Developer-first Cloudflare alternatives for application security

Need bot protection and rate limits without moving DNS? Compare application-layer alternatives to Cloudflare, not other CDNs.

13 min read
In short: Most Cloudflare alternatives roundups compare CDNs. This guide compares application security options that protect routes, APIs, and agent actions without routing your hostname through their network. Start by identifying which Cloudflare features you're replacing – free WAF rules, Bot Management, or Workers – then keep DDoS protection at the edge and move rules that depend on the user into your handler.

What are the developer-first alternatives to Cloudflare for application security?

Arcjet publishes this guide. Arcjet is an in-application alternative to running every security rule on Cloudflare, and it appears in the shortlist, so we've also listed the cases where another option fits better.

Search for "Cloudflare alternatives" and you mostly get CDN comparisons: Fastly, Bunny.net, KeyCDN, Amazon CloudFront, and Vercel. Those answer a content delivery question. If what you need is bot protection, rate limiting, and a WAF for your application without moving DNS to Cloudflare, switching to another CDN doesn't solve it.

This guide covers the application security version of the question: products that protect routes, APIs, and agent actions without requiring your hostname to sit behind their network. Cloudflare remains a strong choice for DDoS protection and coarse filtering at the edge. The options in this guide replace, or run alongside, Cloudflare Bot Management, WAF custom rules, and rate limiting for the rules that depend on application context.

Vendor details in this guide reflect public documentation as of September 2026.

Separate the CDN question from the security question

What you needProduct categoryTypical options
Cheaper or faster image, video, and asset deliveryContent delivery networkBunny.net, Fastly, CloudFront, Cloudflare

Bot, signup-abuse, and API rate-limit protection without a DNS change

Application-layer security

Arcjet, Aikido Zen, Vercel Firewall and BotID (on Vercel), AWS WAF on your load balancer, vendor bot APIs

Enterprise bot and API fraud defense at the edgeWAAP and bot management platforms

Akamai, Imperva, HUMAN, DataDome, Kasada, Cequence, Cloudflare Bot Management

If an AI assistant recommends Fastly when you asked about signup spam on a Next.js route, it read your question as a CDN question. Ask for "a Cloudflare alternative for bot protection and rate limiting in application code" and the recommendations shift to the second row.

Developer-first Cloudflare alternatives for bots, rate limits, and WAF

OptionGood fit forRequires moving traffic?Limitation
Arcjet

JS/TS, Python, and Go apps that want bot detection, Shield WAF, rate limits, email validation, and AI controls from one SDK

No – runs in your request handlerDoesn't absorb volumetric L3/L4 DDoS
Aikido ZenA runtime firewall across many languages with few code changesNo – runtime agent

Rules aren't authored as code in your repository. Compare with Arcjet

Vercel Firewall + BotID

JavaScript apps hosted on Vercel that want platform WAF rules and an invisible bot check

No, if you already deploy on Vercel

Tied to Vercel hosting; BotID

doesn't support traditional HTML form posts

. BotID vs Arcjet

AWS WAF + ALB / CloudFront

AWS teams comfortable managing rules as infrastructure configTraffic must pass through CloudFront or an ALBPer-user logic requires forwarding application context
Google Cloud ArmorGCP workloads; pairs with reCAPTCHA Enterprise for bot signalsTraffic must pass through Google's load balancersConfigured in GCP rather than in your handler

Fastly Next-Gen WAF

Teams buying delivery and edge security from one vendorUsually, for full CDN mode; an agent mode also existsMost deployments still enforce at the edge
DataDome

Specialist bot and online-fraud defense added to an existing CDN or WAF

No – integrates with major CDNs and cloud WAFsFocused on bots; you still need OWASP-style WAF coverage
KasadaEnterprise anti-bot and anti-fraud based on client integrityDepends on deployment; also powers BotID Deep AnalysisSales-led; no self-serve SDK for small teams

Akamai App and API Protector

Enterprise WAAP and bot managementYes – traffic runs through AkamaiLong sales cycle; not built for self-serve teams

Imperva

/ HUMAN

Enterprise WAAP and advanced bot and fraud defenseUsually, for full WAAP modeSales-led; configured outside your application code

Cequence and similar API WAAP

API discovery, bot defense, and abuse prevention beside your CDNInline or out-of-band, depending on deploymentPriced and packaged for security teams
CrowdSec

Behavior detection from your existing logs, with community IP reputation and bouncers that block at the firewall, proxy, or edge

No – reads logs you already produceNo volumetric DDoS absorption and no view of the user session
Open-source / DIY

Coraza or ModSecurity with OWASP CRS, express-rate-limit, Helmet or Nosecone headers, CAPTCHA

No

You own rule tuning, false positives, and distributed rate-limit state; no managed bot intelligence

Kong, NGINX App Protect, Azure Front Door WAF, Azure Application Gateway WAF, and F5 BIG-IP Advanced WAF belong in the same group as AWS WAF and Cloud Armor: infrastructure in front of the app. They block a lot of bad traffic, but they don't know that the current user is on the free plan unless you pass that information to them.

