What is Arcjet?
Runtime security for AI agents, coding agents and web apps Arcjet is a security platform for code that makes decisions on its own.
Our verdict
Arcjet puts the allow-or-block decision inside your application and agent code instead of at a network edge, which means rules can see user, session and tool-call context. It covers prompt injection, PII leaks, bots and abuse in one SDK, supports a long list of frameworks, and has a 15-day trial followed by a free tier.
Full review
Arcjet is a security platform for code that makes decisions on its own. Founded by David Mytton in 2023 and headquartered in San Francisco with an office hub in New York, it started as a developer-first way to add bot protection, rate limiting and a web application firewall (WAF) inside application code. Its current pitch is wider: runtime security for AI agents, whether those are coding agents such as Claude Code, Cursor, GitHub Copilot, OpenAI Codex and Muse Code, or custom agents written in JavaScript, TypeScript, Python or Go.
What Arcjet actually does
For coding agents, Arcjet hooks into the events each tool already fires, so a policy can allow or block a tool call before it runs. Policies are written in OPA Rego. For custom agents, the SDKs let you ask which agents are running, whether an action should be allowed, and what happened afterwards. On top of
Arcjet is a security platform for code that makes decisions on its own. Founded by David Mytton in 2023 and headquartered in San Francisco with an office hub in New York, it started as a developer-first way to add bot protection, rate limiting and a web application firewall (WAF) inside application code. Its current pitch is wider: runtime security for AI agents, whether those are coding agents such as Claude Code, Cursor, GitHub Copilot, OpenAI Codex and Muse Code, or custom agents written in JavaScript, TypeScript, Python or Go.
What Arcjet actually does
For coding agents, Arcjet hooks into the events each tool already fires, so a policy can allow or block a tool call before it runs. Policies are written in OPA Rego. For custom agents, the SDKs let you ask which agents are running, whether an action should be allowed, and what happened afterwards. On top of that sit detections for prompt injection, PII and secrets, plus threat intelligence that checks the URLs, APIs and MCP servers an agent tries to reach.
The older web security features remain part of the same product: bot detection, rate limiting, Shield WAF, email validation, signup form protection and request filters. Because they run in your code rather than at the edge, rules can use real user and session context.
Pricing and setup
Plans are Individual at $25 per month, Startup at $299 per month and a custom Enterprise tier, each billed with usage fees: $5 per million web requests and $50 per million agent requests. Paid plans start with a 15-day trial, after which an account falls back to a free plan capped at 10,000 requests per month. Setup means installing an SDK for your framework (Next.js, Node.js, Express, FastAPI, Flask, SvelteKit and a dozen more) or connecting the MCP server, so expect developer time rather than a point-and-click install.
Who should look at it
Engineering and security teams shipping AI features that touch real data and real tools. Arcjet says it has completed a SOC 2 Type 2 examination, with the report available in its Trust Center.
Who it's for
Best for
- Developer teams shipping AI agents or AI-powered features who need guardrails against prompt injection
- data leaks and runaway token spend
- and who are happy to integrate an SDK.
Not ideal for
- Teams that want a no-code security dashboard with no engineering work
- or buyers who need one flat price with no usage fees.
How we tested
AppsInsight desk research, 5 October 2026. We read Arcjet's homepage, pricing page, About page and docs, and checked prices against the official pricing page on that date. We did not run a hands-on production deployment. Claims about compliance and customer numbers are Arcjet's own.
