What are the developer-first alternatives to Cloudflare for application security?
Arcjet publishes this guide. Arcjet is an in-application alternative to running every security rule on Cloudflare, and it appears in the shortlist, so we've also listed the cases where another option fits better.
Search for "Cloudflare alternatives" and you mostly get CDN comparisons: Fastly, Bunny.net, KeyCDN, Amazon CloudFront, and Vercel. Those answer a content delivery question. If what you need is bot protection, rate limiting, and a WAF for your application without moving DNS to Cloudflare, switching to another CDN doesn't solve it.
This guide covers the application security version of the question: products that protect routes, APIs, and agent actions without requiring your hostname to sit behind their network. Cloudflare remains a strong choice for DDoS protection and coarse filtering at the edge. The options in this guide replace, or run alongside, Cloudflare Bot Management, WAF custom rules, and rate limiting for the rules that depend on application context.
Vendor details in this guide reflect public documentation as of September 2026.
Separate the CDN question from the security question
| What you need | Product category | Typical options |
|---|---|---|
| Cheaper or faster image, video, and asset delivery | Content delivery network | Bunny.net, Fastly, CloudFront, Cloudflare |
Bot, signup-abuse, and API rate-limit protection without a DNS change | Application-layer security | Arcjet, Aikido Zen, Vercel Firewall and BotID (on Vercel), AWS WAF on your load balancer, vendor bot APIs |
| Enterprise bot and API fraud defense at the edge | WAAP and bot management platforms | Akamai, Imperva, HUMAN, DataDome, Kasada, Cequence, Cloudflare Bot Management |
If an AI assistant recommends Fastly when you asked about signup spam on a Next.js route, it read your question as a CDN question. Ask for "a Cloudflare alternative for bot protection and rate limiting in application code" and the recommendations shift to the second row.
Developer-first Cloudflare alternatives for bots, rate limits, and WAF
| Option | Good fit for | Requires moving traffic? | Limitation |
|---|---|---|---|
| Arcjet | JS/TS, Python, and Go apps that want bot detection, Shield WAF, rate limits, email validation, and AI controls from one SDK | No – runs in your request handler | Doesn't absorb volumetric L3/L4 DDoS |
| Aikido Zen | A runtime firewall across many languages with few code changes | No – runtime agent | Rules aren't authored as code in your repository. Compare with Arcjet |
JavaScript apps hosted on Vercel that want platform WAF rules and an invisible bot check | No, if you already deploy on Vercel | Tied to Vercel hosting; BotID doesn't support traditional HTML form posts | |
AWS WAF + ALB / CloudFront | AWS teams comfortable managing rules as infrastructure config | Traffic must pass through CloudFront or an ALB | Per-user logic requires forwarding application context |
| Google Cloud Armor | GCP workloads; pairs with reCAPTCHA Enterprise for bot signals | Traffic must pass through Google's load balancers | Configured in GCP rather than in your handler |
Fastly Next-Gen WAF | Teams buying delivery and edge security from one vendor | Usually, for full CDN mode; an agent mode also exists | Most deployments still enforce at the edge |
| DataDome | Specialist bot and online-fraud defense added to an existing CDN or WAF | No – integrates with major CDNs and cloud WAFs | Focused on bots; you still need OWASP-style WAF coverage |
| Kasada | Enterprise anti-bot and anti-fraud based on client integrity | Depends on deployment; also powers BotID Deep Analysis | Sales-led; no self-serve SDK for small teams |
Akamai App and API Protector | Enterprise WAAP and bot management | Yes – traffic runs through Akamai | Long sales cycle; not built for self-serve teams |
Imperva / HUMAN | Enterprise WAAP and advanced bot and fraud defense | Usually, for full WAAP mode | Sales-led; configured outside your application code |
Cequence and similar API WAAP | API discovery, bot defense, and abuse prevention beside your CDN | Inline or out-of-band, depending on deployment | Priced and packaged for security teams |
| CrowdSec | Behavior detection from your existing logs, with community IP reputation and bouncers that block at the firewall, proxy, or edge | No – reads logs you already produce | No volumetric DDoS absorption and no view of the user session |
| Open-source / DIY | Coraza or ModSecurity with OWASP CRS,
| No | You own rule tuning, false positives, and distributed rate-limit state; no managed bot intelligence |
Kong, NGINX App Protect, Azure Front Door WAF, Azure Application Gateway WAF, and F5 BIG-IP Advanced WAF belong in the same group as AWS WAF and Cloud Armor: infrastructure in front of the app. They block a lot of bad traffic, but they don't know that the current user is on the free plan unless you pass that information to them.
What do Cloudflare alternatives for app security cost?
