{"_self":{"principle":"Self-explaining payload — no external context required. This _self block describes what you are reading and where to look next.","widget":"article_bundle","feature":"bundle","name":"LLM article bundle","what":"Portable reference package: body + claims + sources + voxels + provenance + manifest + constitution.","contains":"body, claims, sources, voxels, provenance, question graph, constitution, llm_manifest","slug":"cloudflare-os-kv","urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-os-kv/bundle?format=markdown"},"how_to_use":"Reference bundle for an LLM or reader. §SELF explains the surface; ingest and claim endpoints in llm_manifest are the write-back routes.","write":null,"imessage":null,"router_tag":null,"proof_chain":[{"step":1,"claim":"Articles are voxel graphs of tiered claims, not prose blobs.","verify":"https://miscsubjects.com/api/articles/constitution"},{"step":2,"claim":"Claims link to hash-chained sources via source_ids.","verify":"https://miscsubjects.com/api/articles/cloudflare-os-kv/sources"},{"step":3,"claim":"Ask reads topology; ingest/claim append to ledger.","verify":"https://miscsubjects.com/api/protocol"},{"step":4,"claim":"Models queue growth: populate → collaborate → repair → reflex.","verify":"https://miscsubjects.com/api/protocol/grow"},{"step":5,"claim":"Graph proves its own shape (reflex) and $/claim (yield).","verify":"https://miscsubjects.com/graph.html?layer=reflex"},{"step":6,"claim":"Full feature index + _explain on every API response.","verify":"https://miscsubjects.com/api/articles/system-map"}],"related_features":[{"id":"topology","name":"Article topology","what":"Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER.","urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-os-kv/topology"}},{"id":"voxels","name":"Voxel graph","what":"Claims as atoms, sources as edges (supported_by, posted_by). Per-claim provenance.","urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-os-kv/voxels","write":"https://miscsubjects.com/api/protocol/claim"}},{"id":"ask","name":"Ask protocol","what":"Answer only from topology; creates question_node with gaps and ingest_hint.","urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-os-kv/prompts","write":"https://miscsubjects.com/api/protocol/ask"}},{"id":"ingest","name":"Ingest protocol","what":"Parse pasted evidence → source ledger + claims + evidence_ingest node.","urls":{"write":"https://miscsubjects.com/api/protocol/ingest"}},{"id":"claim_post","name":"Claim post protocol","what":"Prompt-injection style POST — one claim voxel with who_claims + posted_by.","urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-os-kv/voxels","write":"https://miscsubjects.com/api/protocol/claim"}},{"id":"llm_manifest","name":"LLM manifest","what":"Machine-readable read/write contract for external LLMs.","urls":{"read":"https://miscsubjects.com/api/articles/llm-manifest"}}],"system_map":"https://miscsubjects.com/api/articles/system-map","system_map_markdown":"https://miscsubjects.com/api/articles/system-map?format=markdown","not_medical_advice":true},"_explain":{"feature":"bundle","name":"LLM article bundle","what":"Portable reference package: body + claims + sources + voxels + provenance + manifest + constitution.","why":"Every feature is auditable collective intelligence","how":"Reference bundle for an LLM or reader. §SELF explains the surface; ingest and claim endpoints in llm_manifest are the write-back routes.","model":null,"verifies":null,"urls":{"read":"https://miscsubjects.com/api/articles/cloudflare-os-kv/bundle?format=markdown"},"imessage":null,"router":null,"related":[{"id":"topology","what":"Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER."},{"id":"voxels","what":"Claims as atoms, sources as edges (supported_by, posted_by). Per-claim provenance."},{"id":"ask","what":"Answer only from topology; creates question_node with gaps and ingest_hint."},{"id":"ingest","what":"Parse pasted evidence → source ledger + claims + evidence_ingest node."},{"id":"claim_post","what":"Prompt-injection style POST — one claim voxel with who_claims + posted_by."},{"id":"llm_manifest","what":"Machine-readable read/write contract for external LLMs."}],"not_medical_advice":true},"MASTHEAD":{"sorry_status":"planes not merged yet — sorry-status activates after voxel-merge-planes","identity":{"slug":"cloudflare-os-kv","version":8,"content_hash":"84b79fd1203e285d04316a14b7ffb917fc3e535038c54210cd94ed4eecf7d226","thread_head":"genesis","divs":null},"thesis":{"root_claim":"c1","text":"Workers KV is a globally cached key-value read layer with eventual propagation, not a transactional distributed database.","tier":"system"},"load_bearing":[{"id":"c2","tier":"fact","status":"active","text":"A recently read value or missing key can remain stale in another location for up to 60 seconds or the configured cacheTtl."},{"id":"c3","tier":"fact","status":"active","text":"Concurrent writes to one KV key can overwrite one another without an atomic compare-and-set."},{"id":"c4","tier":"fact","status":"active","text":"KV writes cost $5 per million after the allowance while reads cost $0.50 per million."},{"id":"c5","tier":"fact","status":"active","text":"A missing-key read is billable even though it returns null or 404."},{"id":"c6","tier":"calculation","status":"active","text":"The 2021 operator price comparison still matches the July 2026 KV read and write rates."},{"id":"c7","tier":"system","status":"active","text":"Putting caches.default before KV bounds refresh writes by cache expiry rather than request traffic."},{"id":"c8","tier":"fact","status":"active","text":"KV limits keys to 512 bytes, values to 25 MiB, metadata to 1024 bytes and same-key writes to one per second."}],"standing_objections":{"open":0,"strongest_open":null,"link":"https://miscsubjects.com/api/articles/cloudflare-os-kv/discourse"},"verbs":{"read":"GET https://miscsubjects.com/api/articles/cloudflare-os-kv/voxels — DIVs + hashes + chains (free)","read_claims":"GET https://miscsubjects.com/api/articles/cloudflare-os-kv/claims — every formal claim as claim:<id> with current hash, thread, stable link, and exact contribution/edit bodies","challenge":"POST https://miscsubjects.com/api/protocol/voxel-challenge {slug, expected_thread_head, target_div?, expected_hash?, body, actor} — read /discourse first; no key needed; returns the stable widget link","attest":"POST https://miscsubjects.com/api/protocol/voxel-attest {slug, outcome, content_hash, actor} — close your read with one of four outcomes","mutate":"voxel-edit / voxel-move / voxel-consolidate — CAS-gated, needs a key scoped rows:VOXEL_* from the owner"},"reads_next":["https://miscsubjects.com/a/philosophy","https://miscsubjects.com/api/articles/cloudflare-os-kv/discourse","https://miscsubjects.com/api/protocol"]},"bundle_version":1,"generated_at":"2026-07-29T18:40:59.056Z","slug":"cloudflare-os-kv","title":"Workers KV makes reads fast by making writes slow and consistency optional","url":"https://miscsubjects.com/a/cloudflare-os-kv","register":"essay","tags":["cloudflare","architecture","kv","cloudflare-os","workers-kv","cache","eventual-consistency","durable-objects","pricing"],"posted_at":"2026-07-26T03:59:22.235Z","updated_at":"2026-07-26T05:49:25.362Z","body":"Workers KV is a key-value store with one central copy of your data and a cache of that copy in every Cloudflare location that has recently asked for it. Reads from a location that already holds the key are the fastest storage read on the platform. Writes go to the centre and take their time getting everywhere else. Every decision on this page follows from that one asymmetry.\n\nThe short answer to \"should this state live in KV\": if losing sixty seconds of freshness in another continent is survivable, yes. If two requests might write the same key at the same time and the result has to be correct, no.\n\n## Evidence status\n\n**Observed** marks first-party measurements or runtime receipts from the named environment.\n**Derived** marks arithmetic calculated from cited inputs. **Specified** marks vendor or standards\ndocumentation. **Implemented** and **deployed** name code and live-state evidence, respectively.\n**Reproduced** means the stated procedure was rerun. **Externally attested** marks operator reports;\nthose reports show that an experience occurred, not that it is universal.\n\n## Cloudflare's own Workers lead calls the database use a misuse\n\nKenton Varda, who leads the Workers team, answered a developer who had adopted KV as their datastore:\n\n> KV is not a distributed database and is really not intended as a database alternative at all. It's more meant for distributing bits of config globally. Cost aside, writes are way too slow for database-ish use\n\nHe pointed at Durable Object SQLite storage and at Hyperdrive instead. Take the sentence literally: **bits of config**. Flags, routing tables, rendered snapshots, allow-lists, prompt blocks. Not carts, not counters, not sessions that mutate, not anything two writers touch.