FluxyChat

Learn

Status and limits

What FluxyChat ships today, what is labs, and what is not claimed. For builders and buyers.

FluxyChat is a room on Cloudflare: one Durable Object plus D1. Humans and invokeAgent share the chat timeline. Hosted is beta. Self-host is MIT.

Claim strings in this page are checked against capabilities.json in CI. Game, IoT, fleet, spatial, and voice media are optional modules on the same bus. They are not the product promise.

The kernel is rooms, presence, Yjs, agents on that timeline, feeds (not chat), visibility / visibleTo, and pk_ vs fc_.

Shipped

AreaWhereLimit
Room socketsHibernation API (acceptWebSocket). Cost notesCode path exists. Idle-duration numbers from a Cloudflare invoice are not published yet.
Agent mid-hibernateAgentsRoom DO sleep is not Think chatRecovery. POST /agents/:id/invoke can run on AgentDurableObject room-run:{project}:{room} when AGENT is bound.
Large roomsSupergroup DO (docs/supergroup-room-sharding.md in the repo)Sharding is in tree, not “roadmap only.”
SearchSearchFTS and optional hybrid.
Yjs / cursorsStorage, gallery boardsSecond binary WebSocket, same room route.
HITL / quorum / tool policyTool presets, quorumEmail/Slack tap: GET shows confirm, POST decides (one-time token + payload hash). Maker-checker: requester and agent cannot approve.
Voice → roomPOST /rooms/:id/voice-bridge · LabsTranscripts, tool calls, coaching whispers, handoff. LiveKit Agents / Pipecat / OpenAI Realtime. Not an SFU.
Maker-checker / evidenceHITL decide + sealHitlEvidencePackRequester and agent cannot approve. Pack is SHA-256 over v2 JSON. Autonomy (toolAutonomy) still honors HITL.
Native pushPOST /api/device/register · SDK createPushProviderBackends: expo, fcm-v1, apns. Expo Go (SDK 53+) does not receive remote push.
GenAI tracesOTelinvoke_agent / execute_tool, room as gen_ai.conversation.id. Spec: semantic-conventions-genai @ 1.42.0 Development. fluxy.approval.wait is ours.
Browser handoffPOST /rooms/:id/browser-handoffCloudflare Browser Run / Browserbase Live View as a whisper card. Invoker only (plus named approvers). No screenshots on the transcript.
A2UIPOST /rooms/:id/a2ui · SDK catalogv0.9 data UI mapped to ui-kit. Buttons are attributed actions; quorum optional. Not an iframe.
Public share/share/:token · guideUnguessable token, noindex, no whispers/tool args. type=public only.
Transcript importPOST /rooms/import-transcript · guideFile you already have. Cap 400. Marked imported, unverified.
Room ticketsPOST /rooms/:id/tickets · guideSelf-host env PAT. Hosted: per-project encrypted token. GitHub/Linear/Jira host allowlist. Not OAuth apps.
Integration kitHMAC webhooks + entity links · guideMaps 11 vendors. Writes need intent. No Marketplace.
AG-UI eventscreateAgUiAdapter · POST /ag-ui/join · Generative UIJoin + last-run replay. Not a CopilotKit host. Live tokens stay on the room socket.
Connection fallbackSDK FluxyChatTransport: websocket / SSE / pollingRoom socket fallback.
AI SDK ChatTransportFluxyRoomChatTransport in @fluxy-chat/sdk / @fluxy-chat/sdk/ai-sdkGuide. Full token stream still wants the room WebSocket.
MCP official registryguideManifest in-repo. Not listed on the official MCP registry.
npm@fluxy-chat/sdk (pin 0.6.13+ for ChatTransport / requireApproval / mcpName), react, ui, ui-kit, vue, svelte, agent, protocol, config, create-fluxy-chat@fluxy-chat/auth is in-repo with publishConfig but may not be on npm yet. @fluxy-chat/ai-sdk-workflow is private. chat-adapter-fluxychat is unpublished. Swift/Kotlin/Flutter/.NET are source under packages/. Python HTTP + WS stub: packages/python — not published to PyPI. Go WS: packages/sdk-go. Generated REST: OpenAPI Generator, Apache-2.0, see scripts/generate-rest-sdks.md. Confirm with npm view @fluxy-chat/sdk version.
Clonegithub.com/AlessandroFare/fluxychat
E2EECompareNot claimed.
HIPAA / SOC 2READMEChecklists are not attestations. No BAA. We do not sell healthcare.
BridgesConsoleYou create the vendor app. Not a 14-channel desk.
System OneSYSTEM_ONE_PROVIDERGate next to the room LLM (e.g. Groq). Not a replacement chat model. See Room Decisions.
VoicejoinVoiceStage + voice-bridgeSignaling only for media. Transcripts on the room bus. Media is yours (LiveKit/Pipecat).
Hosted SAML loginOff unless SAML_SSO_ENABLED=trueSelf-host SAML is unchanged.
Shared-room agent defaultsTwo-key HITL · guideOn unless you opt out. Tests use synthetic markers.
Room DecisionsguideLabels + floor. Default shadow. Hosted labels opt-in.
Art. 50 markschecklistHMAC integrity, key rotation. Not a legal guarantee.
Agent InboxGET /inbox/agent · SDK fetchAgentInboxPending HITL for the current approver. Accept / ignore map to HITL decide. LangGraph { ns, value } and askHuman land on the same queue. Ambient cron needs roomId.
DSA noticePOST /public/dsa-report · hosted /reportUnauthenticated, rate-limited. Share tokens are revoked, not reminted. Not legal advice.
RoomDojoapps/worker/src/lib/room-dojo.test.jsSynthetic two-key ON vs OFF. No exploit recipes.

Not shipped yet (priority)

  1. A 60-second hosted clip: two humans, one agent, refresh mid-stream, a second seat approves a tool. Gallery deal-room is the closest app. Guest-first UI: --example shared-ai-room.
  2. Measured load and Durable Object duration from staging (idle sockets vs invoice). Do not treat qualitative hibernation docs as that number.

June 2026 audit files in git history are snapshots. Closed work lives in docs/audit/REMEDIATION.md. Open security work is not listed in this repository.

On this page