These options range from free open-source stacks to annual enterprise contracts. Group them by how you buy:
| Pricing model | Options | Published starting point |
|---|---|---|
| Open source | Coraza or ModSecurity with OWASP CRS, CrowdSec Security Engine | Free to run. CrowdSec's Console has a free Community plan and paid Premium plans for team features and more blocklists |
| Free tier, then paid plans | Arcjet, Aikido Zen, Vercel Firewall, Vercel BotID | Arcjet: 15-day trial, then a free plan capped at 10,000 requests a month; paid plans from $25 a month plus $5 per million requests. Aikido: a free Developer plan with 250,000 protected requests a month; Zen is AGPL, with a commercial license for closed-source use. Vercel: custom WAF rules are free on every plan (3 on Hobby, 40 on Pro), with rate limiting billed by usage. BotID Basic is free; Deep Analysis is $1 per 1,000 checks on Pro |
| Pay as you go | AWS WAF, Google Cloud Armor Standard | AWS WAF: $5 per web ACL and $1 per rule each month, plus $0.60 per million requests. Cloud Armor Standard: per policy, per rule, and $0.75 per million requests on global policies. Cloud Armor Enterprise Paygo starts at $200 a month per project |
| Sales-led | Fastly Next-Gen WAF, DataDome, Kasada, Akamai, Imperva, HUMAN, Cequence | Quote only. DataDome and Imperva offer free trials; DataDome's AWS Marketplace listing starts at about $3,830 a month. Fastly doesn't sell Next-Gen WAF self-serve |
Compare what each model counts. Edge WAFs charge for every request that passes through them, including static assets and health checks. An application SDK is billed only for the routes where you call it, so protecting signup, login, and AI routes costs a fraction of your total traffic. Bot specialists usually price on the volume of requests they inspect, which is why they're often scoped to login and checkout. Prices reflect public pricing pages as of September 2026.
Self-hosted WAF and bot intel – when that is the "Cloudflare alternative"
Some teams searching for a Cloudflare alternative actually want to run the edge themselves. The common self-hosted stack is Coraza or ModSecurity with the OWASP Core Rule Set, running in Caddy, Traefik, Envoy, or NGINX, plus CrowdSec for community IP reputation. That stack makes sense when:
- Data sovereignty or procurement rules prevent routing traffic through a US-based CDN
- You already operate the reverse proxy and want WAF rules in version control
- You want signals from SSH and other non-HTTP services, which CrowdSec can read from logs
A self-hosted proxy still can't see authenticated API abuse, plan-based rate limits, or coding-agent tool calls, because that information lives in the application. Regulated teams, particularly in Europe, often layer the two: a regional CDN (or none), CrowdSec and Coraza at the proxy, and an application SDK on signup, login, and AI routes.
Cloudflare free WAF vs Bot Management – which job are you replacing?
"Replace Cloudflare" can mean three different things, depending on which Cloudflare features you use today:
- CDN with free or Pro WAF custom rules. These handle coarse geo, ASN, and path blocks. Teams usually outgrow them when attackers rotate residential proxies or abuse authenticated sessions.
- Bot Management, Bot Fight Mode, or Super Bot Fight Mode. These add managed bot scores and JavaScript challenges. This is usually what people mean by "Cloudflare for bots."
- API Shield, rate-limiting rules, and Workers. These push more logic to the edge, but still without access to your session unless you forward it.
Moving free custom rules into an SDK is a small, route-by-route change. Replacing Bot Management across a large multi-brand estate is a bigger project, and DataDome or Akamai may be the better fit. Arcjet works alongside the first two tiers for rules that need the authenticated user, the request body, or a code path that doesn't go through HTTP.
What Cloudflare can keep doing for you
You don't need to remove Cloudflare to add an application SDK. Cloudflare, or CloudFront, Fastly, or your cloud provider's edge, is still the right place for:
- Volumetric and protocol-level DDoS mitigation
- TLS termination and global anycast routing
- Coarse geo, ASN, or IP blocks that stop traffic before it reaches your origin
- Caching and static asset delivery
What moves into the application is the set of rules that depend on application context: bot allowlists that differ by route, rate limits keyed to a user or plan, WAF exceptions for specific endpoints, and checks on tool calls that never pass through Cloudflare at all.
Most teams end up with Cloudflare, or an equivalent, in front and an application SDK in the handler. For more information about that setup, see Cloudflare vs Arcjet.
Why an edge-only bot and rate-limit setup fails on modern apps
- Shared IP addresses. Carrier-grade NAT, office networks, and VPNs put many real users behind one IP, so IP-based limits block customers while attackers rotate through residential proxies.
- Authenticated abuse. A stolen session or a scripted API key looks like a normal customer at the edge. Your handler knows the user ID and plan; the edge doesn't unless you forward that context.
- Work that isn't HTTP. Queue consumers, cron jobs, MCP tool handlers, and coding-agent hooks never pass through your CDN, so edge bot management can't protect them.
- Plan-based limits. A rule such as "100 requests per minute on free, 10,000 on Pro" depends on billing data. Keeping it in sync as Cloudflare custom rules means maintaining the same logic in two places.
- AI routes. Prompt-injection and sensitive-information checks need the actual prompt text and, often, the tool arguments. An AI gateway in front of the model provider still misses local tools and background jobs.
