Arcjet vs Aikido
Aikido Security is a developer security platform: code, dependency, secrets, and cloud scanning, AI pentesting, and Zen, an in-app firewall that instruments your runtime to block injection attacks, bots, and abusive traffic. Arcjet is an AI agent runtime security platform that enforces policy in the path of the action: a library you import for HTTP routes and custom agents, and policy in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code that decides before each tool call runs.
The key difference is timing and scope. Aikido finds vulnerable code and malicious packages before they ship and Zen blocks injection-shaped HTTP attacks, while Arcjet decides on what your agents and your developers' coding agents do while they run. Choose Aikido when you want one vendor for code and cloud scanning plus a runtime firewall agent for seven languages. Choose Arcjet when you want security rules in code with user and route context, and runtime policy on agent actions.
Arcjet publishes this comparison. Competitor details come from Aikido's public documentation, reviewed on September 25, 2026. Products change, so check the linked sources before you decide.
How does Aikido Zen differ from Arcjet?
Aikido Zen and Arcjet both run inside your application, but Zen instruments your runtime while Arcjet is a library you call. Zen instruments key packages and built-in modules in your runtime, such as fs.readFile, http.request, fetch, and database clients, and you load Zen with a preload flag. Arcjet is a library that you import and call next to your application logic, so each Arcjet rule can branch on user, plan, route, or any other value as ordinary code.
Zen's feature set covers injection attacks and path traversal; rate limiting by route and user; blocking of bots, Tor, and known threat actors; country blocking; and outbound traffic monitoring. The Zen Node.js README lists seven attack types: NoSQL injection, SQL injection, command injection, prototype pollution, path traversal, SSRF, and JavaScript injection.
Arcjet covers bots, Shield WAF, rate limiting, email validation, filters, and IP checks in request handlers. On agent tool calls and jobs, Arcjet covers prompt-injection detection, token budgets, sensitive-information checks, and destination threat analysis. On coding agents, Arcjet enforces one policy across five vendors.
Integration
You define Arcjet's app-specific rules in code, review them in pull requests, and version them with the feature. Operational Arcjet remote rules – a global bot category, a temporary site-wide rate limit, a country or IP filter, Shield WAF – change in the Arcjet Console, CLI, or MCP server without a redeploy, and still enforce inside the application.
Aikido Zen is configured with environment variables, such as AIKIDO_TOKEN and AIKIDO_BLOCK, and the Aikido dashboard. According to the Zen README, Zen runs in detection mode until you turn on blocking.
Framework, runtime, and language support
Arcjet's SDKs are JavaScript, TypeScript, Python, and Go, with framework support including Next.js, Node.js, Bun, Deno, FastAPI, and Flask. Aikido Zen has agents for seven languages – Node.js, Python, PHP, Java, .NET, Ruby, and Go – which is a wider language surface, and Aikido's getting-started page labels Go as beta.
On Next.js, Zen runs with standalone output, and "user-based rate limiting and manual user blocking are not supported because setUser is not supported in this setup." Zen supports ESM with a -r @aikidosec/firewall/instrument preload, and Aikido documents that Zen "can not protect ESM sub-dependencies of an ESM package."
Local-only versus local-first
Aikido states that Zen does "not send any data back to the cloud to do security checks," and Zen reports detected attacks to the dashboard. Arcjet evaluates locally first with a WebAssembly engine, then uses the Arcjet Cloud API where it needs cross-request state or reputation: rate-limit counters, bot reputation, and prompt-injection detection. Arcjet sensitive-information detection can stay in your process, with a built-in local engine plus an optional on-device ML model.
Bot detection
Zen's bot protection matches a list of user agent strings, alongside IP, Tor, and country controls from the dashboard. Arcjet bot detection in request handlers uses request context, optional advanced client signals collected in the browser, and live or dry-run rollout. Aikido's public documentation doesn't describe client-side signal collection for Zen.