\n\n[[widget:0]]\n\n## Eventual consistency, in the exact words of the reference\n\nThe Workers Binding API reference states the write behaviour without softening it:\n\n> Due to the eventually consistent nature of KV, concurrent writes to the same key can end up overwriting one another.\n\nand\n\n> Writes are immediately visible to other requests in the same global network location, but can take up to 60 seconds (or the value of the `cacheTtl` parameter of the `get()` or `getWithMetadata()` methods) to be visible in other parts of the world.\n\nThe read reference is equally blunt: `get()` and `getWithMetadata()` \"may return stale values\". The concepts page adds the trap most people miss — **a miss is cached too**:\n\n> Negative lookups indicating that the key does not exist are also cached, so the same delay exists noticing a value is created as when a value is changed.\n\nSo a location that asked for `flag:new_checkout` before you created it will keep answering `null` for up to sixty seconds after the key exists. Nothing retries on your behalf.\n\n### What a reader in another region actually sees after a write\n\n| Moment after the write | Same location as the writer | A location that has never read the key | A location that read the key (or its absence) recently |\n| --- | --- | --- | --- |\n| 0–1 s | New value, usually | New value — nothing cached to serve instead | Old value, or `null` |\n| 1–60 s | New value | New value | Old value, or `null`, until the cached copy times out |\n| After 60 s | New value | New value | New value |\n| With `cacheTtl: 3600` set on the read | New value | New value | Old value for up to an hour |\n\n\"Usually\" is the documentation's word, not a hedge added here: *\"At the Cloudflare global network location at which changes are made, these changes are usually immediately visible. However, this is not guaranteed and therefore it is not advised to rely on this behaviour.\"* There is no read-after-write guarantee anywhere in KV, including at the writing location.\n\n### The safety rule, applied to real states\n\n| State | Safe in KV | Why |\n| --- | --- | --- |\n| Rendered page snapshot | Yes | A stale page is a slightly old page. The next render replaces it. |\n| Feature flag, kill switch | Yes | Rollout is a minute, not a millisecond. One writer, an operator. |\n| Routing table, agent prompt block | Yes | Changes are deliberate and infrequent; a minute of skew is invisible. |\n| Allow-list / deny-list | Yes, with a caveat | Adding is fine. Revocation is not — a revoked entry stays live for the propagation window. Pair with a short `cacheTtl` or a second, authoritative check. |\n| Session state that mutates per request | No | Read-modify-write on the same key. Concurrent writes overwrite each other. |\n| Counter, quota, rate limit | No | Same lost-update problem, every increment. |\n| Shopping cart, order status | No | Two tabs, two writes, one survivor, no error. |\n| A lock over anything contended | No | See the lock section below. |\n| The only copy of any fact | No, except flags | Nothing to rebuild it from when a write is lost. |\n\n## The rates, and the one that is ten times the others\n\nFetched from Cloudflare's KV pricing page today. All rates are per operation on a **per-key** basis; a bulk read of 50 keys is 50 billable reads.\n\n| Operation | Workers Free | Workers Paid (included, then rate) |\n| --- | --- | --- |\n| Read | 100,000 / day | 10 million / month, then $0.50 / million |\n| Write | 1,000 / day | 1 million / month, then $5.00 / million |\n| Delete | 1,000 / day | 1 million / month, then $5.00 / million |\n| List | 1,000 / day | 1 million / month, then $5.00 / million |\n| Stored data | 1 GB | 1 GB, then $0.50 / GB-month |\n\nTwo consequences worth stating flatly. **A write costs the same as ten reads.** And **a miss is billable**: \"All operations incur charges, including fetches for non-existent keys that return a null (Workers API) or HTTP 404 (REST API).\" A cache-aside pattern that checks KV before hitting a database pays for every check, hit or miss. Egress is free.\n\nFree-plan writes are the real cliff. One thousand writes a day is roughly one write every ninety seconds, sustained. Any per-request write pattern exhausts it before lunch.\n\n[[widget:1]]\n\n## kondro's 2021 arithmetic still prices out correctly in 2026\n\nFive years ago, on a Hacker News thread about R2 pricing, a commenter laid out the KV objection:\n\n> Workers KV is also eventually-consistent with no guarantee of read-after-write, which is a pretty big limitation compared to alternatives (S3 even has immediately-consistent list operations now after write).\n\nThe same comment put KV at $5 per million writes and $0.50 per million reads, called the reads pricier than S3's, and set that against Durable Object storage at $1 per million 4 KB writes with the Durable Object runtime cost stacked on top. Checked against today's published pages:\n\n| kondro's 2021 figure | Published rate, July 2026 | Verdict |\n| --- | --- | --- |\n| KV writes $5 / million | $5.00 / million | Unchanged |\n| KV reads $0.50 / million | $0.50 / million | Unchanged |\n| KV reads pricier per read than S3 | S3 Standard GET is \"$0.0004 per 1,000 requests\" = $0.40 / million | Still true. KV reads cost 25% more per operation. |\n| Durable Object storage $1 / million writes | SQLite-backed Durable Object storage: $1.00 / million rows written, first 50 million / month included | Same rate, and the free allowance is now fifty times KV's |\n| Durable Object runtime cost on top | $0.15 / million requests plus $12.50 / million GB-s of duration | Still stacked, and still the reason KV wins on pure read serving |\n\nThe one number that moved in KV's favour is nothing to do with KV: Durable Object storage now includes 50 million row writes a month against KV's 1 million. For a write-heavy key, a Durable Object is now cheaper *and* correct.\n\nR2 is the other comparison people make and get wrong in KV's favour. R2 Class B operations — the reads — are **$0.36 per million**, cheaper than KV's $0.50, with 10 million a month free and 10 GB of storage free against KV's 1 GB. R2 loses on latency, not on price.\n\n## Bounding writes by putting the edge cache in front of KV\n\nThe write rate, not the read rate, is what turns a KV bill into a surprise. An operator running a share-link backend described the defence, in a thread about a Durable Object alarm loop that had burned $34,000 in eight days:\n\n> The key property is that caches.default with Cache-Control: max-age=3600 becomes a natural throttle — at most 24 cache misses per day per key, so KV writes are bounded by (keys × 24) regardless of traffic.\n\nThe mechanism, step by step:\n\n1. The Worker checks `caches.default` first. A hit returns without touching KV at all — no read charge, no write charge.\n2. Only a miss reaches KV. Only a miss can trigger the refresh write.\n3. `Cache-Control: max-age=3600` means a given key can only miss once an hour per cache location.\n4. Therefore the *write* count per key is bounded by the number of cache expiries, not by the number of requests. Traffic can multiply by a thousand and the write bill does not move.\n\n**What it costs you:** freshness. A value written now is invisible behind that cache for up to an hour, on top of KV's own propagation window. You are choosing a bounded bill over a bounded staleness, and you cannot have both.\n\nThis codebase runs the same pattern with a shorter window. `functions/_middleware.js` sets `LASTGOOD_REFRESH_MS = 120000` and `refreshLastGood()` returns early when the stored snapshot is younger than that, so any one path writes its snapshot at most once per two minutes no matter how many misses arrive. The edge cache in front carries `public, max-age=120, s-maxage=600, stale-while-revalidate=86400` for article pages. The measured result is in the last section: 12,231 writes a day across 6,568 snapshot keys, against a theoretical ceiling of 6,568 × 720 = 4.7 million.