IAM

D1-backed organizations, projects, users, workers, agents, permission grants, token exchange, billing chains, and spending limits for Tumbric Cloudflare apps.

Hierarchy

Organizations own projects. Apps store organization and project IDs for their own namespaced data.

Agents

Agent API keys exchange for short-lived bearer tokens whose permissions are a subset of the creator.

Budgets

Spend checks evaluate the lowest remaining limit across identities, projects, jobs, sessions, and resources.

GET /api/whoami and GET /api/apps require Cloudflare Access or an IAM bearer token.