Self-hosted service
cloudflare/moltworker avatar
cloudflare/moltworker

Moltworker: Running OpenClaw on Cloudflare Workers via Sandbox Containers

Run OpenClaw, (formerly Moltbot, formerly Clawdbot) on Cloudflare Workers.

9,955 stars1,716 forksTypeScriptApache-2.0

At a glance

What is it?
Moltworker packages the OpenClaw personal AI assistant for deployment inside a Cloudflare Sandbox container, letting individuals run an always-on AI agent without managing a server. It is explicitly experimental, carries no official support, and the README estimates always-on compute at roughly $34.50 per month.
Who is it for?
Moltworker is the right choice for an individual who wants to run OpenClaw across Telegram, Discord, or Slack without maintaining a server, and who already has a Cloudflare account. The Workers Paid plan is a hard requirement even if the container spends most of its time sleeping.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 144 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

DEEP OPEN-SOURCE ANALYSIS

What moltworker packages and who it is for

Moltworker is a deployment wrapper. It does not contain the AI assistant itself; that is OpenClaw (previously named Moltbot, previously Clawdbot), a personal AI assistant with a gateway architecture that connects to Telegram, Discord, and Slack simultaneously. OpenClaw also exposes a web-based Control UI and supports device pairing, persistent conversations, and an extensible agent runtime with skills. Moltworker adds a single thing: it runs OpenClaw inside a Cloudflare Sandbox container, eliminating the need for a self-hosted server. The target user is an individual who already pays for Cloudflare's Workers Paid plan and wants a personal AI without configuring and maintaining a VPS. The repository carries a prominent warning: this is a proof of concept, not an officially supported product, and may break without notice.

The Sandbox container architecture behind the worker

The deployment model puts two pieces in place. A Cloudflare Worker receives all incoming traffic and proxies requests to a Sandbox container. That container runs OpenClaw on a standard-1 instance: one-half vCPU, 4 GiB of memory, and 8 GB of disk. The Dockerfile in the repository installs Node.js 22 on top of the cloudflare/sandbox base image, then installs a pinned version of OpenClaw via npm. The home directory for OpenClaw is set to /home/openclaw rather than /root, because the Sandbox SDK backup API only permits directories under /home, /workspace, /tmp, or /var/tmp. Persistence across container restarts is optional: enabling R2 storage means paired devices and conversation history survive a container restart. Without R2, a restart clears that state. Cloudflare Access (which has a free tier) handles authentication, and Browser Rendering is available for tasks that require web navigation.

Deploying moltworker: install, secrets, and the first access

Clone the repository and install dependencies with the standard Node.js workflow:

bash
# Install dependencies
npm install

# Set your API key (direct Anthropic access)
npx wrangler secret put ANTHROPIC_API_KEY

Alternatively, the Cloudflare AI Gateway can replace the direct Anthropic key for API routing and analytics. After setting the API key, generate a gateway token and deploy with `npm run deploy`, which runs `npm run build && wrangler deploy` as defined in package.json. The Control UI becomes available at your worker subdomain with the token as a query parameter. The README notes the first request may take one to two minutes while the container starts. Before the UI is usable, two additional steps are required: enabling Cloudflare Access on the worker and completing device pairing via the admin UI at /_admin/.

Setting up Cloudflare Access and device pairing

The admin UI at /_admin/ is not accessible until Cloudflare Access is configured. The process involves enabling the built-in Cloudflare Access integration from the Workers and Pages dashboard, then copying the Application Audience (AUD) tag. Once that is done, two secrets must be set so the worker can validate JWTs:

bash
# Your Cloudflare Access team domain (e.g., "myteam.cloudflareaccess.com")
npx wrangler secret put CF_ACCESS_TEAM_DOMAIN

# The Application Audience (AUD) tag from your Access application that you copied in the step above
npx wrangler secret put CF_ACCESS_AUD

After redeploying, the admin UI becomes accessible to the configured email addresses or identity providers. Device pairing then happens via DM authentication and requires explicit approval, which is how OpenClaw controls which devices can interact with the assistant.

Container cost breakdown and the SANDBOX_SLEEP_AFTER option

The README provides a detailed cost table for a standard-1 instance running 24 hours a day, 7 days a week. Memory (4 GiB) accounts for roughly $26 per month because it is billed on provisioned capacity for as long as the container is running. CPU at an estimated 10 percent utilization adds about $2 per month because CPU is billed on active usage only. Disk (8 GB) adds about $1.50 per month. The Workers Paid plan is $5 per month. The total comes to approximately $34.50 per month for always-on operation. Setting SANDBOX_SLEEP_AFTER to a value such as 10m causes the container to sleep when idle. A container running only four hours per day would drop compute costs to roughly $5 to $6 per month on top of the plan fee. The lite instance type (256 MiB, $0.50 per month for memory) is listed in Cloudflare's pricing table as an alternative for lighter use.

Experimental limitations and the self-hosted OpenClaw alternative

The core limitation is the project's stated status: experimental and not officially supported. The repository has no GitHub releases, which means there is no versioned artifact to pin. Changes may break the deployment without warning. The minimum monthly cost is $5 even if the container sleeps almost all the time, because the Workers Paid plan has no free tier for Sandbox containers. The TypeScript build chain uses Vite for the frontend (the control UI in index.html and the public/ directory) and Wrangler for the Worker deployment; both are listed in devDependencies. Running npm run dev starts the Vite development server; npm run start invokes wrangler dev for local Worker testing. The skills/ directory at the repository root contains OpenClaw skill definitions that the running container can load. Developers comfortable with server administration have the alternative of running OpenClaw directly on a VPS or home server. That approach eliminates the Cloudflare dependency and the per-minute container billing, but it puts the responsibility for uptime, system updates, and security on the operator. Moltworker's concrete advantage is the managed infrastructure: Cloudflare handles the network edge, Access handles authentication, and no operating system needs patching. The trade-off is the experimental status and the fixed baseline cost. The last push to the repository was on 2026-05-09. The Apache-2.0 license permits commercial and private use with attribution, and imposes no copyleft obligation on derived work.

Editorial conclusion

Moltworker is the right choice for an individual who wants to run OpenClaw across Telegram, Discord, or Slack without maintaining a server, and who already has a Cloudflare account. The Workers Paid plan is a hard requirement even if the container spends most of its time sleeping. Anyone who needs a stable, production-grade deployment should verify the experimental status first: the README states the project is not officially supported and may break without notice.

Frequently asked questions

What can Moltbot (OpenClaw) do?

According to the README, OpenClaw supports multi-channel messaging across Telegram, Discord, and Slack, provides a web-based Control UI, enables device pairing with DM authentication, maintains persistent conversation history across sessions, and includes an extensible agent runtime with workspace and skills.

Is moltworker free?

No. Moltworker requires the Cloudflare Workers Paid plan at $5 per month, and the container incurs additional compute costs. The README estimates always-on operation at about $34.50 per month; using the SANDBOX_SLEEP_AFTER setting can reduce compute to around $5 to $6 per month extra if the container only runs a few hours daily.

What is the difference between moltworker and OpenClaw?

OpenClaw is the personal AI assistant itself; moltworker is a Cloudflare-specific deployment wrapper that packages OpenClaw to run inside a Cloudflare Sandbox container. OpenClaw can be run directly on a server without moltworker; moltworker exists to make deployment on Cloudflare's infrastructure straightforward.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
For maintainers

Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/cloudflare-moltworker.svg)](https://hysenlabs.com/projects/cloudflare-moltworker)
Community notes

Community notes