Interactions for static sites.
Inside your Cloudflare account.
StaticLayer adds moderated comments, anonymous reactions and StrawPoll-style polls to any static website — no trackers, no comment SaaS, no third-party database. Deploy once into your Cloudflare account and the data is yours.
Owned by you — from first byte to final comment.
One widget. Three ways to engage.
Comments, reactions and polls share the same architecture: anonymous by default, proof-of-work protected, and running entirely inside your Cloudflare account.
Comments
Real conversations on static pages: moderated, nested, and safe by default — plain text only.
- Nested replies (up to 3 levels) + owner “Author” badge
- Likes, pin, report and newest / best sorting
- One moderation queue for all your pages
Reactions
Anonymous emoji counts with real integrity — every click pays a tiny proof-of-work.
- Cost-based anti-abuse, not identity
- Difficulty escalates as a page gets busy
- Fully themeable — choose the emoji set
Polls
StrawPoll-style votes embedded anywhere — even globally on every page of your site.
- No IP, no cookies, no identity
- Single or multi-select, ranked results + leader
- Optional one-vote-per-browser guard
Deploy. Embed. Moderate.
Three steps, about five minutes, and no dashboard clicking sprees. The hard part is done by the CLI or the hosted installer.
Deploy StaticLayer
One command (npx staticlayer init) or the hosted browser installer creates the Worker, the D1 database and the secrets — in your account.
Add the widget
Two lines of HTML on any static page. The same snippet works on every page — thread = page URL. Works with Astro, Hugo, Jekyll, Next.js, plain HTML…
Moderate & publish
Comments land in a private admin queue. Approve, delete or reply from /admin.html — readers see only what you publish.
Why not a traditional comment SaaS?
It comes down to one question: who controls the data?
A third-party platform in the middle
- Your site
- Third-party comment platform
- Their infrastructure
- Their policies & dependencies
Comments stay in your cloud
- Your site
- Your Cloudflare Worker
- Your D1 database
No third-party database
Comments live in the Cloudflare resources you control. There is no centralized comment platform.
Zero cookies, zero fingerprinting
The public widget does not use tracking cookies, local storage, fingerprinting or analytics.
Proof-of-Work + honeypot
Behavioural checks only — a tiny client-side puzzle, a hidden honeypot and a time gate. No friction for readers.
Four components. One owner: you.
Click each component to see what it does — and what it deliberately does not store.
Small surface. Explicit boundaries.
Designed with a minimal attack surface and defense-in-depth controls. No “military-grade” claims — inspect the code instead.
Explanatory checklist of designed behaviors — not a claim of perfect security. Read the full security model.
One widget. Every static site.
If it can embed JavaScript, it can use StaticLayer.
Alice · just now ❤️ 12