Get Started
Quick Start
Studio and the public website are separate deployments. Install Studio first, then connect a site repository or download Preview Data for your own build.
1. Check the deployment prerequisites
Deploy Studio from its repository, using the Deploy to Cloudflare button or the documented build and deploy commands. Local builds require Node.js 22.22.0 or newer.
Cloudflare creates or connects all resources declared in wrangler.jsonc before deploying the Worker. A provisioning failure stops deployment, even when the associated product feature is optional. The default configuration includes dedicated Studio D1 and KV, Edge D1 and KV, and Media R2 bindings. For an existing Edge installation, select its matching D1 and KV resources. Keep the resource identifiers written back to the deployment repository.
2. Deploy the initial configuration
After deploying the Worker, configure these values in Cloudflare and apply the configuration:
| Setting | Storage | Value |
|---|---|---|
STUDIO_SITE_MODE |
Plaintext Variable | initial |
STUDIO_AUTH_SECRET |
Secret | A stable, independent random value |
STUDIO_INSTALL_TOKEN |
Secret | A separate temporary random value |
Both Secrets require 32–256 printable ASCII characters, without spaces. The installation screen can generate values locally in your browser. You can also run openssl rand -hex 32 separately for each value. Keep STUDIO_AUTH_SECRET for the lifetime of the installation; it protects encrypted MFA and service credentials.
Open Studio with an uninstalled Studio database to start installation. See Worker Secrets for storage, local development, and replacement procedures. Operations credentials are not needed for installation.
3. Create the first administrator
Enter the installation token, administrator identity, and a password of 15–256 characters. Studio checks account-related and common passwords and, in a deployed Worker, checks for known password breaches. See Authentication for the policy.
Every account must register a TOTP authenticator. Scan the QR code, confirm a current code, and complete installation. Studio creates the administrator and MFA factor together; it does not create a password-only administrator.
The installer also inspects the Edge database:
| Edge state | Result |
|---|---|
| Empty application catalog with Edge KV available | Initialize Edge and enable Studio’s Edge integration |
| Non-empty application catalog | Preserve it and start with Edge integration disabled |
| Required binding unavailable or initialization fails | Stop installation |
The TOTP code used to complete installation is consumed. If the authenticator still displays that code at sign-in, wait for the next code. See TOTP Verification.
4. Activate the installed Studio
Installation does not change Worker configuration. In Cloudflare:
- Delete the
STUDIO_INSTALL_TOKENbinding. An empty value still counts as configured and blocks normal access. - Set
STUDIO_SITE_MODE=operationaland apply the configuration. - Keep the existing
STUDIO_AUTH_SECRET. - Sign in with the administrator password and a new TOTP code.
You can then register a Passkey as another sign-in method.
5. Configure the first site
In Site Settings, set the public site URL, title, locale, and time zone. The public URL is the website address, not Studio’s administration address. Review routing and media delivery before importing or publishing content.
Create content in Studio or follow WordPress Migration. Configure Edge services if the public site needs comments, forms, or newsletters. These services have their own runtime settings.
6. Publish the public site
For a new public site, deploy Studio Starter. Its Deploy to Cloudflare button creates a repository and deploys a sample site.
- Copy the GitHub URL of the repository’s
zeropress-preview-data.jsonfile. - In Studio’s Site Settings → Publishing, connect that file, create a repository-scoped token, check the connection, enable publishing, and save.
- Save a Post with Published status.
- Open Publish site, select Prepare data, and review the result.
- Select Publish to GitHub and confirm the target. Check the hosting provider’s build result for the public deployment.
GitHub publishing is optional. Prepare data also supports copying and downloading validated JSON for a separate build. Draft and Trash content is not exported. Studio does not implement scheduled publishing.
Read Publishing for preparation and delivery, or GitHub Publishing for change detection and conflict handling. Keep the MFA recovery paths and Operations requirements available for account recovery and future database upgrades.