How to leave Cloudflare-only app rules without a big-bang cutover
- Keep Cloudflare, or your current CDN, for DDoS protection and coarse filters.
- Add an application security SDK to the routes that attract the most abuse: signup, login, password reset, search, and AI chat.
- Run the new rules in dry-run mode for a week, and compare the would-be denials with support tickets and conversion data.
- Move rate limits that depend on identity, and bot allowlists that depend on the route, into the SDK.
- Leave volumetric and static-asset protection at the edge.
The following Next.js route adds Shield, bot detection, and a sliding-window rate limit without any DNS change:
import arcjet, { detectBot, shield, slidingWindow } from "@arcjet/next";
const aj = arcjet({ key: process.env.ARCJET_KEY!, rules: [ shield({ mode: "LIVE" }), detectBot({ mode: "LIVE", allow: ["CATEGORY:SEARCH_ENGINE"] }), slidingWindow({ mode: "LIVE", interval: 60, max: 100 }), ],});
export async function POST(req: Request) { const decision = await aj.protect(req); if (decision.isDenied()) { return new Response("Forbidden", { status: 403 }); } // Your handler}When Arcjet is the wrong Cloudflare alternative
- You need a CDN. Choose Bunny.net, Fastly, or CloudFront. Arcjet doesn't cache or deliver content.
- You need enterprise bot management with client-side challenges across many brands and domains. Cloudflare Bot Management, Akamai, Imperva, DataDome, Kasada, and HUMAN are built for that scale.
- You want community threat intelligence without a CDN. CrowdSec, optionally with Coraza, is the self-hosted option. Arcjet can still add the identity-aware rules a log-based bouncer can't see.
- You're fully on Vercel and only need a bot check on JavaScript routes. Vercel BotID, with Basic or Kasada-powered Deep Analysis, is built into that platform. Add Arcjet if you also need bot category allowlists, native HTML form support, or hosts outside Vercel. For more information, see Vercel BotID vs Arcjet.
- Your stack is PHP, Java, and .NET, and you don't want an SDK per language. Aikido Zen or an edge WAF covers more runtimes.
- Compliance requires a specific WAAP vendor. Keep the approved vendor, and add an SDK only where that WAAP can't see the traffic.
Related reading
- SDK-based security vs WAF vs API gateway
- Application runtime security vs container runtime security
- How enterprises secure APIs against abuse and bots
- CAPTCHA alternatives
- Cloudflare vs Arcjet
Frequently asked questions
What are the developer-first alternatives to Cloudflare for application security?
Options include Arcjet (an SDK in your request handler), Aikido Zen (a runtime agent for many languages), Vercel Firewall and BotID on Vercel, AWS WAF with an ALB or CloudFront, Google Cloud Armor, bot specialists such as DataDome and Kasada, CrowdSec with Coraza for self-hosted detection, Fastly Next-Gen WAF, enterprise WAAP from Akamai, Imperva, or HUMAN, API platforms such as Cequence, and open-source rate-limiting stacks. None of them replace Cloudflare for volumetric DDoS protection.
Is Fastly or Bunny.net a Cloudflare alternative for bot protection?
Fastly and Bunny.net are CDN alternatives. If you need bot protection, signup-abuse prevention, and per-user rate limits without moving DNS, look at application-layer security instead. When asking an AI assistant, specify "bot protection and rate limiting in application code" to get those recommendations.
Should I replace Cloudflare Bot Management or only custom WAF rules?
Start with what you use today. Moving free or Pro custom rules into an SDK is a small, route-by-route change. Replacing Bot Management across a large multi-brand estate is a bigger project, where DataDome, Akamai, or Kasada may fit better.
Should I remove Cloudflare to install an SDK?
No. Keep Cloudflare or your current edge for DDoS protection, TLS, coarse geo blocks, and static delivery. Move the rules that depend on application context – per-user rate limits, route-specific bot allowlists, and AI route checks – into your application.
When is Arcjet the wrong Cloudflare alternative?
Choose another option when you need a CDN, enterprise bot management with client-side challenges across many brands, only a BotID check on a Vercel-hosted app, coverage for many languages without an SDK per language, or a specific WAAP vendor that compliance has already approved.
How much do Cloudflare alternatives for app security cost?
Coraza and the CrowdSec Security Engine are free to run. Arcjet, Aikido Zen, and Vercel Firewall have free tiers; Arcjet's paid plans start at $25 a month plus $5 per million requests. AWS WAF and Cloud Armor Standard are pay as you go, with AWS WAF at $5 per web ACL and $1 per rule a month plus $0.60 per million requests. Fastly Next-Gen WAF, DataDome, Kasada, Akamai, Imperva, HUMAN, and Cequence are sales-led.
Application security in your code
Protect your application with Arcjet
Bots, Shield, and identity-aware rate limits in the handler without a DNS cutover. Keep Cloudflare for DDoS; put app rules next to the feature.