Arcjet vs Vercel WAF
Vercel WAF is the firewall built into the Vercel platform: custom rules, managed rulesets, rate limiting, and bot rulesets that evaluate requests at Vercel's edge, plus automatic DDoS mitigation. Arcjet is an AI agent runtime security platform that enforces policy in the path of the action: Shield WAF, bot detection, and rate limiting inside your request handlers on any host, guard() on your agents' tool calls, and policy in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code. The key difference is where each one decides: Vercel WAF decides at Vercel's edge on request attributes, and Arcjet decides inside your application with the user, plan, and route in hand. Choose Vercel WAF for zero-code edge filtering on Vercel. Choose Arcjet when a rule needs the user, plan, or route, when you deploy outside Vercel, or when the action you need to control happens inside an agent. Run both when you need each layer.
Arcjet publishes this comparison. Competitor details come from Vercel's public documentation, reviewed on September 25, 2026. Products change, so check the linked sources before you decide.
Key differences: Vercel WAF vs Arcjet
Arcjet differs from Vercel WAF in where it runs. Vercel WAF runs at the network and CDN edge, and rules evaluate before a request reaches your application. Vercel WAF rule conditions act on request attributes such as IP, user agent, JA4 fingerprint, path, and headers. Arcjet runs inside your application, so Arcjet rules can also use the context your application already has – session, subscription, feature flags, and route – and can key a limit on a user, account, or plan.
What each layer covers
Vercel WAF handles platform DDoS mitigation and coarse edge filtering for projects on Vercel. Arcjet covers the application layer: Shield WAF, known-bot classification with optional advanced client signals, rate limits keyed on any computed value, filters, and email validation. For agents, Arcjet adds prompt-injection detection, token budgets, sensitive-information checks, and destination threat analysis on tool calls and jobs, and one policy across coding agents.
Configuration
Vercel documents five ways to manage firewall rules: the dashboard, the vercel firewall CLI, the Firewall API, a Terraform provider, and vercel.json. Custom rules change in the dashboard, including from a natural-language description, and take effect without a redeployment. The vercel firewall CLI stages and publishes rule changes, the Firewall API exposes the configuration, and a Terraform provider manages it as code. In vercel.json, only the challenge and deny actions are supported.
Operational Arcjet remote rules change in the Arcjet Console, CLI, or MCP server and take effect without a redeploy: a country, ASN, IP, or VPN block; a global bot category; a filter; a temporary site-wide fixed-window or sliding-window rate limit; and Shield WAF. Arcjet remote rules enforce inside the application and combine with your code rules into one decision. App-specific rules stay in code because they need application context: identity-keyed limits, token budgets, email validation, prompt injection, and sensitive information.
Platform independence
Arcjet works wherever you can run a JavaScript, TypeScript, Python, or Go application, on Vercel or elsewhere. Vercel WAF applies to projects deployed on Vercel.
Bot detection
Vercel's Bot Protection managed ruleset "identifies clients that violate browser-like behavior and serves a javascript challenge to them," and Vercel's pricing page lists it on all plans. Vercel's documentation also states that Bot Protection "doesn't work when a reverse proxy (e.g. Cloudflare, Azure, or other CDNs) is placed in front of your Vercel deployment."
Arcjet classifies known bots by name and category in your request handlers and can add browser-based signals. Arcjet bot detection runs inside the application, so a reverse proxy in front of the origin doesn't change how it works.
Rate limiting
Vercel WAF rate limiting varies by plan, as the following table shows.
| Vercel plan | Rules per project | Keys | Algorithm and window |
|---|---|---|---|
| Hobby | 1 | IP and JA4 Digest | Fixed window up to 10 minutes |
| Pro | 40 | IP and JA4 Digest | Fixed window up to 10 minutes |
| Enterprise | 1,000 | Adds User Agent and arbitrary header keys | Adds token bucket, and windows up to 1 hour |
You configure Arcjet rate limiting in code, keyed on any value that the application can compute, including fixed-window, sliding-window, and token-bucket algorithms on self-serve plans.
