Oxbow runs your handlers in 34 regions, a few milliseconds from every user, and hands the slow work — charges, emails, webhooks, fan-out — to durable queues that retry until it is done. One deploy. Every hop traced.
Running the request path for 4,200 teams — from two-person startups to a payments network settling in eleven currencies.
The platform
Most outages are not in the handler. They are in the retry you forgot, the cron that ran twice, the webhook nobody traced. Oxbow ships the four together so the seams are ours to get right.
Edge functions
Write a function, export it, deploy. It runs in all 34 regions with the same code, the same secrets and the same logs — no per-region config to drift.
Durable queues
At-least-once delivery with idempotency keys, backoff and a dead-letter queue by default.
184k messages a second at peak, one customer, last Black Friday
Schedules
Not once per region, not twice after a failover. Leader-elected, logged and replayable.
Traces by default
The runtime writes the spans, so a trace follows a request from the edge through the queue into the consumer that finished the job — even when that was four retries and two hours later.
Cold starts
2.1ms
Median, TypeScript, measured from socket accept to first byte. Isolates are warmed on deploy, not on the first unlucky request.
Preview deploys
Data residency
Requests from anywhere still land at the nearest edge; the data never leaves the region you chose.
Write it, read it
Queues, retries and idempotency are arguments, not infrastructure. When a message takes a second attempt, the trace shows you both — and why the first one failed.
The network
Requests land at the nearest region and run there. Queue messages move between regions on our private backbone, so a consumer in São Paulo can finish what a request in Frankfurt started.
From the teams on call
−71% checkout p99
We moved checkout off three regional clusters and onto one deploy. The p99 dropped because the request stopped crossing an ocean, not because anyone tuned anything.
0 double charges since
The idempotency key is a queue option, so nobody has to remember it. Our worst incident last year was a retry storm. This year we have not had one.
4 min median time to cause
When a webhook fails at 3am, the trace already has the consumer, the retry and the upstream 503 in one view. On-call went from archaeology to reading.
Free to start
One million invocations and a hundred thousand queue messages a month on the free plan, no card. When you outgrow it, you pay for requests — never for idle.