By · Founder, Stacktree · Last updated
blog · living status post · tested at launch

Cloudflare Drop: live in seconds, deleted in an hour unless you claim it.

Drag a folder into cloudflare.com/drop and there is no signup, no project, no wait: a public workers.dev URL in seconds. The catch is the countdown. Cloudflare's own docs say that if nobody claims the deployment inside 60 minutes, it deletes the account and its resources. We deployed through it at launch and have tracked it since. Here is how it behaves, what the docs now pin down, the terms you accept on the way in, and why the most interesting card in the flow is called Markdown for Agents. Updated 19 September 2026.

Get started free

No card · 3 pages free · about a minute

What is Cloudflare Drop?

Cloudflare Drop (cloudflare.com/drop, launched 8 July 2026) deploys a static site from a dragged folder or zip with no account. The site is live in seconds on a public workers.dev URL and stays up for 60 minutes. Claim it into a Cloudflare account inside that hour, or Cloudflare deletes the deployment and everything with it.

What we saw deploying through it

We dropped a zip through cloudflare.com/drop within hours of launch. The flow, exactly as observed: the dropzone ("Drop a folder. Or a zip. Summon your site - HTML, CSS, JS.") takes a folder or zip with no login; a terms dialog appears ("By deploying, you agree to Cloudflare's Terms of Service"); accept, and seconds later the screen reads "Your site is live" with the site on a public URL shaped like drop-{id}.{words}.workers.dev, which places Drop on Workers static assets rather than Pages. A countdown starts immediately: "Claim (59:38)", alongside "Copy claim link" and "Deploy another." So the leak's one-hour figure is confirmed: sixty minutes to claim an anonymous deployment before it expires, and the claim link is portable, so the person who drops does not have to be the account that keeps it.

The served page itself is public, edge-cached, and carries no access gating of any kind. Two playful details: the dropzone is multiplayer, showing other visitors' live cursors ("Matt", "Priya", "Riley" were dropping files alongside us), and the success screen boasts your site "is reachable within ~32ms of 95% of the world's Internet-connected population." Credit where due: it is the lowest-friction deploy Cloudflare has ever shipped, and a claimed site graduates into the full Workers platform, DNS, HTTPS and DDoS protection included.

The pre-release screenshots showed four post-claim setup cards in the dashboard: add a domain, control access (Worker policies), observability, and "Markdown for Agents." Those live behind the claim step, not in the anonymous flow we tested.

The limits, now that the docs exist

At launch there was nothing to read. There is now: a changelog entry and a Workers page on claiming temporary deployments. Four things they settle, checked 19 September 2026:

  • The hour is real, and so is the deletion. "The intended user must complete the claim within 60 minutes." Miss it and "Cloudflare deletes the account and its resources." Not expires, not archives. Deletes.
  • Up to 1,000 files, each asset up to 5 MiB. That is the static-assets ceiling a Drop deployment inherits, and it rules out a folder full of uncompressed video or a large image library.
  • Static assets only. "Static HTML, CSS, JavaScript, images, and fonts." No build step in the anonymous flow, so a framework project has to be built before it is dropped.
  • The claim link is a credential. Cloudflare's own guidance is to treat the claim URL "like a bearer credential" and deliver it only to the intended user. Anyone holding it can take the deployment into their account.

What the docs still do not cover: pricing specific to Drop, whether a claimed site can be replaced in place at the same URL, and which terms of service govern the anonymous hour, which is the subject of a later section.

Anonymous-first is the notable part

Netlify Drop and Vercel Drop both require an account before anything goes live. Drop inverts that: the site is live before Cloudflare knows who you are, and the account only enters when you want to keep it. Publish first, identify later. That ordering is the whole trick, because the person (or agent) holding a folder of HTML wants to see it on a URL now, not after a signup form.

We know that pattern well, because it is exactly how Stacktree works: anonymous publish first, a claim step to keep it. Cloudflare arriving at the same funnel independently is the strongest validation the no-ceremony model has had yet. It also makes Drop the sixth major entrant in twelve months to converge on "AI makes HTML, it needs a URL, ceremony is the enemy": Shopify's internal Quick, OpenAI's Codex Sites, here.now, Vercel Drop, Notion's HTML block, and now the company that runs a fifth of the web.

Cloudflare Drop vs Netlify Drop vs Vercel Drop

Three platforms, one gesture, three different trades. Netlify Drop is the veteran: account required, serves files as-is, and can update an existing site in place. Vercel Drop is account-first too, but builds framework projects, and every drop creates a new project and URL. Cloudflare Drop is the only anonymous one: live before any signup, sixty minutes to claim, static files only (HTML, CSS, JS), on workers.dev. All three publish publicly with no privacy controls in the flow, and none are drivable by an agent. The full veteran-vs-newcomer table is in Vercel Drop vs Netlify Drop; Cloudflare's entry mostly competes on the missing signup and the platform a claimed site graduates into.