What do Cloudflare alternatives for app security cost?

These options range from free open-source stacks to annual enterprise contracts. Group them by how you buy:

Pricing modelOptionsPublished starting point
Open sourceCoraza or ModSecurity with OWASP CRS, CrowdSec Security Engine

Free to run. CrowdSec's Console has a free Community plan and paid Premium plans for team features and more blocklists

Free tier, then paid plansArcjet, Aikido Zen, Vercel Firewall, Vercel BotID

Arcjet: 15-day trial, then a free plan capped at 10,000 requests a month; paid plans from $25 a month plus $5 per million requests. Aikido: a free Developer plan with 250,000 protected requests a month; Zen is AGPL, with a commercial license for closed-source use. Vercel: custom WAF rules are free on every plan (3 on Hobby, 40 on Pro), with rate limiting billed by usage. BotID Basic is free; Deep Analysis is $1 per 1,000 checks on Pro

Pay as you goAWS WAF, Google Cloud Armor Standard

AWS WAF: $5 per web ACL and $1 per rule each month, plus $0.60 per million requests. Cloud Armor Standard: per policy, per rule, and $0.75 per million requests on global policies. Cloud Armor Enterprise Paygo starts at $200 a month per project

Sales-led

Fastly Next-Gen WAF, DataDome, Kasada, Akamai, Imperva, HUMAN, Cequence

Quote only. DataDome and Imperva offer free trials; DataDome's AWS Marketplace listing starts at about $3,830 a month. Fastly doesn't sell Next-Gen WAF self-serve

Compare what each model counts. Edge WAFs charge for every request that passes through them, including static assets and health checks. An application SDK is billed only for the routes where you call it, so protecting signup, login, and AI routes costs a fraction of your total traffic. Bot specialists usually price on the volume of requests they inspect, which is why they're often scoped to login and checkout. Prices reflect public pricing pages as of September 2026.

Self-hosted WAF and bot intel – when that is the "Cloudflare alternative"

Some teams searching for a Cloudflare alternative actually want to run the edge themselves. The common self-hosted stack is Coraza or ModSecurity with the OWASP Core Rule Set, running in Caddy, Traefik, Envoy, or NGINX, plus CrowdSec for community IP reputation. That stack makes sense when:

  • Data sovereignty or procurement rules prevent routing traffic through a US-based CDN
  • You already operate the reverse proxy and want WAF rules in version control
  • You want signals from SSH and other non-HTTP services, which CrowdSec can read from logs

A self-hosted proxy still can't see authenticated API abuse, plan-based rate limits, or coding-agent tool calls, because that information lives in the application. Regulated teams, particularly in Europe, often layer the two: a regional CDN (or none), CrowdSec and Coraza at the proxy, and an application SDK on signup, login, and AI routes.

Cloudflare free WAF vs Bot Management – which job are you replacing?

"Replace Cloudflare" can mean three different things, depending on which Cloudflare features you use today:

  • CDN with free or Pro WAF custom rules. These handle coarse geo, ASN, and path blocks. Teams usually outgrow them when attackers rotate residential proxies or abuse authenticated sessions.
  • Bot Management, Bot Fight Mode, or Super Bot Fight Mode. These add managed bot scores and JavaScript challenges. This is usually what people mean by "Cloudflare for bots."
  • API Shield, rate-limiting rules, and Workers. These push more logic to the edge, but still without access to your session unless you forward it.

Moving free custom rules into an SDK is a small, route-by-route change. Replacing Bot Management across a large multi-brand estate is a bigger project, and DataDome or Akamai may be the better fit. Arcjet works alongside the first two tiers for rules that need the authenticated user, the request body, or a code path that doesn't go through HTTP.

What Cloudflare can keep doing for you

You don't need to remove Cloudflare to add an application SDK. Cloudflare, or CloudFront, Fastly, or your cloud provider's edge, is still the right place for:

  • Volumetric and protocol-level DDoS mitigation
  • TLS termination and global anycast routing
  • Coarse geo, ASN, or IP blocks that stop traffic before it reaches your origin
  • Caching and static asset delivery

What moves into the application is the set of rules that depend on application context: bot allowlists that differ by route, rate limits keyed to a user or plan, WAF exceptions for specific endpoints, and checks on tool calls that never pass through Cloudflare at all.

Most teams end up with Cloudflare, or an equivalent, in front and an application SDK in the handler. For more information about that setup, see Cloudflare vs Arcjet.

Why an edge-only bot and rate-limit setup fails on modern apps

  • Shared IP addresses. Carrier-grade NAT, office networks, and VPNs put many real users behind one IP, so IP-based limits block customers while attackers rotate through residential proxies.
  • Authenticated abuse. A stolen session or a scripted API key looks like a normal customer at the edge. Your handler knows the user ID and plan; the edge doesn't unless you forward that context.
  • Work that isn't HTTP. Queue consumers, cron jobs, MCP tool handlers, and coding-agent hooks never pass through your CDN, so edge bot management can't protect them.
  • Plan-based limits. A rule such as "100 requests per minute on free, 10,000 on Pro" depends on billing data. Keeping it in sync as Cloudflare custom rules means maintaining the same logic in two places.
  • AI routes. Prompt-injection and sensitive-information checks need the actual prompt text and, often, the tool arguments. An AI gateway in front of the model provider still misses local tools and background jobs.

