Kenton Varda
Kenton Varda is a software engineer and the creator and tech lead of Cloudflare Workers. While at Google he was the primary author of Protocol Buffers version 2 and open-sourced it; after leaving Google he created the serialization and RPC system Cap’n Proto and co-founded the self-hostable app platform Sandstorm.
Contents17 sections
Key facts
2005–2013Working at Google
From 2005 to 2013, Varda worked at Google, where he worked on infrastructure for Universal Search as well as sharing and access control for Google Drive, but his best-known work was on Protocol Buffers.[1]
Protocol Buffers is a serialization protocol that originated at Google. Varda recalled that early in his time at Google he took an interest in the project and began adding features to it; as the company grew and it became difficult to maintain with every team adding what it needed, people started looking to him to maintain the project, and he then proposed open-sourcing it. Because the version 1 code base was tightly tied to many other internal Google libraries, he rewrote it; at Google he was the tech lead for the project.[2][2][2][2][2][2]
July 7, 2008Open-Sourcing Protocol Buffers
On July 7, 2008, Varda announced on the Google Open Source Blog that Google was making Protocol Buffers available to the open source community. By design, developers define data structures in a special definition language and then compile them into classes in the language of their choice; these classes carry highly optimized parsing and serialization code and are at least an order of magnitude faster than XML. The version released as open source was version 2, of which he was the primary author.[3][3][3][3][4]
April 1, 2013Releasing Cap’n Proto
In 2013, Varda left Google to start a startup. He said that at Google the basic underlying encoding of Protocol Buffers could not be changed, because the company held petabytes of data in that format; after leaving he was free to try an entirely new format. On April 1, 2013, he released Cap’n Proto, writing that he “may have rewritten Protocol Buffers. Again.”[2][2][2][5]
Cap’n Proto is a data interchange format and a capability-based RPC system. Its encoding is also its in-memory representation, so there is no encoding or decoding step; the encoding is defined byte for byte independent of any platform, and accessors validate pointers when reading. It was originally built for Sandstorm and is now heavily used at Cloudflare.[4][4][4][4][4]
2014–2016Co-Founding Sandstorm
From 2014 to 2016, Sandstorm was a startup of which Varda was co-founder and technical lead; its co-founders also included Jade Wang. Sandstorm is a self-hostable web productivity suite that isolates each app through fine-grained containerization, and Cap’n Proto’s object-capability RPC system became the basis of the platform.[6][1][1][7][8][1]
Looking back, Varda wrote that Sandstorm ran a successful crowdfunding campaign in 2014 and raised venture capital in early 2015, growing to a team of seven. It had aimed for a Series A round in 2016, but investors were not interested; the company turned to enterprise sales, making only two sales ever, for a mere four figures.[6][6][6]
February 6, 2017Sandstorm Becomes a Community Project
On February 6, 2017, Varda announced that Sandstorm the business had run out of money and had been unable to raise more. Sandstorm would no longer operate as a for-profit startup but would continue as a community-driven open source project; the managed hosting service Sandstorm Oasis would keep running, and he personally would continue to lead its technical development. He attributed the failure to the product still being alpha-quality and to having underestimated the challenge of enterprise sales.[8][8][8][8][8][8][8]
March 13, 2017Joining Cloudflare
Starting March 13, 2017, most of the Sandstorm team, including Varda and Jade Wang, went to work for Cloudflare, while Sandstorm itself remained an independent entity. Varda joined the edge platform team and continued to work on Cap’n Proto; Cloudflare was already a big user of Cap’n Proto.[7][7][7][7][7]
Varda later recalled that by the end of 2016 the company was looking for an acquisition. Like others, Cloudflare offered to acquire the company for only $0, but it made job offers to the whole team and said it wanted to let people run code on its edge network and could give him ownership of that. He asked to keep Sandstorm the company and to continue developing it as an open source project, and Cloudflare agreed.[6][6][6][6]
September 29, 2017Previewing Cloudflare Workers
On September 29, 2017, Varda previewed Cloudflare Workers: developers would be able to write JavaScript against an API similar to Service Workers and deploy it to run on Cloudflare’s edge; at the time Cloudflare ran in 117 locations worldwide. The code is executed by the V8 engine from Google Chrome. He explained that security was one of the main reasons for choosing V8 and said Cloudflare had added its own layers of sandboxing on top of V8.[9][9][9][9][9]
Varda said the Workers project started from scratch when he joined Cloudflare and that he led it.[2]
March 13, 2018Workers Opens to Everyone