Which to use: framework project you want built, Vercel Drop. A folder you want to update at the same URL later, Netlify Drop. The fastest possible "is this live?" check with zero account, Cloudflare Drop. A private artifact for a client, or something an agent publishes rather than a human dragging files: that is the other half of the category, and none of the drops serve it.

Markdown for Agents: AEO goes native

The most interesting card in the flow is not the dropzone. "Markdown for Agents: make your site easy to explore for agents, showing up more in AI conversations," with an enable button. Cloudflare is shipping agent legibility as a one-click hosting feature: a Markdown rendition of your site for AI crawlers and assistants, in the same checklist as DNS and HTTPS.

That confirms something we have bet on for a while: how a page reads to an agent is becoming a property of hosting, not an SEO afterthought. Note the mechanism Cloudflare chose, though: content negotiation (serve the agent a Markdown rendition of the real page), not another static manifest file. That matches what our own crawler logs show, where AI bots overwhelmingly fetch regular pages rather than the llms.txt-style files the industry spent a year adding. Stacktree ships Markdown content negotiation and WebMCP for the same reason. When Cloudflare puts "showing up more in AI conversations" on a setup card, answer-engine visibility has officially gone mainstream, and it is converging on the page itself being legible, not sidecar files.

Whose content is it? The terms you accept

The deploy dialog asks for exactly one thing: "By deploying, you agree to Cloudflare's Terms of Service." Which terms those are matters more than usual here, because Drop's anonymous hour is precisely the window in which you have no account and no subscription agreement. The document that governs Cloudflare's websites and online services when no signed agreement applies is the Website and Online Services Terms of Use (effective 1 August 2025), and its Section 2 license grant reads, in full, because paraphrases of legal text start arguments:

"By submitting, posting, or publishing your content, suggestions, enhancement requests, recommendations, feedback, information, data, or comments ("Content") to any Website or Online Service, you are granting Cloudflare a perpetual, irrevocable, worldwide, non-exclusive, royalty-free right and license (with the right to sublicense) to use, incorporate, exploit, display, perform, reproduce, distribute, and prepare derivative works of your Content."

Two honest readings, and both matter. First, this is not exotic wording: a clause much like it sits under most feedback and comment forms on the web, and nobody reads those as a land grab. Nearly every host's terms include some content license, because serving your files legally requires one. Second, it is notably broader than what Cloudflare's own paying customers agree to. The Self-Serve Subscription Agreement (Section 2.5.1) grants a license to Customer Content only "to the extent necessary to provide the Services." Service-scoped versus perpetual and irrevocable with sublicensing is a real difference, and an anonymous drop looks more like "publishing content to an Online Service" under the first document than like Customer Content under a subscription you have not signed up for yet.

The likeliest explanation is drafting inertia, not intent: the website terms were written for comments and feedback, Drop shipped without docs, and Cloudflare has not said which agreement a pre-claim deployment falls under. Claiming the site into an account presumably moves it under the subscription agreement's narrower license, but "presumably" is doing real work in that sentence, and for the anonymous sixty minutes the plain reading is the perpetual one. If what you are dragging in is your own experiment, none of this matters. If it is a page you are sending to a client, or anything carrying data that is not yours to license, read the words before the drop, and prefer a host whose terms scope the license to serving the page. That is table stakes for private HTML hosting, and license scope is one of the criteria in our private hosting comparison.

What is still unknown

  • Which agreement governs a pre-claim deployment. The dialog says "Terms of Service" without naming a document; see the section above for the two candidates and why the difference matters.
  • Pricing for Drop itself. The file limits are documented now; what a claimed site costs beyond the ordinary Workers free tier is not spelled out anywhere Drop-specific.
  • What "control access" really offers. Worker access policies read like team access control (authenticate viewers against a policy), not a private-by-default share link. Whether Drop grows a lighter-weight gate for sending a deliverable to a client is unknown.
  • Any agent-facing path. The flow shown is browser drag-and-drop. No API, CLI, or MCP surface is visible for Drop itself.
  • Update semantics. Whether a claimed Drop site can be replaced in place at the same URL, or each drop is a new deployment, is still not documented.

Drop or a publish primitive

The boundary that sorted the first five entrants sorts this one too: apps and pages are different shapes. If the folder you are holding is a site that belongs on your Cloudflare account, behind your domain, with observability and access policies, Drop looks like it will be a lovely on-ramp, and the anonymous first hour removes the last excuse not to try it.