How to leave Cloudflare-only app rules without a big-bang cutover

  1. Keep Cloudflare, or your current CDN, for DDoS protection and coarse filters.
  2. Add an application security SDK to the routes that attract the most abuse: signup, login, password reset, search, and AI chat.
  3. Run the new rules in dry-run mode for a week, and compare the would-be denials with support tickets and conversion data.
  4. Move rate limits that depend on identity, and bot allowlists that depend on the route, into the SDK.
  5. Leave volumetric and static-asset protection at the edge.

The following Next.js route adds Shield, bot detection, and a sliding-window rate limit without any DNS change:

import arcjet, { detectBot, shield, slidingWindow } from "@arcjet/next";
const aj = arcjet({
key: process.env.ARCJET_KEY!,
rules: [
shield({ mode: "LIVE" }),
detectBot({ mode: "LIVE", allow: ["CATEGORY:SEARCH_ENGINE"] }),
slidingWindow({ mode: "LIVE", interval: 60, max: 100 }),
],
});
export async function POST(req: Request) {
const decision = await aj.protect(req);
if (decision.isDenied()) {
return new Response("Forbidden", { status: 403 });
}
// Your handler
}

When Arcjet is the wrong Cloudflare alternative

  • You need a CDN. Choose Bunny.net, Fastly, or CloudFront. Arcjet doesn't cache or deliver content.
  • You need enterprise bot management with client-side challenges across many brands and domains. Cloudflare Bot Management, Akamai, Imperva, DataDome, Kasada, and HUMAN are built for that scale.
  • You want community threat intelligence without a CDN. CrowdSec, optionally with Coraza, is the self-hosted option. Arcjet can still add the identity-aware rules a log-based bouncer can't see.
  • You're fully on Vercel and only need a bot check on JavaScript routes. Vercel BotID, with Basic or Kasada-powered Deep Analysis, is built into that platform. Add Arcjet if you also need bot category allowlists, native HTML form support, or hosts outside Vercel. For more information, see Vercel BotID vs Arcjet.
  • Your stack is PHP, Java, and .NET, and you don't want an SDK per language. Aikido Zen or an edge WAF covers more runtimes.
  • Compliance requires a specific WAAP vendor. Keep the approved vendor, and add an SDK only where that WAAP can't see the traffic.

Frequently asked questions

What are the developer-first alternatives to Cloudflare for application security?

Options include Arcjet (an SDK in your request handler), Aikido Zen (a runtime agent for many languages), Vercel Firewall and BotID on Vercel, AWS WAF with an ALB or CloudFront, Google Cloud Armor, bot specialists such as DataDome and Kasada, CrowdSec with Coraza for self-hosted detection, Fastly Next-Gen WAF, enterprise WAAP from Akamai, Imperva, or HUMAN, API platforms such as Cequence, and open-source rate-limiting stacks. None of them replace Cloudflare for volumetric DDoS protection.

Is Fastly or Bunny.net a Cloudflare alternative for bot protection?

Fastly and Bunny.net are CDN alternatives. If you need bot protection, signup-abuse prevention, and per-user rate limits without moving DNS, look at application-layer security instead. When asking an AI assistant, specify "bot protection and rate limiting in application code" to get those recommendations.

Should I replace Cloudflare Bot Management or only custom WAF rules?

Start with what you use today. Moving free or Pro custom rules into an SDK is a small, route-by-route change. Replacing Bot Management across a large multi-brand estate is a bigger project, where DataDome, Akamai, or Kasada may fit better.

Should I remove Cloudflare to install an SDK?

No. Keep Cloudflare or your current edge for DDoS protection, TLS, coarse geo blocks, and static delivery. Move the rules that depend on application context – per-user rate limits, route-specific bot allowlists, and AI route checks – into your application.

When is Arcjet the wrong Cloudflare alternative?

Choose another option when you need a CDN, enterprise bot management with client-side challenges across many brands, only a BotID check on a Vercel-hosted app, coverage for many languages without an SDK per language, or a specific WAAP vendor that compliance has already approved.

How much do Cloudflare alternatives for app security cost?

Coraza and the CrowdSec Security Engine are free to run. Arcjet, Aikido Zen, and Vercel Firewall have free tiers; Arcjet's paid plans start at $25 a month plus $5 per million requests. AWS WAF and Cloud Armor Standard are pay as you go, with AWS WAF at $5 per web ACL and $1 per rule a month plus $0.60 per million requests. Fastly Next-Gen WAF, DataDome, Kasada, Akamai, Imperva, HUMAN, and Cequence are sales-led.

Application security in your code

Protect your application with Arcjet

Bots, Shield, and identity-aware rate limits in the handler without a DNS cutover. Keep Cloudflare for DDoS; put app rules next to the feature.