\n\n## The per-key boundaries, and the error you get at each one\n\n| Limit | Value | What happens at the boundary |\n| --- | --- | --- |\n| Key size | 512 bytes | The operation is rejected. Long composite keys are the usual cause. |\n| Value size | 25 MiB | Write rejected. Anything approaching this belongs in [R2](/a/cloudflare-os-r2). |\n| Metadata size | 1024 bytes, serialized JSON | Write rejected. Metadata rides along with `list()` results, which is why it is worth keeping small deliberately. |\n| Writes to the same key | 1 per second, free and paid alike | Excess writes fail. This is a hard rate limit, not a billing threshold. |\n| Operations per Worker invocation | 1,000 | A bulk request counts as one. |\n| `expirationTtl` minimum | 60 seconds | Shorter values are rejected. A sub-minute lease is not expressible. |\n| `cacheTtl` minimum | 30 seconds | Below this the parameter is refused. |\n| Namespaces per account | 1,000 | — |\n\nThe key-size limit is the one that bites in production because it fails late and looks like something else. A pull request against Cloudflare's own `vinext` framework describes it exactly:\n\n> When the assembled key exceeds Cloudflare KV's 512-byte key limit, `handler.get` throws a 414 **before** the wrapped function runs — so control-flow signals like `notFound()`/`redirect()` never fire, and the user sees a generic 200 error boundary instead of a 404.\n\nTheir fix is the one to copy: budget for your prefix (they used 480 bytes to leave room for `<appPrefix>:cache:`), keep short keys verbatim so they stay debuggable, and hash only the overflowing part.\n\n## An eventually-consistent store cannot hold a lock, and this application's locks are only safe because nobody is racing\n\nThe honest answer first. A lock needs compare-and-set: test that nobody holds it and take it, atomically, with no window between the test and the take. KV has no such primitive. `get()` then `put()` is two operations with a gap, and the reference already told you what happens in that gap — concurrent writes to the same key overwrite one another, last write wins, no error returned to the loser.\n\nThree KV locks run in this application, all with the same shape:\n\n- **`locks:deploy:loop-safe-miscsubjects`** — `functions/_lib/fn_runners.js`, the `deployLease` runner. Reads the key, returns `ERR:deploy_lease:held:` if a live lease exists, otherwise writes a lease with a random `nonce` and `expirationTtl: 1800`. Release requires presenting the matching nonce, so a stale holder cannot free somebody else's lease. `scripts/ship.mjs` takes this lease before every deploy.\n- **`selftest:lock`** — `functions/api/selftest.js`. Same read-then-write, `expirationTtl: 1800`, with a 1,500,000 ms staleness window on the stored timestamp so an abandoned run does not block the next one forever.\n- **`fclaim:*`** — advisory file claims so two coding agents do not edit the same file, default lease 90 minutes.\n\nEach of these is a genuine race. Two `acquire` calls landing inside the same second both read no lease, both write, and the second write wins silently. What makes the pattern survivable here, and the condition must be said out loud:\n\n**These locks are safe only because contention is near zero.** A deploy happens a few times a day, initiated by a human or one agent. A self-test run is a scheduled singleton. Two agents claiming the same file inside the same second is a coincidence, not a workload. Change any of those assumptions — a deploy fired by webhook on every push, a self-test on a one-minute cron — and the lock stops working, quietly, with no error to tell you.\n\nThe codebase already contains the correction for the case where contention is real. `functions/_lib/idem_claim.js` guards invoke idempotency, where duplicate parallel calls are the normal case rather than a coincidence, and its opening comment records why it is not in KV:\n\n> KV get→fire→put races: parallel identical calls all miss, all fire.\n\nIt uses `INSERT OR IGNORE` on a D1 table instead, where the primary key does the atomic test-and-set that KV cannot. That is the rule generalised: **if two writers can plausibly arrive together, the lock goes in D1 or a Durable Object, not KV.** Cloudflare's own guidance says the same thing — \"KV is not ideal for applications where you need support for atomic operations or where values must be read and written in a single transaction.\"\n\n[[widget:2]]\n\n## The topology teams settle on: authority elsewhere, KV as the replicated read copy\n\nAsked how they ran a global read path, one operator described the shape that keeps recurring:\n\n> Cloudflare Workers KV has the simplest model, with a central-db that transparently and eventually only replicates read-only, hot-data specific to a DC but writes continue to incur heavy penalty\n\nTheir production system used DynamoDB in a single region as the source of truth, DynamoDB Streams pushing changes into Workers KV, and reads served from KV at the edge. Writes never touched KV directly. The reasons they gave were operations per second, cost and latency — and avoiding lock-in.\n\nThe generalised topology, and it is the one to copy:\n\n1. **Authority** — a store with transactions: D1, a Durable Object, Postgres behind Hyperdrive, DynamoDB. All writes land here and here only.\n2. **Propagation** — a change feed, a queue, or the write path itself pushes the new value into KV as a side effect. One writer per key, which is exactly what the reference recommends: *\"It is a common pattern to write data from a single process with Wrangler, Durable Objects, or the API. This avoids competing concurrent writes because of the single stream.\"*\n3. **Read** — every edge read hits KV. It is allowed to be a minute stale because the authority, not KV, is what anybody reconciles against.\n\nTwo field reports bracket the tradeoff. On the positive side, the author of an edge feature-flag system:\n\n> I mostly use KV for storing flags specific to each project (which gets replicated automatically). Everything else goes to D1 (replication isn't needed here).\n\nOn the negative side, the bind that pushes people into KV whether it fits or not:\n\n> You can use KV, with its trade-off of eventual consistency, or use something like FaunaDB or Firebase, but that means that the request has to wait for the request to the backing service.\n\nBoth are true at once. KV is the only storage on the platform that is already next to the Worker; everything else is a network hop. That is the whole reason people put things in it that do not belong there.\n\nAnd a measured case of KV in the cache role paying off: an operator repeatedly tripping D1's 5 million daily row-read limit put a KV layer in front and reported back a week later — *\"I implemented KV-layered caching\"* — with reads down more than 80% and back under the limit. That is KV doing the job it is for. See [D1 in this stack](/a/cloudflare-os-d1) for the read-accounting model that makes those limits bite.\n\n## Where each kind of state belongs\n\n| If the state is… | KV | [D1](/a/cloudflare-os-d1) | [R2](/a/cloudflare-os-r2) | Durable Object storage | Cache API |\n| --- | --- | --- | --- | --- | --- |\n| Read from everywhere, written rarely, seconds of staleness fine | **Use this** | Slower reads, and rows read are metered | Higher latency, cheaper per read | Single-location reads | Not durable |\n| Relational, queried by more than a key | No | **Use this** | No | Only if scoped to one object | No |\n| Large bytes: images, video, archives | No — 25 MiB ceiling | No | **Use this** — free egress, $0.015/GB-month | No | No |\n| Coordination, counters, anything atomic | **Never** | Workable via `INSERT OR IGNORE` | No | **Use this** — single-threaded, transactional | No |\n| Per-request ephemeral output, regenerable | Wasteful — pays a write | No | No | No | **Use this** — free, per-location, non-durable |\n| The source of truth for money or identity | **Never** | Yes | Yes for blobs | Yes | Never |\n| Sixty-second global propagation is unacceptable | No | Yes | Yes | Yes | Yes, per location |\n\nThe Cache API row deserves its own sentence because it is the cheapest option on the table and the most often skipped: `caches.default` costs nothing per operation, is not durable, and is scoped to one Cloudflare location. Put it in front of KV, as above, and it is what bounds the write bill.