On March 13, 2018, Cloudflare Workers became available to all users. Varda wrote that exactly one year earlier Cloudflare had given him the mission of making it possible for people to run code on its edge; by then Workers had thousands of scripts deployed and had served many billions of requests, and a deployment reached Cloudflare’s entire network of over a hundred locations worldwide in under 30 seconds.[10][10][10]
July 29, 2020Explaining the Workers Security Model
On July 29, 2020, Varda described the security architecture of Workers, saying that the heart of Workers is a security project and that the team’s primary concern is running third-party code safely. The Workers runtime uses V8 isolates to separate different tenants’ code and can run many isolates in a single process; it takes measures against V8 bugs and Spectre-style attacks, including using process isolation as an extra line of defense.[11][11][11][11][11][11]
September 28, 2020Durable Objects Beta
On September 28, 2020, Varda announced the start of a closed beta of Durable Objects. Each Durable Object is an instance of a class with private state and a globally unique identifier, and exists in only one location at a time, giving edge applications strongly consistent state and real-time coordination between clients.[12][12][12][12]
September 27, 2022Open-Sourcing workerd
On September 27, 2022, Varda released the first beta of workerd, the JavaScript/Wasm runtime that powers Cloudflare Workers. It is open source under the Apache License 2.0 and can be used to self-host Workers applications, for local development and testing, and as a programmable proxy.[13][13][13][13][13]
July 28, 2023Cap’n Proto 1.0
On July 28, 2023, Varda released version 1.0 of Cap’n Proto’s C++ reference implementation, a little over ten years after the first release. He wrote that the new version contained little that was new and that he should have declared 1.0 long before; Cloudflare uses Cap’n Proto extensively and had adopted it before hiring him.[14][14][14]
January 14, 2024Stepping Down as Sandstorm Maintainer
On January 14, 2024, Varda announced that he was no longer the maintainer of Sandstorm; the project now belonged to a community of users led by Jacob Weisz and moved to a new domain, sandstorm.org. He explained that the Workers effort he led at Cloudflare was going well, making him essentially the founder of a successful startup within Cloudflare, and that it had become hard to put energy into Sandstorm.[6][6][6][6][6]
September 2025Cap’n Web and Code Mode
On September 22, 2025, Varda and Steve Faulkner released Cap’n Web, an RPC protocol implemented in pure TypeScript. Like Cap’n Proto it is an object-capability protocol, but it requires no schemas, its underlying serialization is based on JSON, and it is open source under the MIT license.[15][15][15][15][15]
On the 26th of the same month, he and Sunil Pai proposed Code Mode: converting MCP tools into a TypeScript API and having a large language model write code that calls that API rather than calling the tools directly; they found that agents could handle more, and more complex, tools this way.[16][16][16]
March 2026–April 2026Dynamic Workers and Durable Object Facets
On March 24, 2026, Varda, Sunil Pai, and Ketan Gupta released Dynamic Workers, which uses lightweight isolate sandboxes instead of containers to execute code generated on the fly by AI. On April 13, he released Durable Object Facets, which lets Dynamic Workers instantiate Durable Objects with their own SQLite databases for each AI-generated app.[17][17][17][18][18]
Related Organizations, Websites, and Public Accounts
Cap’n Proto: Official website: https://capnproto.org/ (opens in a new window).[4]
Sandstorm: Official website: https://sandstorm.org/ (opens in a new window).[6]
X: Public account: https://x.com/kentonvarda (opens in a new window)[9]
Sources
- About Sandstorm (opens in a new window)
- SED483 Protocol Buffers (opens in a new window)
- Protocol Buffers: Google's Data Interchange Format (opens in a new window)
- Cap'n Proto: Introduction (opens in a new window)
- Announcing Cap'n Proto (opens in a new window)
- Sandstorm now belongs to Sandstorm.org (opens in a new window)
- The Sandstorm Team is joining Cloudflare (opens in a new window)
- Sandstorm is returning to its community roots (opens in a new window)
- Introducing Cloudflare Workers: Run JavaScript Service Workers at the Edge (opens in a new window)
- Everyone can now run JavaScript on Cloudflare with Workers (opens in a new window)
- Mitigating Spectre and Other Security Threats: The Cloudflare Workers Security Model (opens in a new window)
- Workers Durable Objects Beta: A New Approach to Stateful Serverless (opens in a new window)
- Introducing workerd: the Open Source Workers runtime (opens in a new window)
- Cap'n Proto: News (opens in a new window)
- Cap'n Web: a new RPC system for browsers and web servers (opens in a new window)
- Code Mode: the better way to use MCP (opens in a new window)
- Sandboxing AI agents, 100x faster (opens in a new window)
- Durable Objects in Dynamic Workers: Give each AI-generated app its own database (opens in a new window)