Arcjet vs Vercel BotID

Arcjet vs Vercel BotID: BotID checks bots on Vercel routes.

10 min read
In short: BotID runs a browser challenge that your server verifies on a protected Vercel route. Arcjet classifies bots in your request handlers on any host, with allow or deny by category, advanced client signals, and an inspectable decision that includes rate limits and Shield WAF.

Arcjet vs Vercel BotID

Vercel BotID is an invisible CAPTCHA for JavaScript applications deployed on Vercel: a client script runs a challenge, and your server calls checkBotId() on a protected route to learn whether the request came from a bot. Arcjet is an AI agent runtime security platform whose bot detection runs in your request handlers on any host. Arcjet classifies known bots by name and category, can add advanced client signals, and combines them with IP reputation, filters, rate limits, and Shield WAF in one inspectable decision. The key difference is control: BotID returns a verdict for a protected Vercel route, and Arcjet lets you choose which bots to allow or deny on any route and host. Choose BotID if you're fully on Vercel and want a bot check with minimal configuration. Choose Arcjet if you want allow or deny by bot category, support for traditional HTML forms, hosting freedom, or bot detection that sits in the same SDK as the rest of your application and agent security.

Arcjet publishes this comparison. Competitor details come from Vercel's public documentation, reviewed on September 25, 2026. Products change, so check the linked sources before you decide.

Key differences: Vercel BotID vs Arcjet

Vercel BotID and Arcjet differ in four ways: control over which bots to allow, client signals, HTML form support, and hosting. BotID runs a challenge in the browser and verifies the result server-side on a protected Vercel route. Arcjet bot detection runs in your request handlers: it classifies known bots by name and category, layers advanced client signals (headless and browser-environment anomalies, stored in the aj_signals cookie) with IP reputation and filters, and returns a structured reason that you can log or act on. Operational HTTP remote rules for bots, Shield, filters, and fixed-window or sliding-window rate limits change in the Arcjet Console, CLI, or MCP server without a redeploy.

Allow or deny by category

Arcjet lets you allow or deny bots by name and category, and BotID returns a verdict that you branch on in code. Arcjet rules can also vary by request context: allow a search-engine crawler on a content route, deny it on a signup, or change a rate limit by plan. BotID returns isBot plus verified-bot fields – isVerifiedBot, verifiedBotName, and verifiedBotCategory – so you branch in your own code for verified bots such as an AI assistant's operator agent.

To let through traffic that BotID would flag, Vercel documents a bypass rule in the Vercel WAF. BotID's documentation doesn't describe a list of named bots or categories to allow or deny.

Advanced client signals versus Deep Analysis

Arcjet advanced signals run a WebAssembly module in the browser, store a continue token in the aj_signals cookie that later requests reuse, and evaluate it with server-side bot classification and an optional missing-cookie filter. Each Arcjet rule can run live or in dry run.

BotID Deep Analysis, powered by Kasada, uses machine learning on client-side signals and runs after Basic validation passes. Basic is free on all plans. Deep Analysis costs $1 per 1,000 checkBotId() Deep Analysis calls on Pro, is custom-priced on Enterprise, and isn't available on Hobby.

Forms and integration

You call Arcjet bot detection from any request handler, including native HTML form POST requests. BotID is a client script plus a server check, and you declare protected paths on the client with initBotId({ protect: [...] }) in addition to the server check. BotID doesn't support traditional HTML forms that use the action and method attributes, so you submit with fetch or a server action instead.

Hosting

Arcjet bot detection runs on any host, with SDKs for JavaScript, TypeScript, Python, and Go, and behaves the same locally as in production. BotID's setup guide starts from a JavaScript project deployed on Vercel, with guides for Next.js, Nuxt, SvelteKit, and other JavaScript frameworks. In local development, checkBotId() returns { isBot: false }, and a development option lets you simulate a bot.

Vercel's WAF and rate limiting are separate Vercel Firewall products that you configure independently. Arcjet runs bots, rate limiting, Shield WAF, email validation, filters, and IP reputation in the same request-handler call.

Arcjet vs Vercel BotID comparison table

The following table compares Arcjet and Vercel BotID across 11 areas, from what each product is to what it covers beyond bots.

AreaArcjetVercel BotID
What it is

Bot detection in request handlers: known bots by name and category, optional advanced client signals, filters, and IP reputation. Inspectable decision.

Client-side challenge plus server verification on a protected Vercel route. Returns isBot plus verified-bot fields.

HostingAny host, including Next.js on or off Vercel.JavaScript projects deployed on Vercel.
LanguagesJavaScript, TypeScript, Python, and Go.

JavaScript and TypeScript frameworks, including Next.js, Nuxt, and SvelteKit.

Local developmentSame behavior as production.

Returns isBot: false locally; a development option can simulate a bot.

Integration modelCall from code in any handler.

Client script with protected paths declared in initBotId(), plus checkBotId() on the server.

HTML formsWorks with native forms and any HTTP request.

Traditional HTML forms with action and method aren't supported.

Configuration

Allow or deny bots by name and category. Filter rules compose cookie, header, IP, and geo conditions. Operational rules change in the Arcjet Console, CLI, or MCP server.

Basic or Deep Analysis level, set in the Firewall or per route. Branch in code on verified-bot fields, or add a WAF bypass rule.