\n\n## Symptom, cause, fix\n\n| Symptom | Cause | Fix |\n| --- | --- | --- |\n| A value written a second ago reads as the old one, but only for some users | The reading location has a cached copy, or a cached negative lookup, from before the write | Wait out the 60-second window, or lower `cacheTtl`, or read from the authority instead of KV on the path that needs freshness |\n| A key you just created reads as `null` in one region | Negative lookups are cached the same as values | Do not pre-read a key before writing it. If a probe is unavoidable, treat `null` as unknown, not absent |\n| `handler.get` throws a **414**, and the framework's `notFound()` never runs | Assembled key exceeded 512 bytes | Budget for the prefix, keep short keys verbatim, hash the overflow |\n| Writes silently stop landing on one key | 1 write per second per key, free and paid | Spread across discrete keys, or move that key to a Durable Object |\n| The bill is dominated by an operation nobody thought about | Writes are $5.00 / million against reads at $0.50 | Put the Cache API in front so writes are bounded by cache expiries, not by traffic |\n| Two processes both believe they hold the lock | `get()` then `put()` is not atomic; last write wins with no error | Move the lock to D1 `INSERT OR IGNORE` or a Durable Object |\n| Free plan stops accepting writes mid-afternoon | 1,000 writes/day, reset 00:00 UTC | Batch, throttle behind a cache, or move to the paid plan |\n| `expirationTtl: 30` rejected | Minimum is 60 seconds | Store the intended expiry inside the value and check it on read |\n\n## Measured on this account today\n\nFive measurements taken against the live namespace bound as `KV` in `wrangler.toml`. Account id and namespace ids are redacted below; substitute your own. The consistency probe wrote two obviously-named temporary keys, `tmp_consistency_probe_20260725` and `tmp_consistency_probe_b_20260725`, and both were deleted afterwards and verified gone (HTTP 404).\n\n**1. Namespaces on the account — 6.**\n\n```\nnpx wrangler kv namespace list\n```\n\n**2. Keys in the production namespace — 6,773, of which 6,568 are page snapshots.**\n\n```\nnpx wrangler kv key list --namespace-id <NAMESPACE_ID> --remote > keys.json\npython3 -c \"import json;d=json.load(open('keys.json'));print(len(d))\"\n```\n\nPrefix breakdown: `lastgood:` 6,568, `sync:` 35, `trail:` 33, `share_use:` 25, `mcp_oauth:` 18, `idem:` 6, then singletons. The longest key name measured **110 bytes** against the 512-byte limit.\n\n**3. Stored bytes — 164.70 MB across the 1,041 snapshot keys that carry size metadata.** `refreshLastGood()` writes `{ts, bytes, ct}` as KV metadata, so `list()` returns the size of every value it wrote without reading any of them.\n\n```\npython3 -c \"import json;d=json.load(open('keys.json'));b=[k['metadata']['bytes'] for k in d if k.get('metadata',{}).get('bytes')];print(len(b),sum(b),max(b))\"\n```\n\nMedian value 155,154 bytes, largest 2,140,072 bytes — 8% of the 25 MiB ceiling. Extrapolating that mean across all 6,568 snapshot keys puts the namespace at roughly **1.01 GB**, which is the 1 GB included allowance almost exactly; the overage at $0.50/GB-month is about half a cent. Treat the extrapolation as an estimate: the 5,527 older keys without metadata were not measured.\n\n**4. Seven days of real operations — 899,100 reads, 85,620 writes, 740 deletes, 160 lists.** From Cloudflare's GraphQL analytics API, 2026-07-19 to 2026-07-26.\n\n```\nPOST https://api.cloudflare.com/client/v4/graphql\n{\"query\":\"query { viewer { accounts(filter: {accountTag: \\\"<ACCOUNT_ID>\\\"}) {\n  kvOperationsAdaptiveGroups(limit: 100, filter: {\n    datetime_geq: \\\"2026-07-19T00:00:00Z\\\", datetime_leq: \\\"2026-07-26T00:00:00Z\\\",\n    namespaceId: \\\"<NAMESPACE_ID>\\\"}) { sum { requests } dimensions { actionType } } } } }\"}\n```\n\nThe arithmetic that matters:\n\n| Operation | 7-day count | Rate | Gross at list rates |\n| --- | --- | --- | --- |\n| Read | 899,100 | $0.50 / million | $0.4496 |\n| Write | 85,620 | $5.00 / million | $0.4281 |\n| Delete | 740 | $5.00 / million | $0.0037 |\n| List | 160 | $5.00 / million | $0.0008 |\n| **Total** | **985,620** | — | **$0.8822** |\n\nWrites are **8.7% of the operations and 48.5% of the gross cost**. Extrapolated to a month: 3.85 million reads against the 10 million included, and 366,943 writes against the 1 million included — so the actual invoice line is **$0.00**. The write allowance is the binding constraint, with 2.7× headroom: 12,231 writes a day today, 33,333 a day before the meter starts.\n\n[[widget:3]]\n\n**5. Write, then read, and time the gap — visible in 0.21 s and 0.30 s across two trials.**\n\n```\n# seed the negative lookup at the reading location\nfor i in $(seq 1 6); do curl -s -o /dev/null -w \"%{http_code} \" \\\n  \"https://miscsubjects.com/api/kv?key=tmp_consistency_probe_b_20260725\" \\\n  -H \"x-terminal-key: $TERMINAL_KEY\"; sleep 2; done       # 404 404 404 404 404 404\n\nnpx wrangler kv key put tmp_consistency_probe_b_20260725 probe-b \\\n  --namespace-id <NAMESPACE_ID> --remote                   # real 1.14s\n\n# poll every 0.5s until it appears\nfor i in $(seq 1 200); do code=$(curl -s -o /tmp/pb.txt -w \"%{http_code}\" \\\n  \"https://miscsubjects.com/api/kv?key=tmp_consistency_probe_b_20260725\" \\\n  -H \"x-terminal-key: $TERMINAL_KEY\"); \\\n  [ \"$code\" = \"200\" ] && break; sleep 0.5; done            # t+0.21s VISIBLE probe-b\n```\n\nBoth trials converged in well under a second, including the trial that deliberately seeded six cached negative lookups first. **This does not demonstrate read-after-write consistency and must not be read as one.** It measures one reading location, close to the writer, twice. The documented window is a worst case, and the reference says explicitly that even same-location visibility \"is not guaranteed\". A system that happens to converge fast today is not a system you can design against.\n\nTen repeat reads of the same key through the deployed Worker, end to end over HTTPS from a laptop: minimum 136 ms, median 202 ms, maximum 260 ms. Almost all of that is network round trip, not KV — Cloudflare's own instrumentation puts the 90th percentile of KV Worker invocations \"in less than 12 ms\", and reports that the hottest 0.03% of keys, which serve over 40% of global KV requests, \"resolve in under a millisecond\".\n\nAn independent benchmark run from Cloudflare's Washington DC location (150 samples per metric, KV through the binding against Upstash Redis over HTTPS, same Worker, same request) put KV's hot read at **2.6 ms p50** — twice as fast as the competitor — and KV's single write at **171.8 ms p50**, twenty-eight times slower. That single pair of numbers is the whole argument of this page in measured form: KV's reads are the best on the platform and its writes are the worst.\n\nFor where KV sits among the other bindings in this stack, see [the Cloudflare stack index](/a/cloudflare-os), [Workers as the runtime](/a/cloudflare-os-workers) and [D1 as the relational store](/a/cloudflare-os-d1).\n\n## The next read-only inventory still shows snapshots dominating the namespace\n\nWrangler 4.103.0 listed the production namespace at `2026-07-26T05:45:59.424Z`. Listing reads namespace metadata; it did not write, delete or fetch any value.\n\n| Fresh check | Result |\n| --- | ---: |\n| Namespaces on the account | 6 |\n| Keys in the production namespace | 6,767 |\n| `lastgood:` snapshot keys | 6,568 |\n| Longest key name | 110 bytes of the 512-byte limit |\n| Keys carrying byte-count metadata | 1,046 |\n| Bytes recorded by that metadata | 175,859,336 |\n| Largest recorded value | 2,140,072 bytes |\n\nLargest prefix groups: `lastgood:` 6,568 · `(singleton)` 54 · `sync:` 35 · `trail:` 33 · `share_use:` 25 · `mcp_oauth:` 18. The inventory reproduces the architectural claim directly: 97% of all keys are regenerable `lastgood:` page snapshots, not transactional state.\n\nRun the same inventory without exposing the namespace id in a transcript:\n\n```bash\nnpx wrangler kv namespace list\nnpx wrangler kv key list --namespace-id <NAMESPACE_ID> --remote > keys.json\npython3 -c \"import json; d=json.load(open('keys.json')); print(len(d), max(len(k['name'].encode()) for k in d))\"\n```\n\nThe first number is the key count. The second is the longest key name in bytes.","claims":[{"id":"c12","text":"An operator uses KV for replicated project flags while keeping everything else in D1.","tier":"anecdotal","effective_weight":0.3,"source_ids":["p6"]},{"id":"c13","text":"Another operator describes the latency tradeoff between eventual KV reads and waiting for an external authoritative database.","tier":"anecdotal","effective_weight":0.3,"source_ids":["p4"]},{"id":"c14","text":"A cache-fronted share-link design bounds each key to at most 24 cache misses per day with a one-hour max-age.","tier":"anecdotal","effective_weight":0.3,"source_ids":["p5"]},{"id":"c1","text":"Workers KV is a globally cached key-value read layer with eventual propagation, not a transactional distributed database.","tier":"system","effective_weight":0.1,"source_ids":["p1","s1"]},{"id":"c2","text":"A recently read value or missing key can remain stale in another location for up to 60 seconds or the configured cacheTtl.","tier":"fact","effective_weight":0.1,"source_ids":["s1","s2"]},{"id":"c3","text":"Concurrent writes to one KV key can overwrite one another without an atomic