IAM
D1-backed organizations, projects, users, workers, agents, permission grants, token exchange, billing chains, and spending limits for Tumbric Cloudflare apps.
Hierarchy
Organizations own projects. Apps store organization and project IDs for their own namespaced data.
Agents
Agent API keys exchange for short-lived bearer tokens whose permissions are a subset of the creator.
Budgets
Spend checks evaluate the lowest remaining limit across identities, projects, jobs, sessions, and resources.
GET /api/whoami and GET /api/apps require Cloudflare Access or an IAM bearer token.