Advanced bot signals

Browser WebAssembly signals, a reusable cookie, live or dry run, and an inspectable reason.

Deep Analysis powered by Kasada, run on each protected checkBotId() call.

Layered with

Rate limiting, Shield WAF, email validation, filters, and IP reputation in the same request-handler call.

WAF and rate limiting are separate Vercel Firewall products.
Pricing (bot feature)

Included in usage-based pricing: each protect() call is a web request, at $5 per million.

Basic: free on all plans. Deep Analysis: $1 per 1,000 calls on Pro; custom on Enterprise; not on Hobby.

Beyond bots

The same platform enforces policy on agent tool calls and on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code hooks.

Bot detection only.

How does Arcjet layer bot detection?

Vercel BotID reports whether an inbound HTTP client looks automated, which is the same job as Arcjet bot detection in request handlers: stop scrapers, credential stuffing, and other clients that target /login or a signup.

Arcjet layers that decision with other signals. Arcjet can deny a request because the signals look automated, because the user agent matches a known scraper, or because the IP has a poor reputation. A missing aj_signals cookie is itself a signal that you can filter on.

Live or dry run applies per Arcjet rule, so you can review would-be denials before you enforce them. HTTP request checks can fail open when your application can't reach the Arcjet Cloud API, and that behavior is configurable.

Bot detection is one part of Arcjet. The same platform runs guard() on your agents' tool calls and applies policy to coding agents from their hooks. For more information, see AI agent security platforms and application-layer bot detection.

When to choose which

Choose BotID for a minimal-configuration bot check on Vercel, Arcjet for control over which bots to allow on any host, and both when you want BotID's verdict plus Arcjet rules on the same route. The following sections list the signals for each choice.

Choose Arcjet

Choose Arcjet if any of the following apply:

  • You want a Vercel BotID alternative that isn't tied to Vercel hosting.
  • You need support for traditional HTML forms.
  • You want allow or deny by bot category, with inspectable decisions.
  • You need to test locally with production behavior.
  • You want advanced client signals included in request-based pricing.
  • You want filter rules, rate limits, and IP reputation in the same bot decision.
  • You use Python or Go as well as JavaScript.

Choose BotID

Choose BotID if any of the following apply:

  • You're fully on Vercel with a JavaScript framework.
  • You want a bot check with minimal configuration.
  • You don't need to choose which bots to allow beyond verified-bot fields.
  • You're content to configure rate limits and WAF separately in the Vercel Firewall.

Use both

BotID and Arcjet can run on the same route. BotID's result arrives in your handler, and Arcjet adds rate limits, Shield WAF, and category-based bot rules in the same request.

Vercel BotID alternatives

Vercel BotID alternatives include in-app bot detection, challenge widgets, and edge bot management:

  • Arcjet: bot detection by name and category in your request handlers on any host, with advanced client signals, filters, and rate limits in one decision.
  • Kasada: the bot-defense provider behind BotID Deep Analysis, sold directly.
  • Cloudflare Turnstile: a CAPTCHA-replacement widget that you can embed without routing traffic through Cloudflare. For more information, see CAPTCHAs vs Arcjet.
  • Cloudflare Bot Management: edge bot scoring for traffic that goes through Cloudflare. For more information, see Cloudflare vs Arcjet.

Frequently asked questions

What is the difference between Arcjet and Vercel BotID?

Vercel BotID runs a client-side challenge that your server verifies with checkBotId() on a protected route of a JavaScript project deployed on Vercel. Arcjet bot detection runs in your request handlers on any host, classifies known bots by name and category, can add advanced client signals, and combines them with IP reputation, filters, rate limits, and Shield WAF in one inspectable decision.

Is Arcjet an alternative to Vercel BotID?

Yes. Arcjet covers the same job – detecting automated clients on routes such as login and signup – without requiring Vercel hosting, with SDKs for JavaScript, TypeScript, Python, and Go, and with support for native HTML form POST requests, which BotID documents as unsupported.

Can you use Vercel BotID and Arcjet together?

Yes. Vercel BotID and Arcjet both run in your request handler, so they can protect the same route. BotID's result arrives from checkBotId(), and Arcjet adds category-based bot rules, rate limits, and Shield WAF to the same request. BotID's documentation covers JavaScript projects deployed on Vercel, and Arcjet works on any host.

Can I configure which bots to allow or block?

With Arcjet, you allow or deny bots by name and category in your request handlers, for example allowing search-engine crawlers and blocking the rest. BotID returns isBot plus verified-bot fields (isVerifiedBot, verifiedBotName, verifiedBotCategory) that you branch on in code, and Vercel documents a WAF bypass rule for traffic that BotID would flag.

How much does Vercel BotID cost compared with Arcjet?

Vercel documents BotID Basic as free on all plans, and Deep Analysis at $1 per 1,000 checkBotId() Deep Analysis calls on Pro, custom on Enterprise, and not available on Hobby. Arcjet bills each protect() call as a web request at $5 per million, on top of an Individual ($25 per month), Startup ($299 per month), or custom Enterprise plan.

Bot detection in your request handlers

Protect your application with Arcjet

Get allow/deny by bot category, inspectable decisions, and advanced client signals, on Vercel or any other host.