Live data from Hacker News

Cloudlflare builds OAuth with Claude and publishes all the prompts

github.com

251–260 of 552 posts

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#251

On the one hand, I would expect LLMs to be able to crank out such code when prompted by skilled engineers who also understand prompting these tools correctly. OAuth isn’t new, has tons of working examples to steal as training data from public projects, and in a variety of existing languages to suit most use cases or needs. On the other hand, where I remain a skeptic is this constant banging-on that somehow this will…

I like to make a rough analogy with autonomous vehicles. There's a leveling system from 1 (old school cruise control) to 5 (full automation):

* We achieved Level 2 autonomy first, which requires you to fully supervise and retain control of the vehicle and expect mistakes at any moment. So kind of neat but also can get you in big trouble if you don't supervise properly. Some people like it, some people don't see it as a net gain given the oversight required.

^ This is where Tesla "FSD beta" is at, and probably where LLM codegen tools are at today.

* After many years we have achieved a degree of Level 4 autonomy on well-trained routes albeit with occasional human intervention. This is where Waymo is at in certain cities. Level 4 means autonomy within specific but broad circumstances like a given area and weather conditions. While it is still somewhat early days it looks like we can generally trust these to operate safely and ask for help when they are not confident. Humans are not out of the loop.[1]

^ This is probably what where we can expect codegen to grow after many more years of training and refinement in specific domains. I.e. a lot of what CloudFlare engineers did with their prompt engineering tweaking was of this nature. Think of them as the employees driving the training vehicles around San Francisco for the past decade. And similarly, "L4 codegen" needs to prioritize code safety which in part means ensuring humans can understand situations and step in to guide and debug when the tool gets stuck.

* We are still nowhere close to Level 5 "drive anywhere and under any conditions a human can." And IMHO it's not clear we ever will based purely on the technology and methods that got us to L4. There are other brain mechanisms at work that need to be modeled.

[1] https://www.cnbc.com/2023/11/06/cruise-confirms-robotaxis-re...

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#252
post #189

Earlier quoted context omitted.

> Vibe-coding won't be a net creativity gain to a researcher affected by vibe-immigration-policy, vibe-grant-availability, and vibe-firings, for all of which the unpredictability is a punitive design goal. Quite literally this is what I’m trying to get at with my resistance to LLM adoption in the current environment. We’re not using it to do hard work, we’re throwing it everywhere in an intentional decision to dumb d…

This is one of the best comments about the current AI hype. The elite really don't see why the proletariat should be interested in, or enjoy the dignity of, actual skill and quality. Hence the enshitification of everything, and now AI promises to commoditize everything into slop. Sad because it is the very deoth of society that has birthe

This could be a comment about the industrial revolution.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#253

Earlier quoted context omitted.

> can't just rewind and rerun and get to the same point again Why would you want to? The whole point of a retry is that your previous conversation attempt went poorly.

Good engineering? You want automated steps to be repeatable so you know your tweak to the previous conversation have the effect you desire. Though using an AI for coding is probably closer in spirit the the art of writing code than the engineering of writing code and art is pretty much unrepeatable by definition.

Fair enough. Use the respective API or Google Gemini which will let you set temperature to zero resulting in deterministic output barring FP errors accumulating when paired with non-standard GPU/TPU configurations. Likely not to differ by much in the vast majority of cases though.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#254
post #246
post #188

Earlier quoted context omitted.

Sure. Here's something I'd written on the subject that I'd left lying in my drafts folder for a month, but I've now published just for you :) https://www.snellman.net/blog/archive/2025-06-02-llms-are-ch... It has links to public sources on the pricing of both LLMs and search, and explains why the low inference prices can't be due the inference being subsidized. (And while there are other possible explanations, it inc…

Thanks for sharing! It's worthwhile to note that https://github.com/deepseek-ai/open-infra-index/blob/main/20... shows cost vs. theoretical income . They don't show 80% gross margins and there's probably a reason they don't share their actual gross margin. OpenAI is the easiest counterexample that proves inference is subsidized right now. They've taken $50B in investment; surpassed 400M WAUs ( https://www.reuters.com…

Thanks,

I believe the API prices are not subsidized, and there's an entire section devoted to that. To recap:

1) pure compute providers (rather than companies providing both the model and the compute) can't really gain anything from subsidizing. That market is already commoditized and supply-limited.

2) there is no value to gaining paid API market share -- the market share isn't sticky, and there's no benefit to just getting more usage since the terms of service for all the serious providers promise that the data won't be used for training.

3) we have data from a frontier lab on what the economics of their paid API inference are (but not the economics of other types of usage)

So the API prices set a ceiling on what the actual cost of inference can be. And that ceiling is very low relative to the prices of a comparable (but not identical) non-AI product category.

That's a very distinct case from free APIs and consumer products. The former is being given out for no cost in exchange for data, the latter for data and sticky market share. So unlike paid APIs, the incentives are there.

But given the cost structure of paid APIs, we can tell that it would be trivial for the consumer products to be profitably monetized with ads. They've got a ton of users, and the way users interact with their main product would be almost perfect for advertising.