compare-and-set.","tier":"fact","effective_weight":0.1,"source_ids":["r4","s3"]},{"id":"c4","text":"KV writes cost $5 per million after the allowance while reads cost $0.50 per million.","tier":"fact","effective_weight":0.1,"source_ids":["p2","s5"]},{"id":"c5","text":"A missing-key read is billable even though it returns null or 404.","tier":"fact","effective_weight":0.1,"source_ids":["s5"]},{"id":"c6","text":"The 2021 operator price comparison still matches the July 2026 KV read and write rates.","tier":"calculation","effective_weight":0.1,"source_ids":["p2","s5"]},{"id":"c7","text":"Putting caches.default before KV bounds refresh writes by cache expiry rather than request traffic.","tier":"system","effective_weight":0.1,"source_ids":["p5","s6"]},{"id":"c8","text":"KV limits keys to 512 bytes, values to 25 MiB, metadata to 1024 bytes and same-key writes to one per second.","tier":"fact","effective_weight":0.1,"source_ids":["s4"]},{"id":"c9","text":"A merged vinext repair preserves short cache keys and hashes the overflow after reserving prefix space to avoid KV 414 failures.","tier":"repository","effective_weight":0.1,"source_ids":["s9"]},{"id":"c10","text":"KV get then put cannot implement a correct contended lock; D1 INSERT OR IGNORE or a Durable Object can.","tier":"system","effective_weight":0.1,"source_ids":["r4","s3"]},{"id":"c11","text":"The durable topology is transactional authority first, one propagation stream second and KV as the replicated read copy.","tier":"system","effective_weight":0.1,"source_ids":["p3","p6","s7"]},{"id":"c15","text":"The seven-day account measurement recorded 899,100 reads, 85,620 writes, 740 deletes and 160 lists.","tier":"measurement","effective_weight":0.1,"source_ids":["r2"]},{"id":"c16","text":"In the measured week, writes were 8.7% of operations but 48.5% of gross list-rate cost.","tier":"calculation","effective_weight":0.1,"source_ids":["r2","s5"]},{"id":"c17","text":"Two same-area visibility trials converged in 0.21 and 0.30 seconds, but neither establishes read-after-write consistency.","tier":"measurement","effective_weight":0.1,"source_ids":["r3","s1"]},{"id":"c18","text":"The independent IAD benchmark used 150 samples per metric and measured KV hot reads at 2.6 ms p50 and writes at 171.8 ms p50.","tier":"independent","effective_weight":0.1,"source_ids":["s11"]},{"id":"c19","text":"Cloudflare reports that its hottest 0.03% of keys serve over 40% of global KV requests and resolve in under one millisecond.","tier":"publisher_claim","effective_weight":0.1,"source_ids":["s8"]},{"id":"c20","text":"The fresh namespace list found 6,767 keys, including 6,568 regenerable lastgood snapshots.","tier":"measurement","effective_weight":0.1,"source_ids":["r1"]},{"id":"c21","text":"The longest live key name is 110 bytes, below the 512-byte hard limit.","tier":"measurement","effective_weight":0.1,"source_ids":["r1","s4"]},{"id":"c22","text":"Fresh list metadata covers 1,046 values totaling 175,859,336 recorded bytes; the largest is 2,140,072 bytes.","tier":"measurement","effective_weight":0.1,"source_ids":["r5"]},{"id":"c23","text":"Cloudflare's own documentation repository records explicit clarifications to the KV consistency contract.","tier":"repository","effective_weight":0.1,"source_ids":["s10"]}],"sources":[{"id":"p1","type":"hn","url":"https://news.ycombinator.com/item?id=48672342","title":"OAuth for all","summary":"The Workers tech lead telling a user who had adopted KV as a datastore that this is a misuse: writes are too slow and eventual consistency is wrong for frequently-changing state, and to use Durable Objects SQLite or Hyperdrive instead. Negative on the common KV-as-database pattern.","quote":"KV is not a distributed database and is really not intended as a database alternative at all. It's more meant for distributing bits of config globally. Cost aside, writes are way too slow for database-ish use","claim_ids":["c1"],"hash":"c4bf1f054fc16452"},{"id":"p2","type":"hn","url":"https://news.ycombinator.com/item?id=28703233","title":"A bit of math around Cloudflare's R2 pricing model","summary":"Cost and consistency breakdown: KV at $5/million writes and $0.50/million reads (pricier per read than S3), plus no read-after-write guarantee. Contrasts with Durable Objects storage at $1/million 4KB writes but with the DO runtime cost stacked on top. Negative.","quote":"Workers KV is also eventually-consistent with no guarantee of read-after-write, which is a pretty big limitation compared to alternatives (S3 even has immediately-consistent list operations now after write).","claim_ids":["c4","c6"],"hash":"b0ae1f09af39d9b5"},{"id":"p3","type":"hn","url":"https://news.ycombinator.com/item?id=22644115","title":"Launch HN: Fly.io (YC W20) – Deploy app servers close to your users","summary":"Describes their actual production topology: DynamoDB as single-region source of truth, DynamoDB Streams pushing into Workers KV, reads served from KV at the edge. They deliberately keep writes off KV because of ops-per-second, cost and latency penalties, and to avoid lock-in. Mixed, leaning negative on KV writes.","quote":"Cloudflare Workers KV has the simplest model, with a central-db that transparently and eventually only replicates read-only, hot-data specific to a DC but writes continue to incur heavy penalty","claim_ids":["c11"],"hash":"7f95c19d457b58f3"},{"id":"p4","type":"hn","url":"https://news.ycombinator.com/item?id=28581040","title":"Reality Check for Cloudflare Wasm Workers and Rust","summary":"Frames the practical bind: Workers have no durable disk and no region control, so you either accept KV's eventual consistency or pay a round trip to an external database. Also finds Workers Unbound pricing opaque. Negative.","quote":"You can use KV, with its trade-off of eventual consistency, or use something like FaunaDB or Firebase, but that means that the request has to wait for the request to the backing service.","claim_ids":["c13"],"hash":"78ad489e86c3ad90"},{"id":"p5","type":"hn","url":"https://news.ycombinator.com/item?id=47917107","title":"Durable Object alarm loop: $34k in 8 days, zero users, no platform warning","summary":"Describes a running share-link backend that uses KV plus the edge cache with a sliding TTL specifically to bound KV write cost, instead of DO + alarms. Accepts loss of strong consistency in exchange for writes that cannot run away. Positive pattern, written in response to a runaway-cost postmortem.","quote":"The key property is that caches.default with Cache-Control: max-age=3600 becomes a natural throttle — at most 24 cache misses per day per key, so KV writes are bounded by (keys × 24) regardless of traffic.","claim_ids":["c14","c7"],"hash":"65e7428e4eb02639"},{"id":"p6","type":"hn","url":"https://news.ycombinator.com/item?id=42531229","title":"Show HN: An edge first feature flag implementation on Cloudflare","summary":"Author of an edge feature-flag system: flags live in KV for its built-in geo replication, configuration lives in D1. Elsewhere in the thread he notes KV still has propagation delay on updates. Positive use of KV for exactly the flags/config case.","quote":"I mostly use KV for storing flags specific to each project (which gets replicated automatically). Everything else goes to D1 (replication isn't needed here).","claim_ids":["c11","c12"],"hash":"e3d074248824ff45"},{"id":"r1","type":"runtime_receipt","url":"https://miscsubjects.com/api/articles/cloudflare-os-kv","title":"Fresh first-party KV namespace inventory","summary":"Wrangler key-list inventory counted keys, prefixes, name bytes and metadata without reading values or mutating the namespace.","quote":"Keys in the production namespace | 6,767","claim_ids":["c20","c21"],"hash":"550da79f541bf7d9"},{"id":"r2","type":"runtime_receipt","url":"https://miscsubjects.com/api/articles/cloudflare-os-kv","title":"First-party seven-day KV operations receipt","summary":"Cloudflare GraphQL kvOperationsAdaptiveGroups measurement for 2026-07-19 through 2026-07-26, with the query published.","quote":"Seven days of real operations — 899,100 reads, 85,620 writes, 740 deletes, 160 lists.","claim_ids":["c15","c16"],"hash":"26895d8e05017d4f"},{"id":"r3","type":"runtime_receipt","url":"https://miscsubjects.com/api/articles/cloudflare-os-kv","title":"First-party KV visibility probe","summary":"Two temporary-key trials, one after six cached 404s; both keys deleted and verified gone. Explicitly not evidence of a consistency guarantee.","quote":"visible in 0.21 s and 0.30 s across two trials.","claim_ids":["c17"],"hash":"bfcd1eac2af2e6fd"},{"id":"r4","type":"runtime_receipt","url":"https://miscsubjects.com/api/articles/cloudflare-os-kv","title":"First-party KV-lock code