In this article
October 8, 2026
October 8, 2026

Init demo recap: Matt Carey gives every agent a workspace and a browser

Matt Carey of Cloudflare showed a durable Pi agent in a Durable Object at WorkOS init(), then gave it a stateful workspace and the Kitesurf browser to drive.

Explore with AI
Open in ChatGPT
Open in Claude
Open in Perplexity

A web app runs one deployment for many people at once. Cloudflare's Matt Carey argues that a persistent agent for each of those people breaks that model, because every agent wants its own tool loop, memory, files and workspace, and possibly its own VM. His lightning demo at WorkOS init() was about how to build an agent that scales anyway.

Carey presented on October 7, 2026, at SFJAZZ Center in San Francisco. The full init() 2026 recap covers the keynote and the rest of the day.

Why one container per agent doesn't scale

Carey said Cloudflare sees agents arriving for everyone, including consumer agents that keep working while their owners sleep. Give every user, and every user's user, an agent, and the obvious design is one container per agent. That design doesn't scale, he said, least of all at the internet scale Cloudflare runs.

Cloudflare's own browser announcement makes the cost case, saying engines like Chromium use so much memory and compute that giving every agent its own instance becomes prohibitively expensive.

Cloudflare's answer is the isolate, a bet Carey said the company made years ago that suits agents well. He described a Durable Object as an isolate that gives an agent a home.

A durable loop in a Durable Object

Carey said Cloudflare took the Pi harness, helped its maintainers make it durable, put durable Pi inside a Durable Object and exposed an SDK on top. Cloudflare's October 2 changelog names the parts: Pi 1.0, Pi Durable and a new PiHarness class in the Agents SDK, built with Earendil. Pi Durable runs the harness while the SDK's Lifecycle keeps the agent running in its Durable Object through restarts, crashes and network issues, so work survives an interruption mid-turn.

On stage this layer stayed plain. He ran a model call that invoked a tool, showed the code on screen and pointed to the docs. Check the status before you build on it. PiHarness is in beta, Cloudflare calls Pi Durable experimental, and the API will likely change.

Giving the agent somewhere to keep files

Carey didn't linger on the bare loop. Most agents want some kind of computer where they can save files or run a dev server, he said, and that is hard to do with tools and an ephemeral workspace. His fix was the Cloudflare computer library, @cloudflare/computer, which he introduced as Cloudflare's new primitive for giving an agent a scalable, stateful workspace.

For the demo, he had the agent write files listing things to do in San Francisco, and suggested you could treat files like these as stored memories. Carey, visiting from London, said he had already done Alcatraz and the Golden Gate, which left Fisherman's Wharf.

From there, he said, the agent can read and write files in that workspace. Carey said the same computer can spin up a container, run exec and start a dev server, but he moved on without showing it.

Kitesurf puts the browser in an isolate

For outside access, Carey said an agent could use MCP; his demo used Cloudflare's browser instead. He described Kitesurf as fully ephemeral and running inside a Cloudflare Worker, with no Chromium and no container underneath, only a stateless isolate.

The wiring is the part I'd copy. Carey put a skill in the workspace that explains how to use the browser, and the agent writes code in that workspace which calls the browser through what Cloudflare calls code mode, so its tool calls run inside JavaScript it wrote.

The agent crawled example.com and returned the new version of its homepage. Carey then requested a screenshot, which he narrated as the same changed page.

Cloudflare announced Kitesurf on August 6 as an agent-first browser running in V8 isolates on Workers, free while in beta in Browser Run and subject to per-account limits. The announcement lists what it can't handle yet, including video, WebGL, bot challenges that need real TLS fingerprints, and long authenticated sessions that need persistent state. For those jobs Cloudflare points you back to Browser Run's Chromium default.

What the demo showed

What he ran on stage was a tool call, files written to the workspace, a crawl of example.com and a screenshot. The scaling case rests on Carey's argument and Cloudflare's published reasoning, so test it against your own workload before you plan capacity around it.

Give each piece the lifetime it needs

The idea worth taking home is the split between loop, workspace and browser. In Cloudflare's design each one lives for a different length of time. The loop has to survive restarts, the workspace has to hold state, and Kitesurf is built to exist only for the duration of a task. Before you reach for a container per agent, ask of each component in your own stack what it needs to keep, and for how long.

Start with Cloudflare's Pi harness changelog, which links the docs and an example that uses a @cloudflare/computer workspace. Then read the Kitesurf announcement and try your target sites before you assume they will render in an isolate.