Arcjet vs Vercel BotID
Vercel BotID is an invisible CAPTCHA for JavaScript applications deployed on Vercel: a client script runs a challenge, and your server calls checkBotId() on a protected route to learn whether the request came from a bot. Arcjet is an AI agent runtime security platform whose bot detection runs in your request handlers on any host. Arcjet classifies known bots by name and category, can add advanced client signals, and combines them with IP reputation, filters, rate limits, and Shield WAF in one inspectable decision. The key difference is control: BotID returns a verdict for a protected Vercel route, and Arcjet lets you choose which bots to allow or deny on any route and host. Choose BotID if you're fully on Vercel and want a bot check with minimal configuration. Choose Arcjet if you want allow or deny by bot category, support for traditional HTML forms, hosting freedom, or bot detection that sits in the same SDK as the rest of your application and agent security.
Arcjet publishes this comparison. Competitor details come from Vercel's public documentation, reviewed on September 25, 2026. Products change, so check the linked sources before you decide.
Key differences: Vercel BotID vs Arcjet
Vercel BotID and Arcjet differ in four ways: control over which bots to allow, client signals, HTML form support, and hosting. BotID runs a challenge in the browser and verifies the result server-side on a protected Vercel route. Arcjet bot detection runs in your request handlers: it classifies known bots by name and category, layers advanced client signals (headless and browser-environment anomalies, stored in the aj_signals cookie) with IP reputation and filters, and returns a structured reason that you can log or act on. Operational HTTP remote rules for bots, Shield, filters, and fixed-window or sliding-window rate limits change in the Arcjet Console, CLI, or MCP server without a redeploy.
Allow or deny by category
Arcjet lets you allow or deny bots by name and category, and BotID returns a verdict that you branch on in code. Arcjet rules can also vary by request context: allow a search-engine crawler on a content route, deny it on a signup, or change a rate limit by plan. BotID returns isBot plus verified-bot fields – isVerifiedBot, verifiedBotName, and verifiedBotCategory – so you branch in your own code for verified bots such as an AI assistant's operator agent.
To let through traffic that BotID would flag, Vercel documents a bypass rule in the Vercel WAF. BotID's documentation doesn't describe a list of named bots or categories to allow or deny.
Advanced client signals versus Deep Analysis
Arcjet advanced signals run a WebAssembly module in the browser, store a continue token in the aj_signals cookie that later requests reuse, and evaluate it with server-side bot classification and an optional missing-cookie filter. Each Arcjet rule can run live or in dry run.
BotID Deep Analysis, powered by Kasada, uses machine learning on client-side signals and runs after Basic validation passes. Basic is free on all plans. Deep Analysis costs $1 per 1,000 checkBotId() Deep Analysis calls on Pro, is custom-priced on Enterprise, and isn't available on Hobby.
Forms and integration
You call Arcjet bot detection from any request handler, including native HTML form POST requests. BotID is a client script plus a server check, and you declare protected paths on the client with initBotId({ protect: [...] }) in addition to the server check. BotID doesn't support traditional HTML forms that use the action and method attributes, so you submit with fetch or a server action instead.
Hosting
Arcjet bot detection runs on any host, with SDKs for JavaScript, TypeScript, Python, and Go, and behaves the same locally as in production. BotID's setup guide starts from a JavaScript project deployed on Vercel, with guides for Next.js, Nuxt, SvelteKit, and other JavaScript frameworks. In local development, checkBotId() returns { isBot: false }, and a development option lets you simulate a bot.
Vercel's WAF and rate limiting are separate Vercel Firewall products that you configure independently. Arcjet runs bots, rate limiting, Shield WAF, email validation, filters, and IP reputation in the same request-handler call.
Arcjet vs Vercel BotID comparison table
The following table compares Arcjet and Vercel BotID across 11 areas, from what each product is to what it covers beyond bots.
| Area | Arcjet | Vercel BotID |
|---|---|---|
| What it is | Bot detection in request handlers: known bots by name and category, optional advanced client signals, filters, and IP reputation. Inspectable decision. | Client-side challenge plus server verification on a protected Vercel
route. Returns |
| Hosting | Any host, including Next.js on or off Vercel. | JavaScript projects deployed on Vercel. |
| Languages | JavaScript, TypeScript, Python, and Go. | JavaScript and TypeScript frameworks, including Next.js, Nuxt, and SvelteKit. |
| Local development | Same behavior as production. | Returns |
| Integration model | Call from code in any handler. | Client script with protected paths declared in |
| HTML forms | Works with native forms and any HTTP request. | Traditional HTML forms with |
| Configuration | Allow or deny bots by name and category. Filter rules compose cookie, header, IP, and geo conditions. Operational rules change in the Arcjet Console, CLI, or MCP server. | Basic or Deep Analysis level, set in the Firewall or per route. Branch in code on verified-bot fields, or add a WAF bypass rule. |
| Advanced bot signals | Browser WebAssembly signals, a reusable cookie, live or dry run, and an inspectable reason. | Deep Analysis powered by Kasada, run on each protected
|
| Layered with | Rate limiting, Shield WAF, email validation, filters, and IP reputation in the same request-handler call. | WAF and rate limiting are separate Vercel Firewall products. |
| Pricing (bot feature) | Included in usage-based pricing: each | Basic: free on all plans. Deep Analysis: $1 per 1,000 calls on Pro; custom on Enterprise; not on Hobby. |
| Beyond bots | The same platform enforces policy on agent tool calls and on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code hooks. | Bot detection only. |
How does Arcjet layer bot detection?
