Building an Internal Video Platform on Cloudflare’s Edge
Cloudflare produces a steady stream of internal video content—from all-hands recordings to product walkthroughs. The company wanted a secure, centralized place where employees could browse and watch these videos directly from the browser, without hunting through email or chat archives. The result was CloudflareTV, an internal app built entirely on Cloudflare Workers and Stream, with no dedicated origin infrastructure for encoding, storage, or delivery.
The core requirements were straightforward: strict access control so videos remain private, authentication restricted to employees, simple tagging for searchability, and an originless backend. Below is how each piece was put together, focusing on the APIs and configuration steps involved.
Locking Down Video Access with Signed URLs
The first layer of security is enforced at the video level. Every video stored on Cloudflare Stream can be marked as private, meaning it requires a signed URL for playback. This setting is available both in the Stream dashboard and via API.
Once a video is marked private, it cannot be fetched directly. Instead, playback requires a temporary token generated with a Stream signing key. Creating such a key involves an API call that returns a JSON object containing the key’s id and pem values.
A Worker script uses these credentials to generate a signed token for a given video ID, with a configurable expiration—one hour in this case. The token is passed to the video’s embed code in place of the standard video ID in the src attribute. This mechanism ensures each video view is both authorized and time-limited.
Categorizing Content with Custom Metadata
To make videos easy to locate, CloudflareTV allows tagging during the upload process. Stream’s video object includes a meta field that accepts arbitrary JSON. A simple update to this field—for example, assigning a comma-delimited list of tags—associates the video with those categories.
These tags become part of the video data returned by the API, meaning they can be used later to render the UI and filter content.
Fetching Video Lists Without an Origin Server
The application’s main interface depends on fetching a list of all videos and their associated metadata. Cloudflare Stream provides an endpoint that returns exactly this information. Rather than running a traditional backend, CloudflareTV uses a Worker to call this API.
The Worker relies on environment variables to store necessary credentials and configuration. A dedicated Worker function performs the API call and returns the video list, demonstrating how a complete data layer can live on the edge.
To expose this Worker, a route is registered on a zone in the dashboard, pointing traffic to the script.
Restricting Access with Cloudflare Access
The final security measure is controlling who can reach the application itself. Cloudflare Access is configured under the Access tab of the dashboard. Two steps are required:
- Register an identity provider as a login method.
- Define an access policy specifying who is allowed in.
For CloudflareTV, Google was added as the identity provider, which requires entering a Client ID and Client Secret obtained from Google’s developer console.
The subsequent access policy is set to only permit users with email addresses ending in the corporate domain. With that rule in place, the application is effectively invisible to anyone outside the organization.
Further Resources
Combining Stream’s storage and player with Worker routes and Access policies enables fully featured video applications without managing any backend servers. For teams looking to build something similar, the following documentation is a useful starting point:



