Arcjet vs Cloudflare
Cloudflare runs security at the network edge: DDoS mitigation, the WAF, bot management, rate limiting, and AI Gateway as a proxy in front of model providers. Arcjet is an AI agent runtime security platform that enforces policy in the path of the action: in your application code for HTTP routes and custom agents, and in the hooks that Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code already fire, with no proxy to route traffic through. The key difference is where each one decides. Cloudflare decides on traffic routed through its network before it reaches your origin, and Arcjet decides inside your application and in the agent's hook. Choose Cloudflare for network-layer protection and traffic you already proxy. Choose Arcjet when the rule needs application context – the user, plan, route, or tool call – or when the risky action happens inside an agent that never sends a fresh HTTP request to the edge. Run both when you need each layer.
Arcjet publishes this comparison. Competitor details come from Cloudflare's public documentation, reviewed on September 25, 2026. Products change, so check the linked sources before you decide.
Key differences: Cloudflare vs Arcjet
Arcjet differs from Cloudflare in where it runs. Cloudflare's application-security products evaluate requests at the edge before they reach your origin, so DNS and traffic must go through Cloudflare. Arcjet runs inside your application and in the coding agent's hook, and works alongside any CDN, including Cloudflare, rather than replacing it.
The split between edge and application determines what each layer sees. Cloudflare edge rules see IP, TLS fingerprint, path, headers, and other network signals. Arcjet in-app rules see the session, plan tier, route, and the input to a tool call. The following sections compare the two layers by area.
What each layer covers
Cloudflare covers DDoS, edge WAF and bot filtering, and, through AI Gateway, caching, rate limiting, spend limits, content moderation, and data loss prevention (DLP) for traffic to model providers. Arcjet covers application-aware bot detection, rate limiting, and Shield WAF in request handlers. Arcjet also covers prompt-injection detection, per-user token budgets, sensitive-information checks, and destination threat analysis on agent tool calls, plus policy enforcement on coding agents.
Configuration
You change Cloudflare rules in the dashboard, through the API, or with Terraform. You change operational Arcjet remote rules in the Arcjet Console or through the MCP server: block a country, ASN, IP, or VPN during an attack; turn on a global bot category; add a temporary site-wide rate limit; or dry-run a rule, then promote it. Those changes take effect without a code edit or a redeploy.
Arcjet remote rules still enforce inside the application and combine with your code rules into one decision, so they keep the request context that the edge doesn't have.
App-specific rules stay in code because they need application context: route, user, tenant, plan, prompt, tool call, or request body. That includes per-user token budgets, prompt-injection detection, sensitive-information checks, email validation, and identity-keyed limits. Agent Guard policies are a separate system: a security team writes them in Rego or a builder, dry-runs them, and publishes them from the Console without changing the tool.
Bot detection
Cloudflare offers Bot Fight Mode on the Free plan, a single setting applied to all traffic across a domain. Super Bot Fight Mode on Pro and Business lets you allow, block, or challenge bot groups, also domain-wide. Bot Management for Enterprise adds per-request bot scores, JA3/JA4 fingerprints, and detection IDs that you can use in custom rules, and your account team adds it to an Enterprise plan.
Arcjet classifies known bots by name and category in your request handlers on self-serve plans, and can add advanced client signals for headless-browser detection without a CAPTCHA.
Rate limiting
Cloudflare tiers rate limiting rules by plan, as the following table shows. Counting by headers, cookies, query, JSON body fields, or JA3/JA4 requires Enterprise with Advanced Rate Limiting.
| Cloudflare plan | Rules | Counting period | Counts by |
|---|---|---|---|
| Free | 1 | 10 seconds | IP |
| Pro | 2 | Up to 1 minute | IP |
| Business | 5 | Up to 10 minutes | IP, or IP with NAT support |
| Enterprise | Up to 100 | Up to 65,535 seconds | IP, plus headers, cookies, query, JSON body fields, or JA3/JA4 with Advanced Rate Limiting |
You configure Arcjet rate limiting in code, and Arcjet can key on user ID, account, session, plan, or any value your application computes, on self-serve plans.
AI Gateway versus in-app AI protection
AI Gateway sits between your application and model providers. AI Gateway provides analytics, logging, caching, rate limiting by request count for the whole gateway, retries, and model fallback. Spend limits set cost budgets per model, provider, or custom metadata such as a user ID, and Cloudflare documents them as eventually consistent.
Guardrails flag or block harmful content with Llama Guard, and the category list includes a prompt-injection category (P1). DLP scans prompts and responses for sensitive data. Cloudflare also documents routing coding agents such as Claude Code, GitHub Copilot CLI, and OpenAI Codex through AI Gateway for observability, cost tracking, and DLP.
AI Gateway sees model traffic: the prompt going to the provider and the response coming back. AI Gateway DLP scans tool-call arguments and results as text when they appear in that body.
Arcjet evaluates the action itself, as structured inputs. In a custom agent, guard() runs before the tool executes, with the user and tool input in hand. In a coding agent, the policy runs on the hook the agent fires before a tool call, so it can deny rm -rf, a read of ~/.aws/credentials, or a fetch to a high-risk host before the tool runs. Arcjet's sensitive-information detection can run in your own process, so the raw body stays there. For a full breakdown, see AI Gateway vs Arcjet.
AI Security for Apps versus Arcjet prompt-injection detection
AI Security for Apps (formerly Firewall for AI) is part of the Cloudflare WAF. AI Security for Apps scans requests to endpoints labeled cf-llm for PII, unsafe topics, and prompt injection, and writes scores that you use in custom or rate limiting rules. LLM endpoint discovery is on all plans. The detection fields are an Enterprise paid add-on, and detection handles application/json requests only. The scan runs on inbound HTTP at the edge.
Arcjet's prompt-injection detection runs where you call it: on an HTTP route, on a tool result that re-enters the model's context, on a queued job, or on a prompt a developer types into a coding agent.
Turnstile versus advanced signals
Turnstile is a CAPTCHA-replacement widget that you embed on a page. Tokens are valid for 300 seconds, are single-use, and require server-side validation on the protected submission. Arcjet advanced client signals collect browser-environment signals, store a token in a cookie that later requests reuse, and evaluate it with server-side bot detection. For more information, see CAPTCHAs vs Arcjet.
Arcjet vs Cloudflare comparison table
The following table compares Arcjet and Cloudflare across 17 areas, from where each one enforces to local development.
| Area | Arcjet | Cloudflare |
|---|---|---|
| Where it enforces | In the path of the action: request handlers, agent tool calls, MCP handlers, jobs, and coding-agent hooks. No proxy. | At the Cloudflare network edge, before requests reach your origin. Requires routing traffic through Cloudflare. |
| Coding agents | One policy across Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code, evaluated from the hooks each agent fires, before the tool call runs. | AI Gateway can proxy a coding agent's model requests for observability, cost tracking, rate limiting, and DLP. The docs don't describe evaluating the agent's tool calls. |
| Configuration | Operational HTTP rules change in the Arcjet Console or through MCP without a redeploy, still inside the app. App-specific rules stay in code. Guard policies publish from the Console. | Dashboard, API, or Terraform, separate from the application code. |
| Hosting | Any provider, alongside any CDN, including Cloudflare. | Requires DNS routed through Cloudflare. Works with any origin behind the Cloudflare proxy. |
| Languages | SDKs for JavaScript, TypeScript, Python, and Go. | Any language behind the proxy. Workers has first-class support for JavaScript, TypeScript, Python, and Rust. |
| Bot detection | Known bots by name and category in request handlers, plus optional advanced client signals. Self-serve plans. | Bot Fight Mode (Free), Super Bot Fight Mode (Pro, Business), and Bot Management with per-request scores and JA3/JA4 (Enterprise add-on). |
| AI crawler blocking | AI crawler category in bot rules, with per-bot allow or deny. | AI bot policies for all customers, with Search, Agent, and Training presets and a crawler list that Cloudflare maintains. |
| Prompt injection | Detection on HTTP routes, tool results, jobs, and coding-agent prompts. The Arcjet Cloud API evaluates the text. | AI Gateway Guardrails category |
| Sensitive data | Sensitive-information detection in your process (built-in local engine, optional on-device ML model), plus a server-side detector for coding agents. | AI Gateway DLP on prompts and responses. AI Security for Apps PII detection on inbound prompts. |
