
Arcjet
Runtime security for AI apps and agents, running inside your application
About Arcjet
Arcjet is a runtime security layer that runs inside your application rather than at the edge. You call it from your own code, at the point where a decision is being made, so it can see the request, the user, the model output and the tool call being attempted, rather than inferring intent from an HTTP envelope. For conventional web applications that means bot protection, rate limiting, a Shield WAF, signup form protection and email validation. For AI applications it means prompt injection detection, sensitive-information and PII blocking, content moderation, and guards on tool and database calls made by an agent.
The in-application model is the real architectural difference, and it is worth being precise about why it matters. An edge WAF sees traffic; it does not see which authenticated user is attached to a request, which prompt is about to go to a model, or which tool an agent is about to invoke with what arguments. Arcjet sits where that context exists. It ships native SDKs for fifteen web frameworks (Next.js, Express, Fastify, NestJS, Hono, Remix, SvelteKit, Nuxt, Astro, Deno, Bun, React Router, Node.js, Flask and FastAPI) and integrates with fifteen agent frameworks including the Claude Agent SDK, LangChain, LangGraph, CrewAI, Mastra, Google ADK, OpenAI Agents, Strands Agents and the Vercel AI SDK. The SDKs are Apache-2.0 on GitHub; the service behind them is proprietary and billed on usage. Pricing is published end to end, including the per-million usage rates and what happens when you stop paying, which is rarer than it should be.
You install the SDK for your framework and call protect() at the points you want defended: a route handler, a signup endpoint, a model call, an agent tool invocation. Each call carries the context your application already has, so a rule can depend on the authenticated user rather than only the IP address. The call returns a decision your code acts on, which means you decide what blocking looks like rather than having a proxy return an opaque 403. Rules can be run in dry-run mode first, so you can see what would have been blocked before anything actually is. Every protect() call counts as one web request for billing, with rate limit, filter and Shield WAF rules all included in that single call; protecting a coding agent or a custom agent counts as an agent request instead, billed at a higher rate. Budget thresholds can be set to avoid surprises, and the free plan stops at a hard cap rather than spilling into metered overage.
- •Prompt Injection Detection - Inspects input bound for a model and flags injection attempts before the prompt is sent, rather than after the model has acted on it.
- •Tool and Database Call Guards - Authorises the actions an agent is about to take, which is the control that matters once an agent can spend money or write to a database.
- •Sensitive Information and PII Blocking - Detects and redacts sensitive data in transit, with content moderation alongside it.
- •Bot Protection, Rate Limiting and Shield WAF - The conventional web application layer, driven by your application's own context rather than by request headers alone.
- •Fifteen Web SDKs and Fifteen Agent Framework Integrations - Native support across the JavaScript and Python web ecosystem and the major agent frameworks, rather than one SDK and a list of intentions.
- •Fully Published Pricing - Every tier, the per-million usage rates, and a hard-capped free plan that is never billed for overage, all stated on the pricing page.
Arcjet fits developers putting an AI feature or an agent into production in a JavaScript or Python application, particularly where the agent can call tools, touch a database or spend money. It is a good fit for teams who want security decisions in their own code and their own repository, reviewable in a pull request, rather than configured in a separate console. Open source projects are explicitly welcomed on the Individual plan at discounted or free pricing.
Two things argue against it. The directory already carries HOL Guard, an open source runtime security layer for AI coding agents, which overlaps the agent half of Arcjet directly and is open source where Arcjet is not: only the SDK is Apache-2.0, at around 689 stars, and the service behind it is closed. And the economics deserve a look before committing. $50 per million agent requests is not cheap once an agent is chatty, and while the FAQ defines a web request precisely as any protect() call, what exactly constitutes one agent request is described less tightly. If you need a self-hostable, fully open source control, this is not it.
Pricing
- Free$0/mo
- Individual$25/mo
- Startup$299/mo
- EnterpriseContact sales
From the vendor pricing page, 2026-10-09













