Demo host access

How to reach the private SpeakerOps Cloudflare demo, who can log in, and what is seeded.

What the demo host is

The private Cloudflare demo is a full SpeakerOps app on Workers with remote D1 and seeded program data. It is not a marketing site and not a bare IP. SPA routes are served from the Worker ASSETS binding; API stays under /api/* with /health for probes.

Email delivery uses Cloudflare Email Sending from noreply@speakerops.org. Resend is not used on the demo host. Magic links are enqueued as outbox rows and drained asynchronously — never sent on the login request path.

HostRole
https://www.speakerops.orgPrimary app + API custom domain
https://speakerops.orgApex → same Worker
workers.dev fallbackspeakerops-demo.speakerops-dogfood.workers.dev when needed

Who can log in

Judges: open https://www.speakerops.org/judge and enter the access code from the competition submission. This mints a shared demo-persona session (admin, evaluator, or speaker) on the seeded demo event lasting about four hours; the role switcher at the top of every shell moves between roles without re-entering the code and is badged “Shared demo”. Demo sessions can create API keys with a server-clamped 4-hour expiry; only demo-created keys can be revoked.

Everyone else: login is membership-aware — there is no email allowlist. Existing users and provisioned members (for example a speaker whose CFP submission was accepted) can request a magic link on the login page; unknown emails cannot self-register. Check the inbox for the Cloudflare-delivered message, open the link once, and the Worker sets an HttpOnly session cookie. Links are single-use and short-lived.

  1. Judges: open https://www.speakerops.org/judge, enter the access code, and pick a role.
  2. Members: open https://www.speakerops.org/login (or the current demo base URL).
  3. Enter your email and submit the magic-link request.
  4. Open the email from SpeakerOps and click the link once.
  5. Verify the app loads admin or portal chrome matching your role.

What is seeded and what is limited

Demo seed includes a large speaker graph, forms, tasks, and schedule-ready structures so every menu has realistic data. Public CFP is open for the dogfood event slug with Turnstile. Public CFP file upload is limited by a strict mime/size allowlist and best-effort per-IP rate limits so untrusted traffic cannot flood file storage (the demo host stores file bytes as durable D1 rows — file_blobs — because R2 is not bound).

The role switcher is enabled on the shared demo (judge access requires it); the developer outbox stays off. DDoS protection relies on the Cloudflare edge; the /judge access code is rate limited per IP, and magic links go only to existing users and provisioned members.

  • Seeded multi-speaker program graph on remote D1
  • Public CFP open with Turnstile; uploads mime/size-restricted and rate limited
  • Comms and auth email via Cloudflare Email Sending (no attachments — calendar .ics is a portal download)
  • Role switcher on (shared demo); AUTH_DEV_OUTBOX off; demo sessions mint API keys clamped to a 4-hour expiry

Operator checklist after first login

Walk Admin → CFP, submissions, speakers, schedule, readiness, and settings so you know where each Learn guide maps. If you need agent automation, mint a scoped API key under Settings → API keys and follow the CLI and keys guide in this handbook. That article includes install, auth, every inventory command, exit codes, and agent rules so you do not need a second document to automate.

  1. Confirm role and event context after login.
  2. Open readiness to see the health of the seeded program at a glance.
  3. Open at least one form, one submission, and schedule studio.
  4. When ready for automation, mint a least-privilege API key and open CLI and keys.