Security & compliance
At a glance
| Pricing | Free+Paid |
|---|---|
| Starting price | $25 |
| Free plan | Yes |
| Free trial | Yes (15 days) |
| Pricing page | View pricing |
| Platforms | API / SDK, CLI / Terminal |
| API | Yes |
| Company | Arcjet Labs, Inc. |
| Apps Insight Score | 50/100 |
| Implementation | Medium |
| Learning curve | Intermediate |
| Compliance | SOC 2 Type 2 (Security, Availability, Confidentiality) |
Why this app scored 50/100
Editorial Review 26/30
- Product quality 8/10 8/10
- Ease of use 3.5/5 4/5
- Feature depth 4.5/5 5/5
- Innovation 4.5/5 5/5
- Value for money 2/3 2/3
- Recommendation confidence 1.5/2 2/2
Trust & Verification 10/25
- AppsInsight badge installed Badge not installed 0/15
- HTTPS website HTTPS 1/1
- Business support email Provided 1/1
- Privacy policy published Provided 2/2
- Terms of service published Provided 1/1
- Security certifications SOC 2 Type 2 (Security, Availability, Confidentiality) 2/2
- Knowledge base / help center Provided 2/2
- Social profiles linked 4 profiles linked 1/1
Community 0/20
- Verified reviews & rating 0 reviews (5 needed) 0/15
- Recent reviews No reviews yet 0/5
Product Profile 11/20
- Detailed description 338 words 2/3
- Screenshots 2 screenshots 1/3
- Demo video No demo video 0/2
- FAQ 6 items 1/2
- Feature list 9 items 1/2
- Pricing published Plan tiers published 3/3
- Pros & cons Pros & cons listed 1/1
- Integrations 1 integration 0/2
- API available Yes 1/1
- Company details 3 of 3 details filled 1/1
Freshness 3/5
- Listing recently updated Updated 0 days ago 3/3
- Recent changelog entry No changelog entries 0/2
Editorial points are assigned by AppsInsight editors and cannot be purchased or influenced.
Integrations
Built for
Development & DevOps
Security & compliance
AI & automation
SaaS & technology
How Arcjet compares
| Feature | Arcjet | iFixAi | Nivoli Edge |
|---|---|---|---|
| Rating | 4.3 / 5 | 3.8 / 5 | 3.7 / 5 |
| Pricing | Free+Paid | Free+Paid | Free+Paid |
| Starting price | $25 | — | — |
| Free plan | Included | Included | Included |
| Free trial | Yes (15 days) | No | Yes (14 days) |
| Platforms | API / SDK, CLI / Terminal | — | Web app, Self-hosted / On-premise, WordPress plugin |
| Best for | Developer teams shipping AI agents or AI-powered features who need guardrails against prompt injection, data leaks and runaway token spend, and who are happy to integrate an SDK. | Teams deploying AI agents with real authority over money, data or customers, engineering leads who need audit evidence they can defend, and enterprises that want agent governance without building an eval harness. | Public-facing WordPress publishers; site owners maintaining a secure license mailbox; agencies with up to ten sites needing pooled reports; teams willing to validate origin routing and cache exclusions |
Key features
Prompt injection detection
Sensitive information detection
Coding agent policies
Custom agent guards
Real-time threat intelligence
Bot protection, rate limiting and Shield WAF
Email validation and signup form protection
MCP server and remote rules
SIEM export
Key benefits
- Decisions are made in code with real user and session context
- One SDK covers agent security and classic web protection
- Dry-run mode lets you test a rule before it blocks anything
Pricing
Free (after trial)
$0 /mo
- Account continues on a free plan after the 15-day trial. Hard cap of 10
- 000 requests per month
- no overage billing.
Individual
$25 /mo
- 1 team member. 1 hour log retention. Email support. 15-day trial. Usage fees apply.
Startup
$299 /mo
- 2 team members. 24 hour log retention. Email and Slack support. 15-day trial. Usage fees apply.
Enterprise
Custom /mo
- Unlimited team members. SIEM export. Priority support. Book a demo. Usage fees apply.
Pros & Cons
Pros
- SDKs for more than a dozen frameworks, including Next.js, Node.js, Express, FastAPI, Flask and SvelteKit
- Covers both coding agents and custom agents with the same policy engine
- 15-day trial, then an account continues on a free plan with 10,000 requests per month
- Completed a SOC 2 Type 2 examination, per its own About page
- Docs at docs.arcjet.com and a public GitHub organisation with SDKs and agent skills
Cons
- Usage fees ($5 per 1M web requests, $50 per 1M agent requests) are added on top of the plan price
- Individual plan has one team member and one hour of log retention
- Needs engineering time to integrate, so it is not a point-and-click tool
- Enterprise pricing is custom and only available through a demo
Screenshots & media
Arcjet alternatives
View all alternatives
Nivoli Edge
WordPress edge shields, owner-confirmed locks and managed page caching
- Web app
- Self-hosted / On-premise
- WordPress plugin
User reviews
No reviews yet. Be the first to review this app.
Already have an account? Log in to track your reviews.




