdiction is namespace-scoped and immutable after create. Pick
eu/usbefore you mint a million repos in the default unrestricted namespace. - Event subscriptions and Builds/Previews are the interesting half; if you only store blobs and never subscribe, you bought a Git remote without the agent-native control plane.
- Some docs pages may still say closed beta. That is a discrepancy to flag, not a reason to ignore the October blog.
What builders should do this week
- If you already have Workers Paid, create a namespace in the dashboard (Storage and databases → Artifacts) and mint one throwaway repo. Confirm you were not stopped by a waitlist form.
- Wire
create/fork/readFilein a Worker. Handremote+tokento one agent session. Watch agit pushshow up in repo metrics. - Connect a Worker to that repo and push a non-main branch. Confirm a Preview appears. That is the test that Artifacts is more than object storage.
- Model cost as ops + GB-month, not "unlimited repos are free." Delete session repos or they will sit on the storage meter after October 14/15.
- If you have a platform idea, the contest clock is October 14. Permissive license is required; do not submit proprietary glue.
Closing
Artifacts open beta is Cloudflare productizing the claim that agents should speak Git, not a vendor RPC. The Workers binding, scoped tokens, Builds/Previews, and push events are the control plane. The contest is Cloudflare admitting the review-and-merge layer is still unsolved and paying people to try.
Use it as a per-agent remote this month if you are on Workers Paid. Re-read pricing before mid-October. Ignore stale "closed beta" banners when they contradict the October 1 blog.
Follow @explainx_ai as the docs, billing date, and contest entries catch up.
Related on explainx.ai
- Cloudflare Computer: agents need isolates, not just containers — the execution side of the same agent-cloud bet
- Cloudflare Worker Previews: a production-like environment per git branch — what Artifacts branch pushes can now deploy into
- Loop engineering: coding-agent loops that run while you sleep — why one shared checkout is the wrong primitive for N agents
- Claude Code commands complete reference — where a
remote+tokenhandoff belongs in a harness - What is MCP? — the other way to give tools to models; Artifacts is Git, not MCP
- Host an MCP server on ChatGPT Sites — still not a Git remote; wrap clone/push yourself
- Cloudflare OS: Gatekeepers and Gadgets — workspace policy sitting above storage
- Cloudflare temporary accounts for AI agents — another Wrangler path for agent-driven deploys
Sources
- Cloudflare Blog — We want you to build the next Git platform on Cloudflare (October 1, 2026)
- Cloudflare Blog — Artifacts: versioned storage that speaks Git (April 16, 2026, private beta)
- Cloudflare Artifacts docs
- Artifacts pricing
- Artifacts limits
- Artifacts changelog
- Cloudflare Artifacts product page
Access, prices, limits, remote URL formats, and the contest rules reflect Cloudflare's October 1, 2026 open-beta materials and the pages linked above. Re-check the blog, pricing table, and changelog before you rely on a billing date or a host name — those have already disagreed across Cloudflare's own surfaces.
