github cloudflare/workers-sdk @cloudflare/workers-auth@0.10.0

Minor Changes

  • #15883 ae70e63 Thanks @Kmschr! - Allow cf to request the account token creation scope

    New cf OAuth logins can request account_api_tokens:create. Existing sessions must authenticate again to receive the scope.

  • #15948 a0712e5 Thanks @akoval-cf! - Add beta K2 producer bindings for existing streams

    Configure a stream created through Wrangler, the Dashboard, or the API in wrangler.json:

    {
      "k2": [
        {
          "binding": "ORDERS",
          "stream": "0123456789abcdef0123456789abcdef"
        }
      ]
    }

    The binding supports env.ORDERS.send([{ content: new TextEncoder().encode("order"), headers: { event: "order.created" } }]). Batches use either all ArrayBuffer or all Uint8Array content. Check the returned success value, handle rejected RPC promises, and retry only when the returned error explicitly allows it. Generated environment types describe this producer contract without requiring a separate application dependency.

    K2 requires an enabled account. Deployment credentials need Worker deployment and K2 configuration-read access. Default Wrangler logins now request the K2 OAuth scopes; existing OAuth users should run wrangler login again to grant the new permissions. Development always uses a real K2 stream and may incur usage charges; no local simulator is provided. The remote setting can be omitted, remote: true suppresses the usage warning, and remote: false is rejected. Consumption is not part of this Worker binding.

  • #15948 a0712e5 Thanks @akoval-cf! - Add beta K2 stream management commands

    Use wrangler k2 streams create order_events, wrangler k2 streams list, wrangler k2 streams get <stream-id>, and wrangler k2 streams delete <stream-id> to manage K2 streams. Creation enables Worker bindings but not HTTP ingestion by default, matching the dashboard. Pass --http-enabled to enable authenticated HTTP ingestion and print its endpoint. Creation prints the stream ID and a binding configuration with a YOUR_BINDING_NAME placeholder for the Worker's variable name, but does not edit the configuration file automatically.

    All four commands support --json. Deletion requires confirmation, or --force/-y to skip it; use --force --json for JSON deletion output. Creation also accepts retention, HTTP authentication, Worker-input, and CORS options; listing supports pagination and a name filter. Default Wrangler logins now request k2.read and k2.write; existing OAuth users should run wrangler login again, or use a custom API token granting K2 Config Write. The account must be enabled for K2.

Patch Changes

  • Updated dependencies [b9f1cdc, a0712e5]:
    • @cloudflare/workers-utils@0.45.0

Don't miss a new workers-sdk release

NewReleases is sending notifications on new releases.