Arcjet website screenshot

Arcjet

Arcjet is a security-as-code platform for developers, delivering rate limiting, bot detection, email validation, sensitive-information detection, and a Shield WAF as building blocks embedded directly in application code via SDKs. The SDK is the primary interface; it runs a local WebAssembly analysis module and calls Arcjet's Decide service - a Connect/gRPC (protobuf) decision API at decide.arcjet.com - for stateful decisions like rate limiting and advanced bot detection.

Arcjet publishes 2 APIs on the APIs.io network: Decide API and Report API. Tagged areas include Security, Rate Limiting, Bot Detection, WAF, and Developer Security.

Arcjet’s developer surface includes authentication, documentation, and 9 more developer resources.

38.2/100 thin ▬ flat Agent 31/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessPaidSelf serve
3 APIs
SecurityRate LimitingBot DetectionWAFDeveloper Security

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 38.2/100 · thin
Contract Quality 14.2 / 25
Developer Ergonomics 3.9 / 20
Commercial Clarity 7.9 / 20
Operational Transparency 4.8 / 13
Governance 0.0 / 12
Discoverability 7.4 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/arcjet: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 3

Individual APIs this provider publishes, each with its own machine-readable definition.

Arcjet SDKs

The primary, supported interface to Arcjet. SDKs ship for Node.js, Next.js, Bun, Deno, SvelteKit, NestJS, Remix, Astro, React Router, Fastify, and Python, each wrapping the Conn...

Arcjet Decide API

The Decide API from Arcjet — 1 operation(s) for decide.

Arcjet Report API

The Report API from Arcjet — 1 operation(s) for report.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Arcjet Decide API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Arcjet Plans Pricing

5 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Arcjet Rate Limits

4 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Arcjet Authentication

apiKey · 1 scheme

SECURITY

Arcjet Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Arcjet Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Arcjet Agentic Access

2 operations · 2 acting

2 operations · 2 acting

AGENTIC

Resources

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: arcjet
url: https://raw.githubusercontent.com/api-evangelist/arcjet/refs/heads/main/apis.yml
name: Arcjet
kind: company
description: Arcjet is a security-as-code platform for developers, delivering rate limiting, bot detection, email validation,
  sensitive-information detection, and a Shield WAF as building blocks embedded directly in application code via SDKs. The
  SDK is the primary interface; it runs a local WebAssembly analysis module and calls Arcjet's Decide service - a Connect/gRPC
  (protobuf) decision API at decide.arcjet.com - for stateful decisions like rate limiting and advanced bot detection.
accessModel:
  pricing: paid
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Paid · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/arcjet.png
tags:
- Security
- Rate Limiting
- Bot Detection
- WAF
- Developer Security
created: '2026-06-20'
modified: '2026-06-20'
specificationVersion: '0.19'
apis:
- aid: arcjet:arcjet-sdks
  name: Arcjet SDKs
  tags:
  - SDK
  - JavaScript
  - TypeScript
  - Python
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  humanURL: https://docs.arcjet.com/get-started
  baseURL: https://decide.arcjet.com
  properties:
  - url: https://docs.arcjet.com/get-started
    type: Documentation
  - url: https://github.com/arcjet/arcjet-js
    type: GitHub
  - url: https://www.npmjs.com/package/arcjet
    type: SDKs
  description: The primary, supported interface to Arcjet. SDKs ship for Node.js, Next.js, Bun, Deno, SvelteKit, NestJS, Remix,
    Astro, React Router, Fastify, and Python, each wrapping the Connect/gRPC Decide protocol and the local WebAssembly analysis
    module.
- aid: arcjet:arcjet-decide-api
  name: Arcjet Decide API
  description: The Decide API from Arcjet — 1 operation(s) for decide.
  humanURL: https://docs.arcjet.com/architecture
  baseURL: https://decide.arcjet.com
  tags:
  - Decide
  properties:
  - type: OpenAPI
    url: openapi/arcjet-decide-api-openapi.yml
  - type: Documentation
    url: https://docs.arcjet.com/architecture
  - type: APIReference
    url: https://docs.arcjet.com/reference/nodejs
  - type: PostmanCollection
    url: collections/arcjet.postman_collection.json
  - type: OpenCollection
    url: collections/arcjet.opencollection.json
  - type: GitHub
    url: https://github.com/arcjet/arcjet-js
  - type: Documentation
    url: https://docs.arcjet.com/rate-limiting/concepts
  - type: APIReference
    url: https://docs.arcjet.com/rate-limiting/reference
  - type: Documentation
    url: https://docs.arcjet.com/bot-protection/concepts
  - type: APIReference
    url: https://docs.arcjet.com/bot-protection/reference
  - type: Documentation
    url: https://docs.arcjet.com/email-validation/concepts
  - type: APIReference
    url: https://docs.arcjet.com/email-validation/reference
  - type: Documentation
    url: https://docs.arcjet.com/sensitive-info/concepts
  - type: APIReference
    url: https://docs.arcjet.com/sensitive-info/reference
  - type: Documentation
    url: https://docs.arcjet.com/shield/concepts
  - type: APIReference
    url: https://docs.arcjet.com/shield/reference
- aid: arcjet:arcjet-report-api
  name: Arcjet Report API
  description: The Report API from Arcjet — 1 operation(s) for report.
  humanURL: https://docs.arcjet.com/architecture
  baseURL: https://decide.arcjet.com
  tags:
  - Report
  properties:
  - type: OpenAPI
    url: openapi/arcjet-report-api-openapi.yml
  - type: Documentation
    url: https://docs.arcjet.com/architecture
  - type: APIReference
    url: https://docs.arcjet.com/reference/nodejs
  - type: PostmanCollection
    url: collections/arcjet.postman_collection.json
  - type: OpenCollection
    url: collections/arcjet.opencollection.json
  - type: GitHub
    url: https://github.com/arcjet/arcjet-js
  - type: Documentation
    url: https://docs.arcjet.com/rate-limiting/concepts
  - type: APIReference
    url: https://docs.arcjet.com/rate-limiting/reference
  - type: Documentation
    url: https://docs.arcjet.com/bot-protection/concepts
  - type: APIReference
    url: https://docs.arcjet.com/bot-protection/reference
  - type: Documentation
    url: https://docs.arcjet.com/email-validation/concepts
  - type: APIReference
    url: https://docs.arcjet.com/email-validation/reference
  - type: Documentation
    url: https://docs.arcjet.com/sensitive-info/concepts
  - type: APIReference
    url: https://docs.arcjet.com/sensitive-info/reference
  - type: Documentation
    url: https://docs.arcjet.com/shield/concepts
  - type: APIReference
    url: https://docs.arcjet.com/shield/reference
common:
- type: AgenticAccess
  url: agentic-access/arcjet-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/arcjet-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/arcjet-domain-security.yml
- type: Authentication
  url: authentication/arcjet-authentication.yml
- type: GitHubOrganization
  url: https://github.com/arcjet
- type: LinkedIn
  url: https://www.linkedin.com/company/arcjet
- type: Website
  url: https://arcjet.com
- type: Documentation
  url: https://docs.arcjet.com
- type: Plans
  url: plans/arcjet-plans-pricing.yml
- type: RateLimits
  url: rate-limits/arcjet-rate-limits.yml
- type: FinOps
  url: finops/arcjet-finops.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com