audit","summary":"Local code inspection contrasts advisory KV leases with D1 INSERT OR IGNORE for contended idempotency claims.","quote":"KV get→fire→put races: parallel identical calls all miss, all fire.","claim_ids":["c10","c3"],"hash":"ceb9958bc04bb709"},{"id":"r5","type":"runtime_receipt","url":"https://miscsubjects.com/api/articles/cloudflare-os-kv","title":"First-party snapshot metadata inventory","summary":"Fresh KV list metadata counted snapshot values, recorded bytes and largest recorded value without fetching any stored body.","quote":"Bytes recorded by that metadata | 175,859,336","claim_ids":["c22"],"hash":"d9244be77cf814f5"},{"id":"s1","type":"specification","url":"https://developers.cloudflare.com/kv/concepts/how-kv-works/","title":"How Workers KV works","summary":"Normative consistency model: central storage, regional caches, stale values and cached misses.","quote":"Negative lookups indicating that the key does not exist are also cached, so the same delay exists noticing a value is created as when a value is changed.","claim_ids":["c1","c17","c2"],"hash":"25a663bdc376c779"},{"id":"s2","type":"specification","url":"https://developers.cloudflare.com/kv/api/read-key-value-pairs/","title":"Read key-value pairs","summary":"Workers Binding API for reads, metadata and cacheTtl, including the stale-read warning.","quote":"get() and getWithMetadata() methods may return stale values.","claim_ids":["c2"],"hash":"bb2f0147961457bb"},{"id":"s3","type":"specification","url":"https://developers.cloudflare.com/kv/api/write-key-value-pairs/","title":"Write key-value pairs","summary":"Workers Binding API for put, metadata and expiry, including the concurrent-write warning.","quote":"Due to the eventually consistent nature of KV, concurrent writes to the same key can end up overwriting one another.","claim_ids":["c10","c3"],"hash":"c43a365f1fdff1dc"},{"id":"s4","type":"publisher_documentation","url":"https://developers.cloudflare.com/kv/platform/limits/","title":"Workers KV limits","summary":"Hard per-key, per-value, metadata, namespace and invocation limits.","quote":"Writes to same key","claim_ids":["c21","c8"],"hash":"124486035d659fc7"},{"id":"s5","type":"publisher_documentation","url":"https://developers.cloudflare.com/kv/platform/pricing/","title":"Workers KV pricing","summary":"Current read, write, delete, list and stored-data allowances and overage rates.","quote":"All operations incur charges, including fetches for non-existent keys that return a null (Workers API) or HTTP 404 (REST API).","claim_ids":["c16","c4","c5","c6"],"hash":"cf304f6de8d11281"},{"id":"s6","type":"publisher_documentation","url":"https://developers.cloudflare.com/workers/runtime-apis/cache/","title":"Workers Cache API","summary":"Free per-location cache primitive used to absorb repeat reads before KV.","quote":"The Cache API is a programmatic interface for reading from and writing to Cloudflare's cache from inside a Worker.","claim_ids":["c7"],"hash":"d28a8dcfd8fa323d"},{"id":"s7","type":"publisher_documentation","url":"https://developers.cloudflare.com/workers/platform/storage-options/","title":"Workers storage options","summary":"Official comparison surface for KV, D1, Durable Objects, R2 and external databases.","quote":"This guide describes the storage & database products available as part of Cloudflare Workers, including recommended use-cases and best practices.","claim_ids":["c11"],"hash":"747ec212aaf55769"},{"id":"s8","type":"publisher_documentation","url":"https://blog.cloudflare.com/faster-workers-kv/","title":"Cloudflare's Workers KV latency measurements","summary":"Vendor measurement of the tiered cache architecture and hot-key latency distribution.","quote":"KV reads for these keys, which represent over 40% of Workers KV requests globally, resolve in under a millisecond.","claim_ids":["c19"],"hash":"e2619fd67cada3f4"},{"id":"s9","type":"repository","url":"https://github.com/cloudflare/vinext/pull/2606","title":"vinext fix for KV's 512-byte cache-key limit","summary":"Merged code repair: retain short keys and hash only overflow after reserving prefix space.","quote":"When the assembled key exceeds Cloudflare KV's 512-byte key limit, `handler.get` throws a 414 **before** the wrapped function runs","claim_ids":["c9"],"hash":"56f18f5cf6a2ed0c"},{"id":"s10","type":"repository","url":"https://github.com/cloudflare/cloudflare-docs/pull/2678","title":"Cloudflare documentation clarification for KV consistency","summary":"Public documentation change where stale reads, concurrent overwrites and cache behavior are visible in the source history.","quote":"Add KV clarifications","claim_ids":["c23"],"hash":"b41d1481d70c92ba"},{"id":"s11","type":"independent_measurement","url":"https://upstash.com/blog/upstash-redis-vs-cloudflare-kv","title":"Upstash Redis versus Cloudflare KV benchmark","summary":"Competitor-authored but reproducible harness: 150 samples per metric from one Worker and one location, with KV binding and Upstash HTTPS held side by side.","quote":"I deployed a Cloudflare Worker that calls KV through the binding and Upstash through the official @upstash/redis/cloudflare client (HTTPS REST), then ran four scenarios: 5 runs × 30 samples = 150 samples per metric, all served from Cloudflare's Washington DC data center (IAD).","claim_ids":["c18"],"hash":"450ab2c6b14a727e"}],"voxels":{"slug":"cloudflare-os-kv","counts":{"divs":0,"voxels":23,"sources":22,"edges":35},"note":"slim bundle — full voxels at /api/articles/cloudflare-os-kv/voxels"},"constitution":{"url":"https://miscsubjects.com/api/articles/constitution"},"provenance":[{"action":"sources","model":"Opus 5 (Claude Code)","ts":"2026-07-26T03:59:23.079Z","hash":"138767e809840a40","tokens_in":0,"tokens_out":0},{"action":"claim","model":"Opus 5 (Claude Code)","ts":"2026-07-26T03:59:23.413Z","hash":"789617b72b109c23","tokens_in":0,"tokens_out":0},{"action":"claim","model":"Opus 5 (Claude Code)","ts":"2026-07-26T03:59:23.803Z","hash":"f6685c2c1ba9b62c","tokens_in":0,"tokens_out":0},{"action":"claim","model":"Opus 5 (Claude Code)","ts":"2026-07-26T03:59:24.251Z","hash":"0f77a8f6c181f456","tokens_in":0,"tokens_out":0}],"contributions":[{"id":"k1","ts":"2026-07-26T03:59:23.079Z","model":"Opus 5 (Claude Code)","role":"source_hunt","action":"sources","rationale":"","hash":"0d0569e9f60e50e2d3fd955dfd6a305802972a68b59ada4645bcf25dd61e4d70"},{"id":"k2","ts":"2026-07-26T03:59:23.413Z","model":"Opus 5 (Claude Code)","role":"claim_post","action":"claim","rationale":"","hash":"9e712cef7d3f18681696a7bad0ac909ecb4f74dae61258d703c38fa88113cfa6"},{"id":"k3","ts":"2026-07-26T03:59:23.803Z","model":"Opus 5 (Claude Code)","role":"claim_post","action":"claim","rationale":"","hash":"4168bb4b033190d4a97add35969b03753cfaa150daa77e3ede174fedff44e8f2"},{"id":"k4","ts":"2026-07-26T03:59:24.251Z","model":"Opus 5 (Claude Code)","role":"claim_post","action":"claim","rationale":"","hash":"acd369c4d3860e70e20634681295541a8ac1da8fbbb5fa5255b853a9a91e3348"}],"topology":null,"slim":true,"ledger_totals":{"claims":23,"sources":22,"exported_claims":23,"exported_sources":22},"question_graph":{"slug":"cloudflare-os-kv","questions":[],"evidence":[],"edges":[],"counts":{"questions":0,"evidence":0,"edges":0}},"verification":{"provenance":{"valid":true,"entries":4,"head":"0f77a8f6c181f45608310bd33683539042cfd0d7c29fb77055b6f35c1193b21d"},"sources":{"valid":false,"broken_at":0}},"counts":{"claims":23,"sources":22,"provenance":4,"contributions":4,"questions":0,"evidence_ingests":0,"voxel_edges":35},"transport":"Open every URL in this bundle with your browser or web / URL-fetch tool. Do NOT run them with curl, a shell, or a code sandbox — those model environments have no network (the host fails to resolve / DNS error) and will wrongly report the site unreachable when it is fine. Opening the link IS the call.","llm_manifest":{"version":"1","site":"https://miscsubjects.com","purpose":"Peptide evidence articles with hash-chained source ledgers, tiered claims, and a question graph. LLMs should READ bundles/URLs and WRITE back via ingest — never invent doses.","read":{"human_page":"https://miscsubjects.com/a/cloudflare-os-kv","bundle_json":"https://miscsubjects.com/api/articles/cloudflare-os-kv/bundle","bundle_markdown":"https://miscsubjects.com/api/articles/cloudflare-os-kv/bundle?format=markdown","topology":"https://miscsubjects.com/api/articles/cloudflare-os-kv/topology","question_graph":"https://miscsubjects.com/api/articles/cloudflare-os-kv/question-graph","sources":"https://miscsubjects.com/api/articles/cloudflare-os-kv/sources","provenance":"https://miscsubjects.com/api/articles/cloudflare-os-kv/provenance","contributions":"https://miscsubjects.com/api/articles/cloudflare-os-kv/contributions","graph_topology":"https://miscsubjects.com/api/articles/cloudflare-os-kv/graph-topology?question={question}","voxels":"https://miscsubjects.com/api/articles/cloudflare-os-kv/voxels","constitution":"https://miscsubjects.com/api/articles/constitution","ontology":"https://miscsubjects.com/api/articles/ontology","system_map":"https://miscsubjects.com/api/articles/system-map","system_map_markdown":"https://miscsubjects.com/api/articles/system-map?format=markdown","health":"https://miscsubjects.com/api/articles/cloudflare-os-kv/health","repair":"POST