Plan gating
The OWASP Core Ruleset, token-bucket rate limiting, and User Agent or header rate-limit keys are Vercel Enterprise features. Bot Protection and AI Bots managed rulesets are on all plans. Arcjet Shield WAF, bot detection, advanced signals, filters, and identity-keyed rate limits are on self-serve plans.
Arcjet vs Vercel WAF comparison table
The following table compares Arcjet and Vercel WAF across 13 areas, from where each one enforces to local development.
| Area | Arcjet | Vercel WAF |
|---|---|---|
| Where it enforces | Inside your application request handlers and agent tool calls, and in coding-agent hooks. No proxy. | At the Vercel edge, before requests reach your application. |
| Configuration | Operational HTTP rules change in the Arcjet Console, CLI, or MCP server without a redeploy. App-specific rules stay in code. Guard policies publish from the Console. | Dashboard,
, Firewall API, and Terraform. |
| Hosting | Any provider, or self-hosted. | Projects deployed on Vercel. |
| Languages | SDKs for JavaScript, TypeScript, Python, and Go. | Any language deployed on Vercel. Rules apply at the edge. |
| Bot detection | Known bots by name and category in request handlers, with optional advanced client signals. Works behind any proxy or CDN. | Bot Protection managed ruleset (all plans) serves a JavaScript challenge. Vercel documents that it doesn't work behind a reverse proxy. |
| WAF / attack coverage | Shield WAF in request handlers on self-serve plans. | OWASP Core Ruleset (Enterprise). L3, L4, and L7 DDoS mitigation on all plans. |
| Rate limiting | Key on user ID, account, session, plan, or any computed value. Token bucket on self-serve plans, set in code. | Hobby and Pro: IP or JA4 Digest, fixed window up to 10 min. Enterprise: User Agent and header keys, token bucket, up to 1 hour. Rules: 1 / 40 / 1,000. |
| Custom rules | Filters in code that combine cookie, IP reputation, geo, VPN or proxy, header, and path with bot and rate-limit rules. | Log, deny, challenge, bypass, redirect, and rate limit actions. Hobby projects can have up to 3 custom rules . |
| Email / identity | Email validation and identity-keyed rules in the same SDK. | Request attributes such as IP, JA4, user agent, and headers. |
| AI crawler blocking | AI crawler category in bot rules. | AI Bots managed ruleset on all plans, in log or deny mode. |
| Coding agents | One policy across Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code, evaluated before each tool call. | Not documented for Vercel WAF. |
| Custom agents and tool calls | Prompt injection, token budgets, sensitive information, and destination threat analysis on tool and job inputs. | The WAF inspects inbound HTTP. Vercel Sandbox has a separate egress firewall for sandboxed code. |
| Local development | Same behavior as production. | Vercel's documentation doesn't describe firewall rules applying in
|
How does in-app security differ from the edge?
Vercel WAF is an inbound HTTP control, and it's a good fit for edge filtering and platform DDoS mitigation on Vercel. Arcjet is the application layer: Shield, bots, rate limits, filters, and email validation in your request handlers through protect(), with the identity and route context that the edge doesn't have.
Arcjet also covers the agent layer. The guard() function runs on tool calls, MCP handlers, and jobs, where a model's action happens after the HTTP request that started it. There, Arcjet runs prompt-injection detection (evaluated by the Arcjet Cloud API), token budgets, and sensitive-information detection that can run in your own process, and it scores the hosts an agent is about to contact with Arcjet threat intelligence. Arcjet has integrations for 15 agent frameworks, including the Vercel AI SDK, Vercel Eve, Mastra, LangChain, and OpenAI Agents.
Vercel's own agent-adjacent controls sit elsewhere in the platform. Vercel Sandbox restricts egress from sandboxed code, and AI Gateway offers zero data retention routing, prompt-training controls, and provider allowlists. Vercel Sandbox and AI Gateway govern where code and model traffic can go. Arcjet decides whether a specific action is allowed, for a specific user, before it runs.
For coding agents, Arcjet applies one policy to Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code from the hooks they already fire, with no SDK and no code change. For more information, see how to secure AI coding agents.
