Arcjet logo

Arcjet

Runtime security for AI apps and agents, running inside your application

Overview

About Arcjet

Arcjet is a runtime security layer that runs inside your application rather than at the edge. You call it from your own code, at the point where a decision is being made, so it can see the request, the user, the model output and the tool call being attempted, rather than inferring intent from an HTTP envelope. For conventional web applications that means bot protection, rate limiting, a Shield WAF, signup form protection and email validation. For AI applications it means prompt injection detection, sensitive-information and PII blocking, content moderation, and guards on tool and database calls made by an agent.

The in-application model is the real architectural difference, and it is worth being precise about why it matters. An edge WAF sees traffic; it does not see which authenticated user is attached to a request, which prompt is about to go to a model, or which tool an agent is about to invoke with what arguments. Arcjet sits where that context exists. It ships native SDKs for fifteen web frameworks (Next.js, Express, Fastify, NestJS, Hono, Remix, SvelteKit, Nuxt, Astro, Deno, Bun, React Router, Node.js, Flask and FastAPI) and integrates with fifteen agent frameworks including the Claude Agent SDK, LangChain, LangGraph, CrewAI, Mastra, Google ADK, OpenAI Agents, Strands Agents and the Vercel AI SDK. The SDKs are Apache-2.0 on GitHub; the service behind them is proprietary and billed on usage. Pricing is published end to end, including the per-million usage rates and what happens when you stop paying, which is rarer than it should be.

Pricing

Free tier
  • Free$0/mo
  • Individual$25/mo
  • Startup$299/mo
  • EnterpriseContact sales

From the vendor pricing page, 2026-10-09

Details

GitHub Stars 689
Forks 33
Data from: GitHub • Website•Updated: Oct 9, 2026
infrastructuredevopsdeploymentruntime-security