The reason OpenAI is not making a profit isn't that inference is expensive. It's that they're choosing not to monetize like 95% of their users, despite the unit economics being very lucrative in principle. They're making a loss because for now they can, and for now the only goal of their consumer business is to maximize their growth and consumer mindshare.

If OpenAI needed to make a profit, they would not raise their prices on things being paid for. They'd just need to extract a very modest revenue from their unpaid users. (It's 500M unpaid users. To make $5B/year in revenue from them, you'd need just a $1 ARPU. That's an order of magnitude below what's realistic. Hell, that's lower than the famously hard to monetize Reddit's global ARPU.)

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#255
post #97

Earlier quoted context omitted.

It's said that much of research is data janitorial work, and from my experience that's not just limited to the machine learning space. Every research scientist wishes that they had an army of engineers to build bespoke tooling for their niche, so they could get back to trying ideas at the speed of thought rather than needing to spend a day writing utility functions for those tools and poring over tables to spot anoma…

> Vibe-coding won't be a net creativity gain to a researcher affected by vibe-immigration-policy, vibe-grant-availability, and vibe-firings, for all of which the unpredictability is a punitive design goal. Quite literally this is what I’m trying to get at with my resistance to LLM adoption in the current environment. We’re not using it to do hard work, we’re throwing it everywhere in an intentional decision to dumb d…

This is a bit stronger than my point, I should say. I do think that LLMs would have a net benefit to society, by way of their effects on research and innovation... if we could get our political houses in order such that we weren’t negating those effects, and such that we were empowering small businesses and high-tech startups to build with the results of this innovation sustainably.

And in a world where policy is horrid and the effects are mainly negated, things would be even worse if the remaining researchers lost AI as a tool. For better or for worse, fire has been shared with humanity, and we might as well cook.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#256

Earlier quoted context omitted.

Yep, and it allows them to build POCs that they can pass to "real" devs in a way that was not possible before.

Real devs excel at writing software for hundreds, thousands, millions of users with fractal use cases and feature needs. LLMs excel at writing software for one or a handful of users with a very narrow but very well defined use cases. I don't need an LLM to write Excel.exe for keeping track of 20 employee's hours. A simple GUI on a SQLite database can easily do that.

Yes!

We're about to enter a world where everyone has their own custom software for their specific use cases. Each of these is relatively simple, yet they may replace something complex. Excel is complex because it needs to handle everyone's use cases, but for any one particular spreadsheet, you could pretty easily vibe-code a replacement that does that one spreadsheet's job better than Excel can.

I've also found that vibe-coding a presentation as a React app is better than using Power Point.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#257
post #97

Earlier quoted context omitted.

It's said that much of research is data janitorial work, and from my experience that's not just limited to the machine learning space. Every research scientist wishes that they had an army of engineers to build bespoke tooling for their niche, so they could get back to trying ideas at the speed of thought rather than needing to spend a day writing utility functions for those tools and poring over tables to spot anoma…

> much of research is data janitorial work In applied research perhaps, Fundamental research is nothing like that in any field including ML.

All experimental or empirical research is like that, is closer to the point.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#258
Some examples of prompt exchanges that seem representative:

https://claude-workerd-transcript.pages.dev/oauth-provider-t... ("Total cost: $6.45")!

https://github.com/cloudflare/workers-oauth-provider/commit/...

https://github.com/cloudflare/workers-oauth-provider/commit/...

The first transcript includes the cost, would be interesting to know the ballpark of total Claude spend on this library so far.

--

This is opportune for me, as I've been looking for a description of AI workflows from people of some presumed competency. You'd think there would be many, but it's hard to find anything reliable amidst all the hype. Is anyone live coding anything but todo lists?

antirez: https://antirez.com/news/144#:~:text=Yesterday%20I%20needed%...

tptacek: https://news.ycombinator.com/item?id=44163292

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#259
> I thoughts LLMs were glorified Markov chain generators that didn't actually understand code and couldn't produce anything novel.

so he's been convinced by it shitting out yet another javascript oauth library?

this experiment proves nothing re: novelty

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#260

On the one hand, I would expect LLMs to be able to crank out such code when prompted by skilled engineers who also understand prompting these tools correctly. OAuth isn’t new, has tons of working examples to steal as training data from public projects, and in a variety of existing languages to suit most use cases or needs. On the other hand, where I remain a skeptic is this constant banging-on that somehow this will…

I like to make a rough analogy with autonomous vehicles. There's a leveling system from 1 (old school cruise control) to 5 (full automation): * We achieved Level 2 autonomy first, which requires you to fully supervise and retain control of the vehicle and expect mistakes at any moment. So kind of neat but also can get you in big trouble if you don't supervise properly. Some people like it, some people don't see it as…

That's a good analogy. OAuth libraries and integrations are like a highly-mapped California city. Just because you can drive a Waymo or coding agent there, doesn't mean you can drive it through the Rockies.
Post reply on HN