When a Guard check can't finish, the direct Guard client returns allow with an error result, and hasFailedOpen() lets your code refuse the action. Framework wrappers fail closed unless you opt into continuing on error. HTTP request checks can fail open when your application can't reach the Arcjet Cloud API, and that behavior is configurable.
When to choose which
Choose Vercel WAF for zero-code edge protection on Vercel, Arcjet for rules that need application or agent context, and both when you need each. The following sections list the signals for each choice.
Choose Arcjet
Choose Arcjet if any of the following apply:
- You want a Vercel WAF alternative with rules in application code.
- You need per-user or account-level logic.
- You deploy outside Vercel, or might later.
- You sit behind a CDN or reverse proxy in front of Vercel.
- You want Shield WAF, bots, and identity-keyed rate limits without an Enterprise contract.
- You're building agents or rolling out coding agents and need policy on their actions.
Choose Vercel WAF
Choose Vercel WAF if any of the following apply:
- You want zero-code edge protection for a project on Vercel.
- You need L3/L4/L7 DDoS mitigation, which is automatic on all plans.
- You want JA4 Digest as a rule condition.
Use both
Vercel's DDoS mitigation stays on either way. Use Vercel WAF for coarse edge filtering and Arcjet for application-aware rules and agent policy.
Vercel WAF alternatives
Vercel WAF alternatives fall into two groups: controls in your application and edge providers in front of Vercel.
- Arcjet: application-layer Shield WAF, bots, and identity-keyed rate limits in your code on any host, plus policy on agent tool calls and coding-agent hooks.
- Cloudflare: an edge WAF, bot management, and DDoS provider. Placing it in front of Vercel affects Vercel Bot Protection, as noted earlier.
- Fastly: a CDN with a web application and API protection product.
- AWS WAF: an option when you move the application to AWS.
For bot-only protection on Vercel, see Vercel BotID vs Arcjet.
Frequently asked questions
What is the difference between Arcjet and Vercel WAF?
Vercel WAF evaluates requests at Vercel's edge using request attributes such as IP, JA4, user agent, path, and headers, and applies to projects deployed on Vercel. Arcjet runs inside your application on any host, so Arcjet rules can use the user, plan, session, and route. Arcjet also enforces policy on agent tool calls through guard() and on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code through their hooks.
Is Arcjet an alternative to Vercel WAF?
Yes, for application-layer rules: Shield WAF, bot detection, identity-keyed rate limiting, filters, and email validation in your code, on Vercel or any other host, on self-serve plans. Vercel's automatic DDoS mitigation stays on for projects on Vercel either way, so a project on Vercel keeps that protection when it adds Arcjet.
Can you use Vercel WAF and Arcjet together?
Yes. Vercel's DDoS mitigation runs on all plans, and you can use Vercel WAF for coarse edge filtering and Arcjet for per-user rate limits, bot detection with request context, and policy on agent tool calls. Arcjet rules run after the request passes Vercel's edge, so each Arcjet decision can use the user, plan, and route.
Does Vercel WAF support per-user rate limiting?
Vercel WAF can key a rate limit on a user only through a header key, which requires Enterprise. Vercel WAF rate limiting counts by IP or JA4 Digest on Hobby and Pro, and Enterprise adds User Agent and arbitrary header keys and token bucket. Keying on a user requires your application to send an identifying header. Arcjet rate limiting is configured in code and can key on any value your application computes.
What happens if I put Cloudflare or another CDN in front of Vercel?
Vercel documents that its Bot Protection managed ruleset doesn't work when a reverse proxy such as Cloudflare, Azure, or another CDN sits in front of the deployment. Arcjet bot detection runs inside the application, so a proxy in front of the origin doesn't change how Arcjet works.
How is Vercel WAF priced compared with Arcjet?
Vercel lists custom rules and DDoS mitigation on all plans, bills WAF rate limiting per allowed request, and reserves the OWASP Core Ruleset and token-bucket rate limiting for Enterprise. Arcjet has Individual ($25 per month), Startup ($299 per month), and custom Enterprise plans, with usage at $5 per million web requests and $50 per million agent requests.
In-app security on any host
Get Shield, bots, and rate limits in the app
Identity-keyed rules, email validation, and filters in your request handlers. Works on Vercel or any other host.