Pockets
Pockets - a bookmarking system with a Chrome extension, a Cloudflare Workers and D1 API, and a Next.js reading list with search, comments, an RSS feed and weekly newsletter digests.
- Pet Project
- Bookmarks
- Chrome Extension
- Cloudflare
Pockets is my own bookmarking system. When I find something worth reading, I save it from the browser in one click. It then shows up on pockets.msar.me, a public reading list where anyone can search my saved links and discuss them.
At a glance
- Role: Solo developer. I designed and built all three parts.
- Parts: a Chrome extension, an API with its own dashboard, and the public reading list
- Stack: Cloudflare Workers, D1, KV, Hono, Next.js 16, React 19, TypeScript, Tailwind CSS
- Live: pockets.msar.me · Extension · API
The problem
Browser bookmarks pile up in folders and never get read. Read-later services lock your links into their own app. I wanted:
- one click to save the page I'm on, without leaving it
- a store I own and can reach over a simple REST API
- a clean public page where my saved links can be searched, shared and discussed
How it fits together
Chrome extension: A Manifest V3 extension written in plain JavaScript. Save the current page from the toolbar popup or from the right-click menu on any page or link. A notification confirms the save. The API key and project ID stay in chrome.storage.
Pockets API: An API on Cloudflare Workers built with Hono, with its data in D1. Anyone can register a project with an email and a unique project slug, and gets back an API key. The API manages saved items and their comments. It ships with a React dashboard, served by the same Worker, for managing items and comments.
Reading list: A Next.js site that lists every saved link with search, a detail page and a comment thread ("Discuss") for each link. It also has an RSS feed and a PIN-protected /hq page for adding links by hand.
Signals: A weekly newsletter digest I generate from my inbox and publish to Drop Share. The /signals page pulls in the latest issue and lets you browse earlier ones.
Technical details
API keys done safely. Keys are 160 bits of random data, and the database stores only a SHA-256 hash, so a leaked database doesn't leak working keys. A key is shown once, when the project is created. A lost key can be reset by email through Cloudflare Email Service.
Abuse protection on the edge. Registration and key resets are rate-limited per IP with a fixed-window counter in Workers KV. Signup can also be protected with Cloudflare Turnstile.
Data that cleans up after itself. Items and comments are scoped by project slug, and slugs are unique within a project. Comments reference their item through a composite foreign key that cascades on delete, so deleting a link also deletes its discussion.
Fast pages without a database on every request. The Next.js API routes cache responses with time-based revalidation: 60 seconds for links, 30 for comments and an hour for the RSS feed. A revalidation endpoint can refresh a path or tag on demand.
Input validation at the edge. Every request body is validated with Zod before it reaches D1. List endpoints are paginated.
Why it matters
Pockets covers the whole route of a link: saved in the browser, stored behind a small authenticated API, and published on a public reading list. Everything runs on Cloudflare's free tier, plus the hosting for the Next.js site.

Technologies
Gallery







