Demo host access
How to reach the private SpeakerOps Cloudflare demo, who can log in, and what is seeded.
What the demo host is
The private Cloudflare demo is a full SpeakerOps app on Workers with remote D1 and seeded program data. It is not a marketing site and not a bare IP. SPA routes are served from the Worker ASSETS binding; API stays under /api/* with /health for probes.
Email delivery uses Cloudflare Email Sending from noreply@speakerops.org. Resend is not used on the demo host. Magic links are enqueued as outbox rows and drained asynchronously — never sent on the login request path.
| Host | Role |
|---|---|
| https://www.speakerops.org | Primary app + API custom domain |
| https://speakerops.org | Apex → same Worker |
| workers.dev fallback | speakerops-demo.speakerops-dogfood.workers.dev when needed |
Who can log in
Judges: open https://www.speakerops.org/judge and enter the access code from the competition submission. This mints a shared demo-persona session (admin, evaluator, or speaker) on the seeded demo event lasting about four hours; the role switcher at the top of every shell moves between roles without re-entering the code and is badged “Shared demo”. Demo sessions can create API keys with a server-clamped 4-hour expiry; only demo-created keys can be revoked.
Everyone else: login is membership-aware — there is no email allowlist. Existing users and provisioned members (for example a speaker whose CFP submission was accepted) can request a magic link on the login page; unknown emails cannot self-register. Check the inbox for the Cloudflare-delivered message, open the link once, and the Worker sets an HttpOnly session cookie. Links are single-use and short-lived.
- Judges: open https://www.speakerops.org/judge, enter the access code, and pick a role.
- Members: open https://www.speakerops.org/login (or the current demo base URL).
- Enter your email and submit the magic-link request.
- Open the email from SpeakerOps and click the link once.
- Verify the app loads admin or portal chrome matching your role.
What is seeded and what is limited
Demo seed includes a large speaker graph, forms, tasks, and schedule-ready structures so every menu has realistic data. Public CFP is open for the dogfood event slug with Turnstile. Public CFP file upload is limited by a strict mime/size allowlist and best-effort per-IP rate limits so untrusted traffic cannot flood file storage (the demo host stores file bytes as durable D1 rows — file_blobs — because R2 is not bound).
The role switcher is enabled on the shared demo (judge access requires it); the developer outbox stays off. DDoS protection relies on the Cloudflare edge; the /judge access code is rate limited per IP, and magic links go only to existing users and provisioned members.
- Seeded multi-speaker program graph on remote D1
- Public CFP open with Turnstile; uploads mime/size-restricted and rate limited
- Comms and auth email via Cloudflare Email Sending (no attachments — calendar .ics is a portal download)
- Role switcher on (shared demo); AUTH_DEV_OUTBOX off; demo sessions mint API keys clamped to a 4-hour expiry
Operator checklist after first login
Walk Admin → CFP, submissions, speakers, schedule, readiness, and settings so you know where each Learn guide maps. If you need agent automation, mint a scoped API key under Settings → API keys and follow the CLI and keys guide in this handbook. That article includes install, auth, every inventory command, exit codes, and agent rules so you do not need a second document to automate.
- Confirm role and event context after login.
- Open readiness to see the health of the seeded program at a glance.
- Open at least one form, one submission, and schedule studio.
- When ready for automation, mint a least-privilege API key and open CLI and keys.