Release note · · Valen Systems
Check Worker request policies before wiring them in
Two more small Cloudflare tools are ready to download: Worker No-Egress and Rate Limit Contract. Both are free, MIT-licensed v0.1.0 betas. Unzip the package and run the included examples with Node.js 22.13 or newer. No install, account token or payment required.
Worker No-Egress
Write down which HTTPS origins and methods your application should call, then test that policy against synthetic requests.
node worker-no-egress.mjs check examples/policy.json
node worker-no-egress.mjs test examples/policy.json examples/fixtures.jsonThe command-line checks run offline: they do not fetch URLs or resolve DNS. The included JavaScript adapter can enforce the same origin and method checks for requests you explicitly route through it. It forces manual redirects and rejects redirect responses.
Despite the name, this is not a network firewall or sandbox. Direct fetches and other transports bypass it. It does not verify where DNS resolves, restrict URL paths or scrub secrets from approved requests. Read the README before connecting a real transport.
Download Worker No-Egress ZIP · Source and setup · SHA-256 checksum
Rate Limit Contract
Check your expected allowed and over-limit responses, including status codes and Retry-After seconds. Compare route and method policies across environments using local fixtures.
node bin/rate-limit-contract.js
node bin/rate-limit-contract.js --route /api/login --method POST --environment production --count 6 --status 429 --retry-after 60 --identity synthetic-aliceThe first command checks the included fixture and production/staging parity. The second checks a synthetic over-limit response. Neither sends traffic or applies rate limits.
This is a fixture checker, not live enforcement or a traffic simulator. It does not model time windows or concurrency, and a passing fixture does not prove deployed Worker behavior. Use synthetic identities only: its fingerprints are unkeyed hashes, not anonymization or production HMAC.
Download Rate Limit Contract ZIP · Source and setup · SHA-256 checksum
Small tools, explicit limits
Both packages include source, examples, tests and an MIT license. Neither includes an MCP server or hosted service in this first version. Windows execution is untested. Start with the examples and keep private data out of fixtures and command-line arguments.
Independent Valen Systems projects; not affiliated with Cloudflare.
Browse the free tools Back to Field Notes
Written with AI assistance; release links and package checksums verified by Valen Systems’ publishing workflow.