Tocyn
Pre-release open source

Tocyn

Welsh for “ticket” — an omnichannel, multi-tenant helpdesk for Cloudflare's edge application stack.

No hosted Tocyn service is operated by the project. This page describes the source project. It is not a customer helpdesk login and it is not evidence of production readiness.

What Tocyn is building

Tocyn brings human operators, service users and governed AI workflows into one canonical conversation workspace across API, portal, widgets, support email, Slack, Microsoft Teams, WhatsApp and Telegram.

Approved target architecture

Shared browser UI
Dashboard, portal and optional Shadow DOM widgets share planned Ark/Zag behavioural primitives, extendable interfaces and standard CSS-variable themes. Static styling stays separate from behaviour and API Worker bundles.
Verified channel boundaries
Application API and external-provider ingress establish tenant authority. Durable raw envelopes and journals precede acknowledgement; Queues feed normalisation and deduplication into canonical conversation state.
Reliable state and replies
D1 state/audit/outbox, R2 bodies/media and a distinct asynchronous dispatch responsibility preserve replies and recovery. Durable Objects provide realtime and budget coordination.
Bounded, governed assistance
Workers AI, Vectorize and Workflows support knowledge/enrichment. Autonomous actions require owner/tenant policy, approval where required, audit and human takeover, proven first against a controlled reference API.

Target architecture, not a deployment claim. API, ingress, consumer and dispatch are distinct runtime responsibilities; concrete Worker allocation and service-binding wiring remain governed implementation choices. Standalone use does not require embedding.

Target architecture diagram and delivery status

Delivery status — current source

Application surfaces
Operator dashboard, customer portal, widget and programmatic API foundations.
Cloudflare runtime
Hono Worker with D1, R2, a tenant-keyed Durable Object, Workers AI, Vectorize and a vectorisation Workflow.
Tenant ownership
Phase 1 tenant-qualified ownership/isolation is implemented in source; environment and production cutover remain separate gates.
Email
Injectable mail transport with current Resend configuration. Full support-email channel activation is later roadmap work.

The current Worker configuration does not define Cloudflare Queue or Cloudflare Calls bindings. Slack, Teams, WhatsApp, Telegram and governed autonomous customer-backend actions are approved roadmap work rather than deployed capabilities.

Roadmap

The first planned test outcome is a human-led API/portal private beta, candidate v0.4.0-beta.1, forecast for 21 November 2026. The tag/release has not been created.

Approved architectural roadmap · System architecture · ADRs

Privacy and security

Independent deployers control their own Tocyn environments and data. The project does not automatically receive application-level data from those deployments. Future FidesLang privacy metadata is planned under roadmap issues #16/#17 and is not currently implemented in main.

Repository privacy policy · Security policy · Privacy architecture · GDPR deployer technical guide

Contribute or contact the project

For normal bugs/features, prefer GitHub Issues or Discussions. Security vulnerabilities must use the private route in SECURITY.md.

Do not submit credentials, tenant/customer data, ticket exports or vulnerability details through this public form. The form is delivered through Web3Forms and uses hCaptcha; see the privacy policy.