Vercel BotID reports whether an inbound HTTP client looks automated, which is the same job as Arcjet bot detection in request handlers: stop scrapers, credential stuffing, and other clients that target /login or a signup.
Arcjet layers that decision with other signals. Arcjet can deny a request because the signals look automated, because the user agent matches a known scraper, or because the IP has a poor reputation. A missing aj_signals cookie is itself a signal that you can filter on.
Live or dry run applies per Arcjet rule, so you can review would-be denials before you enforce them. HTTP request checks can fail open when your application can't reach the Arcjet Cloud API, and that behavior is configurable.
Bot detection is one part of Arcjet. The same platform runs guard() on your agents' tool calls and applies policy to coding agents from their hooks. For more information, see AI agent security platforms and application-layer bot detection.
When to choose which
Choose BotID for a minimal-configuration bot check on Vercel, Arcjet for control over which bots to allow on any host, and both when you want BotID's verdict plus Arcjet rules on the same route. The following sections list the signals for each choice.
Choose Arcjet
Choose Arcjet if any of the following apply:
- You want a Vercel BotID alternative that isn't tied to Vercel hosting.
- You need support for traditional HTML forms.
- You want allow or deny by bot category, with inspectable decisions.
- You need to test locally with production behavior.
- You want advanced client signals included in request-based pricing.
- You want filter rules, rate limits, and IP reputation in the same bot decision.
- You use Python or Go as well as JavaScript.
Choose BotID
Choose BotID if any of the following apply:
- You're fully on Vercel with a JavaScript framework.
- You want a bot check with minimal configuration.
- You don't need to choose which bots to allow beyond verified-bot fields.
- You're content to configure rate limits and WAF separately in the Vercel Firewall.
Use both
BotID and Arcjet can run on the same route. BotID's result arrives in your handler, and Arcjet adds rate limits, Shield WAF, and category-based bot rules in the same request.
Vercel BotID alternatives
Vercel BotID alternatives include in-app bot detection, challenge widgets, and edge bot management:
- Arcjet: bot detection by name and category in your request handlers on any host, with advanced client signals, filters, and rate limits in one decision.
- Kasada: the bot-defense provider behind BotID Deep Analysis, sold directly.
- Cloudflare Turnstile: a CAPTCHA-replacement widget that you can embed without routing traffic through Cloudflare. For more information, see CAPTCHAs vs Arcjet.
- Cloudflare Bot Management: edge bot scoring for traffic that goes through Cloudflare. For more information, see Cloudflare vs Arcjet.
Frequently asked questions
What is the difference between Arcjet and Vercel BotID?
Vercel BotID runs a client-side challenge that your server verifies with checkBotId() on a protected route of a JavaScript project deployed on Vercel. Arcjet bot detection runs in your request handlers on any host, classifies known bots by name and category, can add advanced client signals, and combines them with IP reputation, filters, rate limits, and Shield WAF in one inspectable decision.
Is Arcjet an alternative to Vercel BotID?
Yes. Arcjet covers the same job – detecting automated clients on routes such as login and signup – without requiring Vercel hosting, with SDKs for JavaScript, TypeScript, Python, and Go, and with support for native HTML form POST requests, which BotID documents as unsupported.
Can you use Vercel BotID and Arcjet together?
Yes. Vercel BotID and Arcjet both run in your request handler, so they can protect the same route. BotID's result arrives from checkBotId(), and Arcjet adds category-based bot rules, rate limits, and Shield WAF to the same request. BotID's documentation covers JavaScript projects deployed on Vercel, and Arcjet works on any host.
Can I configure which bots to allow or block?
With Arcjet, you allow or deny bots by name and category in your request handlers, for example allowing search-engine crawlers and blocking the rest. BotID returns isBot plus verified-bot fields (isVerifiedBot, verifiedBotName, verifiedBotCategory) that you branch on in code, and Vercel documents a WAF bypass rule for traffic that BotID would flag.
How much does Vercel BotID cost compared with Arcjet?
Vercel documents BotID Basic as free on all plans, and Deep Analysis at $1 per 1,000 checkBotId() Deep Analysis calls on Pro, custom on Enterprise, and not available on Hobby. Arcjet bills each protect() call as a web request at $5 per million, on top of an Individual ($25 per month), Startup ($299 per month), or custom Enterprise plan.
Bot detection in your request handlers
Protect your application with Arcjet
Get allow/deny by bot category, inspectable decisions, and advanced client signals, on Vercel or any other host.