· via dev.to (home feed)
Cloudflare Agents SDK adds free-tier MCP clients and Durable Objects
The Cloudflare Agents SDK now supports MCP clients and Durable Objects on the free tier, letting developers ship a stateful, tool-using AI agent at the edge with no compute bill.

Free-tier agents become practical
Cloudflare's Agents SDK now supports MCP clients and Durable Objects on the free tier, according to a walkthrough on dev.to. In practice, that means a developer can build and deploy a stateful, tool-using AI agent that runs at Cloudflare's edge, scales to zero when idle, and generates no infrastructure bill until usage pushes past the free limits.
The three layers
The post breaks the architecture into three cooperating pieces. Workers supply the compute: a lightweight, globally distributed JavaScript and TypeScript runtime that handles HTTP requests and executes agent logic. Durable Objects supply the state: single-instance, strongly consistent objects with ACID transaction guarantees, used for agent state, conversation history and context. The MCP (Model Context Protocol) client and server layer supplies integration, letting agents call external services — the author cites SAP, GitHub and databases — or host MCP servers that other agents can connect to.
In the flow the author describes, a Worker receives a request, an MCP client queries external services using context stored in a Durable Object, the agent reasons over the result, and the response returns with what the post claims is sub-second global latency.
Two ways to expose an MCP server
For stateful, long-running agents, the SDK offers a McpAgent base class. This suits agents that need to maintain conversation state or accumulate knowledge over time, and the same class can serve custom HTTP endpoints alongside standard MCP requests for tools, resources and prompts.
For stateless work, createMcpHandler builds a standalone handler that can be mounted in any Worker under a route such as /mcp. The author recommends it for simple, idempotent operations, or when external stores like Cloudflare D1 or Workers KV hold the state instead.
What the free tier actually allows
The post lists limits worth knowing before committing to an architecture. Workers on the free tier get 100,000 requests per day, 10 MB of total memory storage, an average of 50ms of CPU time per request, a 30-second maximum request duration and 30 unique scripts. Durable Objects allow 1,000 objects, 128 MB of total storage across all of them, 1,000 reads and writes per day per object, and a 10-second maximum per call.
Caveats include no custom domains (only a workers.dev subdomain), limited diagnostics, no uptime SLA and possible rate limiting during peak periods. The $5 per month paid tier raises most limits roughly tenfold, the author notes. Since these figures come from a single community post rather than Cloudflare's pricing documentation, treat them as a starting point rather than a guarantee.
Code Mode instead of tool dumping
The post's sharpest argument concerns tool design. Agents that expose every backend function as a separate tool — potentially more than 200 for an SAP integration — flood the model's context window and make tool selection unreliable. The alternative the SDK supports is a single execute_code tool that runs model-written JavaScript in a sandboxed context with timeouts and resource limits.
The claimed benefits: one tool definition instead of hundreds, dynamic composition of operations, no need to predict every operation in advance, backend changes without touching tool definitions, and explicit security boundaries. For SAP specifically, the author suggests one abstraction-layer tool for constructing queries and function calls rather than a function-by-function surface.
OAuth for enterprise access
Connecting an agent to business systems needs real authentication. The post walks through the standard OAuth 2.0 authorization-code flow and recommends using established client libraries rather than hand-rolled implementations, encrypting tokens before storing them in a Durable Object or KV, refreshing tokens automatically before expiry and requesting the narrowest possible scopes. Provider-specific notes include GitHub token scopes, Salesforce's JWT Bearer flow for server-to-server access, and SAML Bearer or client-credentials flows for SAP depending on the landscape.
Why it matters
The cost floor for shipping a production-shaped agent has effectively dropped to zero for prototypes and low-traffic workloads. Durable state and a standard tool protocol — the two requirements that usually push teams toward paid servers — are now available without a credit card, and the next step up is a $5 plan rather than a cluster to operate. The constraints are operational rather than financial: 1,000 reads and writes per day per Durable Object will bite a chatty agent quickly, and the absence of an SLA or detailed diagnostics matters once real users depend on the result. For experimentation and MVPs, though, the economics of edge-hosted agents have changed meaningfully.
- #cloudflare
- #mcp
- #ai-agents
- #serverless
- #durable-objects