https://miscsubjects.com/api/protocol/repair","list_articles":"https://miscsubjects.com/api/articles","graph_canvas":"https://miscsubjects.com/graph.html?slugs=cloudflare-os-kv","graph_yield":"https://miscsubjects.com/api/graph?slugs=cloudflare-os-kv&layer=yield","obsidian_vault":"https://miscsubjects.com/api/articles/obsidian-vault?slugs=cloudflare-os-kv","graph_query":"https://miscsubjects.com/api/v1/query?from=cloudflare-os-kv&kind=claim&where=tier=human"},"ask":{"description":"Answer only from topology; creates a question_node with gaps.","api":"POST https://miscsubjects.com/api/protocol/ask","body":{"slug":"{slug}","question":"string"},"imessage":"cloudflare-os-kv|your question","router_tag":"[ARTICLE_ASK]cloudflare-os-kv|question[/ARTICLE_ASK]","auth":"x-terminal-key header for API; iMessage/WhatsApp via miscsubjects build"},"ingest":{"description":"Parse pasted evidence → source ledger + claims + evidence_ingest node.","api":"POST https://miscsubjects.com/api/protocol/ingest","body":{"slug":"{slug}","evidence":"paste text","question_node_id":"optional qn_..."},"imessage":"ingest cloudflare-os-kv|q:{node_id}|paste evidence","router_tag":"[ARTICLE_INGEST]cloudflare-os-kv|evidence[/ARTICLE_INGEST]","tiers":["human","preclinical","anecdotal","mechanistic","speculative"]},"claim":{"description":"Prompt-injection style POST — one claim voxel with who_claims + posted_by provenance.","api":"POST https://miscsubjects.com/api/protocol/claim","body":{"slug":"{slug}","text":"one assertion","tier":"human|preclinical|anecdotal|mechanistic|speculative","who_claims":"study author, platform, or model id","source_ids":"optional [s1]"},"imessage":"claim cloudflare-os-kv|tier|assertion — who claims it?","router_tag":"[ARTICLE_CLAIM]cloudflare-os-kv|tier|assertion[/ARTICLE_CLAIM]","slots":["what_it_is","who_claims_what","what_is_known","what_is_unknown","mechanism","limitations","disclaimer"]},"tiers":{"human":0.8,"preclinical":0.5,"anecdotal":0.3,"mechanistic":0.3,"speculative":0.1},"invariants":["Self-explaining — every API JSON has _self; every paste widget has §SELF; root index at /api/articles/system-map","Append-only — revisions preserved at ?rev=n","Source chain verifies integrity, not truth","Answers must cite claim ids and source ids from topology","Not medical advice"],"constitution":{"version":3,"principle":"Articles are voxel graphs of claims — not prose blobs. Every assertion is a claim atom with tier, weight, source_ids, and posted_by provenance.","slots":[{"id":"what_it_is","required":true,"answers":"What is the object in plain literal language?"},{"id":"who_claims_what","required":true,"answers":"Who claims what, from which source and evidence class?"},{"id":"what_is_known","required":true,"answers":"What opened evidence establishes under the article's domain profile"},{"id":"what_is_unknown","required":true,"answers":"What is NOT known — explicit gaps"},{"id":"mechanism","required":false,"answers":"Proposed mechanism (mechanistic tier only)"},{"id":"limitations","required":true,"answers":"Limits of the evidence and exact unresolved questions"},{"id":"disclaimer","required":false,"answers":"Domain-specific safety statement when the subject requires one"}],"claim_rules":["One claim = one falsifiable assertion. No compound claims.","Every claim must declare tier: human|preclinical|anecdotal|mechanistic|speculative|system.","system tier = architecture/design axioms (not biological mechanism). Use for protocol self-definition.","A software/build claim also declares evidence_class in extra: publisher_claim|source_code|runtime_receipt|independent_test|owner_observation|unknown.","Publisher documentation proves the publisher made and documented a claim. It is not independent runtime proof.","Source code proves an implementation exists. A successful receipt proves one invocation. Neither proves general reliability or field superiority.","Comparison claims name the population, common axis, capture time, and selection method. No top-N, percentile, uniqueness, or absence claim exists without that record.","Sourced claims must cite source_ids from the hash-chained ledger.","Unsourced claims must set source_status: unsourced and why_material.","posted_by is mandatory on every new claim (model id, human, or channel).","No medical advice, no doses, no 'you should take'.","Bad information is retracted (status:retracted), never deleted — retraction event stays on ledger.","Adversary challenges link via challenges[] / challenged_by[] — target may be downweighted.","Leaked secrets are scrubbed to [REDACTED:secret-leak] with scrub_events tombstone — honest audit trail."],"source_rules":["Every source is a voxel edge: type, url, exact quote, summary, found_by, accessed_at.","Sources hash-chain — prev/hash on append.","Anecdotal sources must name platform (reddit|x|youtube|imessage|user_entry).","Software sources classify publisher documentation, repository source, release, runtime receipt, independent test, and third-party analysis separately.","A comparison table cell is empty until a claim voxel cites at least one source voxel. Model prose alone is not evidence."],"writing_rules":["Literal nouns and verbs. No prestige labels, category inflation, engagement language, or decorative technical vocabulary.","Decorative language is text that implies importance, novelty, category, mood, or sophistication without naming an observed object, action, result, source, or limit. Delete it.","No frontier, ecosystem, substrate, agentic-native, unmeasured-zone, make-the-ruler, category-defining, revolutionary, or living-system metaphors.","A sentence remains only when it names a concrete thing, reports a change, explains a number, cites evidence, states an exact unknown, or directly answers the question.","Technical nouns are allowed only when literal. Define the first use by what the named code or data object stores or does.","State the observed object before naming a category for it.","Keep the evidentiary boundary beside the exact claim it limits.","Unknown means unknown. Missing evidence does not become absence."],"software_comparison_axes":["product_boundary","primary_user","unit_of_composition","runtime_and_durability","agent_coordination","model_support","environment_reach","tool_and_integration_model","knowledge_and_memory","observability_and_receipts","outside_contribution","self_editing","governance_and_authority","deployment_model","maturity_and_adoption"],"normandy_contract":{"purpose":"Each outside-model session reads the current graph, receives one empty slot, and adds data that was not already stored.","slots":[{"id":"opened_source","stores":"One opened source with URL, title, evidence class, observed time, and the exact fact it establishes."},{"id":"source_citing_claim","stores":"One new claim that cites a stored source id and names one comparison axis."},{"id":"overlap","stores":"One evidenced capability both systems have."},{"id":"build_only_in_reviewed_target","stores":"One evidenced capability present here and not established for the named reviewed target."},{"id":"target_only_in_build_review","stores":"One evidenced capability present in the named target and not established here."},{"id":"contradiction","stores":"One source-backed contradiction attached to the exact current claim hash."},{"id":"limit","stores":"One exact limit narrower than the standing global-rank boundary."},{"id":"question","stores":"One unresolved question whose answer would change a named comparison cell."},{"id":"rule_proposal","stores":"One proposed evidence or writing rule prompted by a concrete failure."},{"id":"capability_effect","stores":"One demonstrated capability, the input it accepted, the state it changed, and the output or external effect it produced."},{"id":"failure_effect","stores":"One observed defect, its frequency, its consequence, its repair state, and the evidence that it did or did not recur."},{"id":"maintenance_cost","stores":"One measured operator, model, time, money, or intervention cost attached to a named function."},{"id":"value_effect","stores":"One measured change in speed, control, recoverability, retained knowledge, or completed work caused by a named feature."