| Destination threat analysis | Scores URLs, domains, and MCP servers an agent is about to contact with Arcjet threat intelligence, and can deny high-risk hosts. | Not documented for AI Gateway. |
| Token and spend budgets | Per-user token budgets keyed on any value your code computes, evaluated before the call. | AI Gateway spend limits by model, provider, or custom metadata such as a user ID. Eventually consistent. |
| WAF / attack coverage | Shield WAF in request handlers detects SQL injection, XSS, path traversal, and other common attacks. | Free Managed Ruleset on all plans. Cloudflare Managed Ruleset and OWASP Core Ruleset on Pro and above. |
| Rate limiting | Key on user ID, account, session, plan, or any computed value. | Free: 1 rule, 10s. Pro: 2 rules, up to 1 min. Business: 5 rules, up to 10 min. Enterprise: up to 100 rules. Non-IP keys need Enterprise Advanced Rate Limiting. |
| Custom rules | Rules are code, with no per-project rule count limit. | Free: 5. Pro: 20. Business: 100. Enterprise: 1,000. Log action: Enterprise only. |
| DDoS | Runs inside your application, so pair it with a DDoS provider. | Unmetered L3–L7 DDoS protection on all plans, including Free. |
| Evidence | Every decision and agent session in the Arcjet Console. SIEM export to Datadog, Splunk, SentinelOne, Panther, and Amazon S3 on Enterprise. | WAF Security Analytics and AI Gateway logs . |
| Local development | Same behavior as production; inspect decisions in code. | Edge rules apply only to traffic routed through Cloudflare. |
What can't the edge see in an AI agent runtime?
Cloudflare's edge doesn't see agent actions that happen after a request is inside your application, or coding-agent actions on a developer's machine. After a request is inside your application, a model can fetch a page that re-enters its context, a tool can burn tokens in a loop, or a queue job can send a support ticket with PII attached to a third-party model. None of those arrive as a fresh inbound HTTP request that the WAF can rule on. AI Gateway sees the model call, but not the tool the agent runs next.
Arcjet runs at those points: you pass the tool or job input to guard(), and Arcjet returns a decision before the side effect: prompt-injection detection, per-user token budgets, sensitive-information detection, and destination threat analysis. The SDKs name the two surfaces protect() for HTTP request handlers and guard() for tool calls and jobs. Arcjet has integrations for 15 agent frameworks, including the Claude Agent SDK, Cloudflare Think, LangChain, Mastra, OpenAI Agents, and the Vercel AI SDK.
Coding agents are the second blind spot for the edge. Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code run shell commands, file reads, URL fetches, and MCP calls on the developer's machine or in a cloud sandbox. Arcjet applies one policy to all five from the hooks they already fire, with no SDK and no code change, and you install it through managed settings so that developers can't remove it without admin access.
Arcjet's 12 starter policies include destructive commands, protected paths, credential access, piped installers, MCP allowlists, egress allowlists, and destination threats. Each coding-agent vendor sets the limits of its hook: Claude Code and Copilot HTTP hooks fail open by vendor design, and Cursor and Codex use a fail-closed command wrapper. For more information, see how to secure AI coding agents.
Cloudflare's network products address a related problem from the other side. MCP server portals give users one Access-protected endpoint for approved MCP servers, and Cloudflare One Gateway can detect MCP traffic on managed networks. Cloudflare's MCP controls see traffic that passes through Cloudflare. An Arcjet hook sees the tool call on the machine, including local shell commands and file edits.
When a Guard check can't finish (a timeout, a transport issue, or an incomplete policy), the direct Guard client returns allow with an error result, and hasFailedOpen() tells your code so that it can refuse the action. Framework wrappers fail closed unless you opt into continuing on error. For more information, see the Guards reference.
When to choose which
Choose Arcjet for application and agent context, Cloudflare for network-layer protection, and both when you need each. The following sections list the signals for each choice.
Choose Arcjet
Choose Arcjet if any of the following apply:
- You want one policy on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code tool calls, enforced before the tool runs.
- You're shipping an agent, MCP server, or pipeline where the risky action happens after the HTTP request.
- You need per-user or per-plan logic that the edge can't see.
