Multi-tenant document management on Cloudflare Workers (Hono, D1 + KV + R2). Folders, file upload/versioning/download, token-gated public sharing, comments, trash with 30-day auto-purge, per-tenant analytics, Stripe subscription billing across four storage tiers, and AI-assisted summarization/auto-tagging via the fleet's engine runtime.
| Access | Method | Path | Description |
|---|---|---|---|
| Public | GET | /health, /status |
Health |
| Public | GET | /shared/:token, /shared/:token/download |
Public share links (own unguessable-token gate) |
| Public | POST | /webhooks/stripe |
Stripe webhook (own HMAC signature check) |
| Authenticated | GET/POST/PUT/DELETE | everything else | Tenants, folders, files (upload/download/versions/comments), shares, trash, activity, analytics, plans, AI |
All routes other than the public ones listed above require X-Echo-API-Key, compared to
env.ECHO_API_KEY in constant time. See SECURITY.md for what changed in this
consolidation pass -- the repo as found exempted every GET request from auth, which meant
/files/:id/download served real file content to anyone who could guess a file id.
npm install
npm testThis service stores tenant document content and Stripe billing metadata. See SECURITY.md to report a vulnerability -- never as a public issue.
See LICENSE. Contributions: see CONTRIBUTING.md.