This worker connects the SmartFlow frontend with Google Gemini AI. It acts as a secure serverless proxy — handling authentication, CORS, rate limiting and Gemini API communication so the API key is never exposed in the browser.
Live app: https://barakzai.cloud · Main repo: aryanbarak/smartflow
| Method | Path | Protection | Description |
|---|---|---|---|
POST |
/analyze |
JWT + Origin | Send a message to Gemini, returns AI response |
POST |
/briefing |
JWT + Origin | Generate personalized weekly life briefing |
POST |
/translate |
JWT + Origin | Translate text via Gemini |
POST |
/tts |
JWT + Origin | Text-to-speech conversion |
GET |
/health |
Public | Health check |
| Measure | Implementation |
|---|---|
| API key isolation | Stored in Cloudflare Worker secrets only |
| User authentication | JWT validation on every protected endpoint |
| Rate limiting | Per-user request counter via Cloudflare KV |
| Origin restriction | CORS whitelist for SmartFlow frontend only |
| Layer | Technology |
|---|---|
| Runtime | Cloudflare Workers (V8 isolates) |
| Language | JavaScript (ES2022) |
| AI | Google Gemini 2.5 Flash → 2.0 Flash (fallback) |
| Rate limiting | Cloudflare KV |
| Auth | JWT validation |
| Deploy | Wrangler CLI |
- AI Learning Assistant
- Weekly Life Briefing
- Document Analysis & OCR Summaries
- Action Item Generation
- Text-to-Speech
Aryan Barakzai · barakzai.cloud · GitHub
All Rights Reserved — Copyright © Aryan Barakzai