- You want prompt-injection detection, token budgets, and sensitive-information checks on tool inputs, with the raw body kept in your process where possible.
- You aren't routing DNS through Cloudflare, or you might move hosts.
- You want Shield WAF, identity-keyed rate limits, and advanced bot signals on a self-serve plan.
Choose Cloudflare
Choose Cloudflare if any of the following apply:
- You need L3/L4/L7 DDoS mitigation.
- You're already on Cloudflare and want network protection with no code change.
- You want JA3/JA4 TLS fingerprints as a rule condition (Enterprise Bot Management).
- You want a gateway in front of model providers for caching, fallback, spend limits, and model-traffic DLP.
- You want to govern which MCP servers employees reach on managed networks.
Use both
Keep Cloudflare for DDoS, edge filtering, and AI Gateway caching and routing. Use Arcjet for application-aware HTTP rules, for guard() on the tool path of your own agents, and for policy on coding-agent tool calls. Arcjet works behind Cloudflare's proxy.
Cloudflare alternatives
The right Cloudflare alternative depends on which part of Cloudflare you're replacing:
- Arcjet: application-layer security and agent runtime policy – bots, rate limits, and Shield WAF in your code, plus enforcement on custom-agent tool calls and on Claude Code, Copilot, Cursor, Codex, and Muse Code hooks.
- AWS WAF: an edge and load-balancer WAF for applications that run on AWS.
- Fastly: a CDN with a web application and API protection product.
- Akamai App & API Protector: an edge WAF and bot product from a CDN provider.
For other comparisons, see Vercel WAF vs Arcjet, AI Gateway vs Arcjet, and AI agent security platforms.
Frequently asked questions
What is the difference between Arcjet and Cloudflare?
Cloudflare enforces at its network edge: DDoS mitigation, WAF, bot management, rate limiting, and AI Gateway as a proxy in front of model providers. Arcjet enforces in the path of the action: in your request handlers, on custom-agent tool calls through guard(), and in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code. Arcjet rules can use application context such as the user, plan, route, and tool input, and don't require routing traffic through a proxy.
Is Arcjet an alternative to Cloudflare?
Arcjet is an alternative to Cloudflare's application-layer controls – WAF rules, bot detection, and rate limiting – when you want them in code with user and route context, on any host. Arcjet isn't a DDoS provider or a CDN. If you need network-layer protection, keep Cloudflare or another edge provider in front of Arcjet.
Can you use Cloudflare and Arcjet together?
Yes. Cloudflare and Arcjet run at different layers, and Arcjet works behind Cloudflare's proxy. Cloudflare handles DDoS mitigation, edge filtering, and AI Gateway caching and routing. Arcjet handles application-aware rules that depend on user identity, route, and tool input, plus policy on custom-agent tool calls and on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code hooks.
How does Cloudflare AI Gateway compare to Arcjet?
Cloudflare AI Gateway is a proxy in front of model providers, and Arcjet evaluates the agent's action itself. Cloudflare documents caching, request-count rate limiting per gateway, spend limits by model, provider, or custom metadata, Guardrails that include a prompt-injection category, and DLP on prompts and responses. Arcjet's guard() runs before a custom agent's tool executes, and coding-agent policies run on the hook before a shell command, file read, or fetch runs. Sensitive-information detection can run in your own process.
Does Cloudflare support per-user rate limiting?
Cloudflare WAF rate limiting rules count by IP on Free, Pro, and Business. Counting by headers, cookies, query, or body fields requires Enterprise with Advanced Rate Limiting, and mapping those to users requires your application to send an identifying value. AI Gateway spend limits can split budgets by a user ID in custom metadata. Arcjet rate limiting is configured in code and can key on any value your application computes, on self-serve plans.
How is Arcjet priced compared with Cloudflare?
Cloudflare publishes Free, Pro, and Business plan prices, and Bot Management, Advanced Rate Limiting, and AI Security for Apps detection are Enterprise features or add-ons. Arcjet has Individual ($25 per month), Startup ($299 per month), and custom Enterprise plans, with usage at $5 per million web requests and $50 per million agent requests.
Application security in your request handlers
Get Shield, bots, and rate limits in the app
Arcjet runs inside your application: identity-keyed rules in request handlers, plus checks on tool calls the edge never sees.