Aikido and Arcjet at a glance
The following table compares Aikido and Arcjet across 12 areas, from product scope to hosting.
| Area | Arcjet | Aikido |
|---|---|---|
| Product scope | AI agent runtime security plus application security: HTTP rules, agent tool-call policy, and coding-agent hooks. | Developer security platform: SAST, SCA, secrets, IaC, cloud, and container scanning, AI pentesting, and the Zen runtime firewall. |
| Coding agents | One policy across Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code from their hooks: destructive commands, protected paths, credential access, MCP and egress allowlists, and destination threats, decided before the tool call runs. | Aikido MCP scans AI-generated code for vulnerabilities and secrets. Safe Chain and Aikido Endpoint block malicious packages and risky installs. |
| Custom agents |
| Zen tracks LLM usage : models, input and output tokens, and cost estimates. Blocking a tool call isn't documented. |
| Languages | JavaScript, TypeScript, Python, and Go. | Node.js, Python, PHP, Java, .NET, Ruby, and Go (labeled beta), each with its own agent. |
| Integration model | A library that you import and call. Rules can branch on any request or tool context. | An agent that instruments packages and built-in modules. Policy is mostly dashboard and environment variables. |
| Runtime and module system | ESM in JavaScript, including edge runtimes. | CommonJS, and ESM with a preload. ESM sub-dependencies of ESM packages aren't protected. |
| Bot protection | Known bots by name and category, optional advanced client signals, and filter rules. | User agent list plus IP, Tor, and country controls. |
| Rate limiting | Per route, user, account, or any key in code, with fixed-window, sliding-window, and token-bucket algorithms. | Route and user limits from the dashboard. User-based limits aren't supported on Next.js. |
| WAF and attack coverage | Shield WAF in request handlers. | In-process detection of SQL, NoSQL, command, and JavaScript injection, path traversal, SSRF, and prototype pollution. |
| Data handling | Local-first. Sensitive information can stay in your process. Some rules call the Cloud API with request metadata. | Security checks run locally. Attack data is reported to the Aikido dashboard. |
| Evidence | Every decision and agent session in the Arcjet Console. SIEM export to Datadog, Splunk, SentinelOne, Panther, and Amazon S3 on Enterprise. | Attack events in the Aikido dashboard. |
| Hosting | Any host. | Any host where the agent can run. Next.js in standalone mode. |
How do Aikido and Arcjet handle AI agents?
Aikido's AI-related products work at build time, install time, and on inbound HTTP, while Arcjet works on the agent's action at runtime. The Aikido MCP plugin scans code that Claude Code, Cursor, Codex, Copilot, and other assistants generate for vulnerabilities and hardcoded secrets. Safe Chain and Aikido Endpoint, launched April 20, 2026, block malicious packages, IDE extensions, and other risky installs. Zen protects the running application from injection-shaped HTTP attacks and tracks LLM token usage.
In a coding agent, the Arcjet policy runs on the hook the agent fires before a tool call. The policy can deny rm -rf, a git push --force, a read of ~/.aws/credentials, a piped installer, or a fetch to a host that Arcjet threat intelligence scores as high risk, before the tool runs. You install Arcjet through managed settings so that developers can't remove it without admin access.
Each vendor sets the limits of its hook: Claude Code and Copilot HTTP hooks fail open by vendor design, and Cursor and Codex use a fail-closed command wrapper. For more information, see how to secure AI coding agents and malware downloads by coding agents.
In your own agents, Arcjet takes the tool or job input through guard() and returns a decision before the side effect. Prompt-injection detection, token budgets, and sensitive-information checks run there, and labeled Guard policies let a security team change the policy for a labeled action without changing the tool.
When an Arcjet Guard check can't finish, the direct Guard client returns allow with an error result, and hasFailedOpen() lets your code refuse the action. For more information, see the Guards reference.
Scanning and runtime policy cover different moments. Scanning catches a vulnerable line before it merges and a malicious package before it installs. Runtime policy catches the destructive command, the credential read, or the injected instruction while the agent is running.