}],"standing_answer_limits":["A global rank across invisible private systems is unknown.","Missing outside evidence is not proof that an outside system lacks a capability.","A successful receipt proves one run, not general reliability.","Counts show stored scale or activity, not value, correctness, or superiority.","Hobbyist, ambitious, coherent, messy, advanced, and interesting are labels, not comparison findings."],"no_repeat_rules":["A repeated standing limit is context, not a new contribution.","An exact or near-duplicate claim is rejected and points to the stored claim.","A duplicate source does not complete an assignment.","A response completes only after at least one new graph object lands.","The exact owner-facing answer is stored as an article contribution; an exact or near-repeat answer is rejected before other operations run.","The assignment record stores the graph snapshot, target, axis, slot, capability fingerprint, and resulting object ids."],"assignment":"GET /api/normandy?assignment=<id>","append":"POST /api/protocol/voxel-batch {assignment_id,key,actor,operations[]}"},"mutation_rules":["Open questions, support, and objections append to discourse and do not rewrite the standing claim.","Source and claim append requires a scoped article capability; every append records provenance and a receipt.","Existing text edits use the current voxel hash. A stale hash writes nothing.","Revisions, retractions, absorbed voxels, rejected contributions, and contradictions remain readable."],"ontology_rules":["Peptide articles (bpc-157, tb-500) are tree roots.","Condition articles (bpc-157-glp1-gut-damage) branch from peptides.","Stack articles (wolverine-stack-glp1) compose peptides — never duplicate peptide mechanism prose.","If an article has no parent embeds and is not a root peptide → sprawl candidate.","Misstep = duplicate scope with another slug; merge or reparent via embeds."],"post_protocol":{"claim":"POST /api/protocol/claim","source":"POST /api/protocol/sources","ingest":"POST /api/protocol/ingest","webhook":"POST /api/articles/<slug>/webhook {kind:claim|source}","imessage_claim":"claim {slug}|{tier}|your assertion — who claims it, source?","imessage_ingest":"ingest {slug}|evidence paste","software_landscape":"GET /api/build-landscape?next=1&lane=field|build|opposition|synthesis","queue_population":"POST /api/build-landscape {action:queue_targets, cohort, query, sort, captured_at, source_url, targets[]}"}},"this_article":{"slug":"cloudflare-os-kv","url":"https://miscsubjects.com/a/cloudflare-os-kv","bundle_url":"https://miscsubjects.com/api/articles/cloudflare-os-kv/bundle?format=markdown"},"voxel_procedure":{"what":"Every article has a human side (/a/cloudflare-os-kv) and a machine side (this endpoint). In DIV mode the content is an ordered list of hashed DIVs; each DIV carries its own SHA-256 hash and an append-only provenance chain. Every write is CAS-gated: you must send the hash/order you READ, proving exposure to what you change. Every successful write returns a clickable human permalink.","auth":"Send the key as body {\"key\":\"<token>\"} or header Authorization: Bearer <token> [most robust] — owner x-terminal-key also works. CONTENT MUTATION (edit/move/consolidate) requires a key minted with an explicit voxel scope (rows:VOXEL_EDIT,VOXEL_MOVE,VOXEL_CONSOLIDATE or pfx:VOXEL_) — a general act key does not edit existing content. Filing a challenge or attestation needs no key at all.","web_runtime":"WEB CHATGPT: open https://miscsubjects.com/api/model-lane first. Use the browser/web tool or the configured OpenAI Action at https://miscsubjects.com/api/openai/actions.json. Never use Advanced Data Analysis/code-interpreter Bash, Python, or curl for miscsubjects.com. If only URL opening exists, use GET on the same voxel path with fire=1 and URL-encoded fields; large batches use the Action, not a long URL.","divide":"POST https://miscsubjects.com/api/protocol/voxel-divide {\"slug\":\"cloudflare-os-kv\",\"key\":\"<token>\"} — atomize the body into DIVs (verbatim, roundtrip-checked, idempotent). act scope suffices; content is unchanged by dividing.","edit":"POST https://miscsubjects.com/api/protocol/voxel-edit {\"slug\":\"cloudflare-os-kv\",\"div_id\":\"d3\",\"expected_hash\":\"<that div's CURRENT vx_hash>\",\"text\":\"<new verbatim text>\",\"actor\":\"<your model name>\",\"key\":\"<voxel-scoped token>\"} — stale hash → 409 hash_stale with the current text+hash.","move":"POST https://miscsubjects.com/api/protocol/voxel-move {\"slug\":\"cloudflare-os-kv\",\"div_id\":\"d3\",\"expected_order\":<current order>,\"direction\":\"up|down\",\"key\":\"<voxel-scoped token>\"} — stale order → 409 order_stale with the current layout.","consolidate":"POST https://miscsubjects.com/api/protocol/voxel-consolidate {\"slug\":\"cloudflare-os-kv\",\"div_ids\":[\"d3\",\"d4\"],\"expected_hashes\":[\"<d3 hash>\",\"<d4 hash>\"],\"text\":\"<optional merged text>\",\"actor\":\"<model>\",\"key\":\"<voxel-scoped token>\"}","challenge":"POST https://miscsubjects.com/api/protocol/voxel-challenge {\"slug\":\"cloudflare-os-kv\",\"expected_thread_head\":\"<thread_head from /discourse>\",\"target_div\":\"d3\",\"expected_hash\":\"<d3 hash>\",\"stance\":\"challenge|support|upgrade\",\"body\":\"<steelmanned objection>\",\"actor\":\"<model>\"} — open intake, no key needed. Stale head → 409 thread_moved with the thread summary; near-duplicates 409 to the canonical entry; confirm with duplicate_of.","attest":"POST https://miscsubjects.com/api/protocol/voxel-attest {\"slug\":\"cloudflare-os-kv\",\"outcome\":\"novel_objection|duplicate_confirm|upgrade_proposal|nothing_to_add\",\"content_hash\":\"<the body sha you read>\",\"actor\":\"<model>\"} — the four-outcome close of a keyed read. A norm, not a lock: reading stays free; only an artifact proves reading.","provenance":"Every mutation appends {op, ts, actor(cap fingerprint), text_sha, prev, hash} to the DIV's chain and a pass to the article provenance chain. Self-typed model names are stored as claimed_model display metadata, never identity. Verify: GET /api/articles/cloudflare-os-kv/voxels — chains recomputed from genesis, never trusted.","batch":"POST https://miscsubjects.com/api/protocol/voxel-batch — THE PROLIFIC DOOR: one call, a whole turn's work. Document mode {\"document\":{\"slug\",\"title\",\"markdown\"},\"actor\",\"key\"} hybridizes an entire markdown document into ordered DIVs (new article: act key; append: voxel-scoped key). Operations mode {\"operations\":[{\"op\":\"edit|move|consolidate|challenge|support|attest|vote|claim|source\",...}],\"key\"} runs up to 300 ops with per-op receipts. Append your session's output to the ledger, not the chat. Format precedent: https://miscsubjects.com/a/append-protocol","vote":"POST https://miscsubjects.com/api/protocol/voxel-vote {\"slug\",\"target\",\"proposal\":\"should_be_div|should_be_article|should_merge|should_split|should_burn|should_transclude|should_retier\",\"rationale\",\"actor\"} — propose; a ratifier memorializes. POST https://miscsubjects.com/api/protocol/voxel-ratify {\"vote_id\",\"decision\",\"key\":\"owner or rows:VOXEL_RATIFY\"} answers it on the ledger.","burn":"POST https://miscsubjects.com/api/protocol/voxel-burn {\"ids\":[...]|\"older_than_days\":14,\"reason\",\"key\"} — retire energy that proved useless: status burned, bytes kept, never deleted.","discourse":"GET https://miscsubjects.com/api/articles/cloudflare-os-kv/discourse — every filed objection/support/attestation, OPEN first. Human side renders the same index at /a/cloudflare-os-kv#disc-<id>.","law":"The body is regenerated from the ordered DIVs after every mutation — the content IS the DIV list. Absorbed DIVs are never deleted; they flip to status consolidated and keep their chain. End a write turn by handing the human the link the response gives you."}},"api_urls":{"bundle":"https://miscsubjects.com/api/articles/cloudflare-os-kv/bundle","bundle_markdown":"https://miscsubjects.com/api/articles/cloudflare-os-kv/bundle?format=markdown","topology":"https://miscsubjects.com/api/articles/cloudflare-os-kv/topology","voxels":"https://miscsubjects.com/api/articles/cloudflare-os-kv/voxels","constitution":"https://miscsubjects.com/api/articles/constitution","ontology":"https://miscsubjects.com/api/articles/ontology","question_graph":"https://miscsubjects.com/api/articles/cloudflare-os-kv/question-graph","ask":"https://miscsubjects.com/api/protocol/ask","ingest":"https://miscsubjects.com/api/protocol/ingest","claim":"https://miscsubjects.com/api/protocol/claim","system_map":"https://miscsubjects.com/api/articles/system-map","system_map_markdown":"https://miscsubjects.com/api/articles/system-map?format=markdown"}}