If the thing you are holding is an artifact (a report for a client, a dashboard your agent regenerates nightly, a prototype that needs feedback rather than infrastructure), the trade flips. An artifact wants a private, unguessable URL by default because agent output routinely embeds real data. It wants replace-in-place so thirty revisions do not mean thirty URLs. It wants gates a recipient can pass without an account, and it increasingly wants to be published by the agent itself, over MCP or an API, with a read on how it landed afterwards. That half of the category is still the half the platform drops leave on the table, and it is the half Stacktree is built for.

Fix it now

You've read why the public link is a problem. Paste the artifact here and get a private one, no account, and a passcode if you want it.

FAQ

Frequent questions

What is Cloudflare Drop? +
A way to deploy a static site to Cloudflare with no account: drag a folder or a zip into cloudflare.com/drop and it is live in seconds on a public workers.dev URL. You then have 60 minutes to claim the deployment into a Cloudflare account, or it is deleted. Launched 8 July 2026.
How long do unclaimed Cloudflare Drop sites last? +
Sixty minutes, and then they are gone. Our test deploy showed a "Claim (59:38)" countdown the moment it went live, and Cloudflare's claim-deployments docs are blunt about the ending: "If the user does not complete the claim, Cloudflare deletes the account and its resources." The claim link is portable, so someone else can keep it.
What are Cloudflare Drop's limits? +
Cloudflare documents up to 1,000 files per deployment, with each asset up to 5 MiB. Accepted content is static assets only: HTML, CSS, JavaScript, images and fonts. No build step, no server code in the anonymous flow. Deploying is free; claiming needs a free Cloudflare account, and a claimed site lands on Workers static assets.
Is Cloudflare Drop released? +
Yes, since 8 July 2026, a day after James Ross spotted it in development. There is now a changelog entry and a "Claim temporary deployments" page in the Workers documentation, both of which confirm the 60-minute window and the file limits. There is still no dedicated Drop product doc covering pricing or update semantics.
Is Cloudflare Drop the same as Cloudflare Pages direct upload? +
No. Pages direct upload has offered drag-and-drop zip/folder deploys for years, but it requires an account and a project first. Drop inverts the order: deploy anonymously first, see it live, then claim. The pre-release URLs are also workers.dev, suggesting Drop sits on Workers static assets rather than Pages.
Are Cloudflare Drop sites private? +
No. We checked the deployed test site directly: it serves publicly with edge caching and no access gating of any kind. The unguessable subdomain gives you privacy by obscurity, like an unlisted link, but there is no password, viewer gate or expiry in the flow. Access policies sit behind the claim step, and those are team access control, not a recipient-friendly gate.
What is "Markdown for Agents" in Cloudflare Drop? +
One of Drop's post-deploy cards reads "Make your site easy to explore for agents, showing up more in AI conversations." Cloudflare is shipping agent legibility, a Markdown rendition of your site for AI crawlers and assistants, as a one-click hosting feature. It is the clearest signal yet that answer-engine visibility is becoming a hosting concern rather than an SEO afterthought.
Can an AI agent use Cloudflare Drop? +
Not really. The flow is a browser file-chooser plus a terms-consent dialog, human-shaped at both steps, with no API, CLI or MCP path. Agents deploying to Cloudflare still use Wrangler or the API with account credentials. Stacktree, the product this blog belongs to, fills that gap: an agent calls publish_html over MCP and gets a URL back, with no browser step.
Are Cloudflare Drop sites free? +
Deploying is free and needs no account. Claiming needs a free Cloudflare account, and the claimed site becomes an ordinary Workers deployment serving static assets, so the Workers free tier applies from then on. Cloudflare has not published pricing specific to Drop itself, and the anonymous hour costs nothing.
Who owns content uploaded to Cloudflare Drop? +
You keep ownership, but the licence question is open. The deploy dialog references "Cloudflare's Terms of Service" without naming a document. The Website and Online Services Terms of Use, which govern when no signed agreement applies, grant a "perpetual, irrevocable, worldwide, non-exclusive, royalty-free" licence with sublicensing. Account customers get a narrower one, scoped to providing the Services. Cloudflare has not said which applies here.
How does Cloudflare Drop compare to Netlify Drop and Vercel Drop? +
Same gesture, third platform. Netlify Drop is the veteran; Vercel Drop shipped June 2026 aimed at AI-tool exports; Cloudflare's version adds the anonymous-first hour and the agent-legibility card. All three end in the same place: a public URL on the vendor's platform, claimed into an account, iterated via the platform's own tooling.
Keep reading

Related guides

References

Sources and further reading

Need the artifact version today?

Anonymous publish, private by default, same URL across revisions, and your agent can do it over MCP. The claim step is optional here too.

Sign up free →