Which fits: Aikido, Arcjet, or both?
Choose Aikido for scanning plus a runtime firewall agent for seven languages, Arcjet for security as code and runtime policy on agents, and both when you want scanning and runtime policy together. The following sections describe the fit for each product.
Choose Arcjet
Choose Arcjet if any of the following apply:
- You want policy on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code tool calls, enforced before the tool runs.
- You're building agents that need prompt-injection detection, token budgets, and sensitive-information checks on tool inputs.
- Your core stack is JavaScript, TypeScript, Python, or Go, and you want a library rather than a runtime agent.
- You want security as code next to auth and billing, including user-keyed rate limits on Next.js.
- You need bots, rate limits, Shield WAF, and email validation in one SDK.
Choose Aikido
Choose Aikido if any of the following apply:
- You want one vendor for SAST, dependency, secrets, and cloud scanning, with Zen as the runtime module.
- You have services in PHP, Java, .NET, or Ruby and want the same firewall agent on all of them.
- You want runtime injection protection with minimal code changes.
- You want install-time malware blocking for packages on developer machines.
Use both
Arcjet is a normal library and Aikido Zen is a runtime agent, so both can run in the same application. A common split is Aikido for code and dependency scanning and Zen on non-JavaScript services, with Arcjet for application rules, agent tool calls, and coding-agent policy.
What are the alternatives to Aikido?
The alternatives to Aikido depend on which part of the platform you're replacing: the runtime firewall, AI agent runtime security, or application security testing. The following products cover overlapping ground:
- Arcjet: runtime policy for coding agents and custom agents, plus bots, rate limits, and Shield WAF in your code.
- Rein: another in-code approach to AI agent runtime security.
- Datadog App and API Protection: runtime application protection inside the Datadog platform.
- Contrast Security: application security testing and runtime protection.
For a broader view, see AI agent security platforms.
Frequently asked questions
What is the difference between Arcjet and Aikido?
Aikido is a developer security platform: code, dependency, secrets, and cloud scanning, AI pentesting, and Zen, a runtime firewall agent that instruments your application to block injection attacks, bots, and abusive traffic. Arcjet enforces policy in the path of the action: a library you import for HTTP rules and custom-agent tool calls, and policy in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code that decides before each tool call runs.
Is Arcjet an alternative to Aikido?
Arcjet is an alternative to Aikido Zen for JavaScript, TypeScript, Python, and Go applications: bots, rate limiting, Shield WAF, and email validation as code, including user-keyed rate limits on Next.js. Arcjet isn't a code or dependency scanner, so teams that want SAST and SCA keep a scanning product such as Aikido alongside Arcjet.
Can you use Aikido and Arcjet together?
Yes. Arcjet is a normal library and Zen is a runtime agent, so both can run in one application. A common split is Aikido for code and dependency scanning and Zen on PHP, Java, .NET, or Ruby services, with Arcjet for application rules, agent tool calls, and coding-agent policy.
Does Aikido secure AI coding agents?
Aikido secures the code and packages around coding agents, not their tool calls. Aikido documents an MCP plugin that scans code generated by assistants such as Claude Code and Cursor for vulnerabilities and secrets, and Safe Chain and Aikido Endpoint, which block malicious packages and risky installs. Arcjet enforces policy on the agent's tool calls from its hooks, so Arcjet can deny a destructive command, a credential read, or a fetch to a high-risk host before the tool runs.
How is Aikido priced compared with Arcjet?
Aikido and Arcjet both publish plan tiers. Aikido's pricing page lists tiers from a free Developer plan to custom Enterprise pricing. Arcjet has Individual ($25 per month), Startup ($299 per month), and custom Enterprise plans, with usage at $5 per million web requests and $50 per million agent requests.
AI runtime security in your code
Protect your AI agent workflows with Arcjet
Arcjet runs inside your application, where it can use runtime context to enforce agent actions and budgets, detect prompt injection, and protect sensitive information before a workflow acts.