DataDome website screenshot

DataDome

DataDome is a real-time bot and online fraud protection platform that inspects every web, mobile, and API request and decides — within milliseconds — whether it should be allowed, challenged, or blocked. The platform combines a JavaScript tag and mobile SDKs (iOS, Android, React Native, Flutter) on the client side with 40+ server-side integrations (Nginx, Apache, IIS, OpenResty, HAProxy, Cloudflare Workers, AWS CloudFront, Fastly, Bunny, Node.js, Python ASGI, Go, Ruby, Java, ASP.NET Core, Kong, Apigee, Tyk, Traefik) that forward signals to DataDome's decisioning service. Products in the platform include Bot Protect, Account Protect, Ad Protect, Page Protect, Priority Protect, Agentic Trust (governing AI agent traffic), and DDoS Protect.

DataDome publishes 8 APIs on the APIs.io network, including Account API, AccountProtect API, CustomRules API, and 5 more. Tagged areas include Bot Mitigation, Fraud Protection, Account Protection, Ad Fraud, and DDoS.

DataDome’s developer surface includes authentication, documentation, API reference, engineering blog, status page, and 9 more developer resources.

33.9/100 thin ▬ flat Agent 31/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreeSelf serve⚡ Free to try
17 APIs
Bot MitigationFraud ProtectionAccount ProtectionAd FraudDDoSReal-TimeEdge SecurityApplication SecurityAgentic Trust

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 33.9/100 · thin
Contract Quality 11.7 / 25
Developer Ergonomics 5.7 / 20
Commercial Clarity 5.8 / 20
Operational Transparency 3.4 / 13
Governance 0.0 / 12
Discoverability 7.4 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/datadome: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 17

Individual APIs this provider publishes, each with its own machine-readable definition.

DataDome Bot Protect

Bot Protect is DataDome's core bot management product, scoring every request against the platform's threat intelligence and machine-learning models to classify and block automat...

DataDome Account Protect

Account Protect targets account takeover, fake account creation, and post-login abuse using behavioral, device, and credential signals layered on top of the Bot Protect decision...

DataDome Ad Protect

Ad Protect filters invalid traffic from ad-supported properties and protects publishers and advertisers from automated click and impression fraud, leveraging the same signal pip...

DataDome Page Protect

Page Protect provides client-side security and Magecart / formjacking defense, inventorying third-party scripts and detecting unauthorized data exfiltration from sensitive pages...

DataDome Agentic Trust

Agentic Trust is DataDome's product for managing AI-agent traffic, letting customers identify, authenticate, and govern interactions from autonomous agents and LLM-driven crawle...

DataDome DDoS Protect

DDoS Protect mitigates application-layer denial-of-service attacks using the same edge-distributed signal pipeline as Bot Protect, defending APIs and web properties against high...

DataDome JavaScript Tag

The DataDome JS tag collects browser, device, and behavioral signals that are forwarded to the DataDome decisioning service. The tag is configured per property and loaded asynch...

DataDome Server Modules & SDKs

DataDome ships 40+ server-side integrations (web servers, CDNs, application frameworks, API gateways) that forward each request to the DataDome decisioning service and apply the...

DataDome Mobile SDKs

Native iOS and Android SDKs (with React Native and Flutter wrappers) integrate with common HTTP libraries (OkHttp, Alamofire, Axios, Dio) so DataDome verdicts can be applied to ...

DataDome Account API

The Account API from DataDome — 4 operation(s) for account.

DataDome AccountProtect API

The AccountProtect API from DataDome — 1 operation(s) for accountprotect.

DataDome CustomRules API

The CustomRules API from DataDome — 2 operation(s) for customrules.

DataDome Endpoints API

The Endpoints API from DataDome — 2 operation(s) for endpoints.

DataDome Priorities API

The Priorities API from DataDome — 3 operation(s) for priorities.

DataDome Templates API

The Templates API from DataDome — 2 operation(s) for templates.

DataDome TrustedProxies API

The TrustedProxies API from DataDome — 2 operation(s) for trustedproxies.

DataDome VerifiedModels API

The VerifiedModels API from DataDome — 1 operation(s) for verifiedmodels.

Scroll for all 17

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

DataDome Management API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Datadome Rate Limits

2 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Datadome Authentication

apiKey · 1 scheme

SECURITY

Datadome Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Datadome Agentic Access

31 operations · 17 acting

31 operations · 17 acting

AGENTIC

Resources

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Company 4

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: datadome
name: DataDome
description: 'DataDome is a real-time bot and online fraud protection platform that

  inspects every web, mobile, and API request and decides — within

  milliseconds — whether it should be allowed, challenged, or blocked.

  The platform combines a JavaScript tag and mobile SDKs (iOS, Android,

  React Native, Flutter) on the client side with 40+ server-side

  integrations (Nginx, Apache, IIS, OpenResty, HAProxy, Cloudflare

  Workers, AWS CloudFront, Fastly, Bunny, Node.js, Python ASGI, Go,

  Ruby, Java, ASP.NET Core, Kong, Apigee, Tyk, Traefik) that forward

  signals to DataDome''s decisioning service. Products in the platform

  include Bot Protect, Account Protect, Ad Protect, Page Protect,

  Priority Protect, Agentic Trust (governing AI agent traffic), and

  DDoS Protect.

  '
type: Index
accessModel:
  pricing: free
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Free · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
position: Provider
access: Commercial
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/datadome.png
tags:
- Bot Mitigation
- Fraud Protection
- Account Protection
- Ad Fraud
- DDoS
- Real-Time
- Edge Security
- Application Security
- Agentic Trust
url: https://raw.githubusercontent.com/api-evangelist/datadome/refs/heads/main/apis.yml
created: '2026-05-23'
modified: '2026-05-23'
specificationVersion: '0.20'
apis:
- aid: datadome:bot-protect
  name: DataDome Bot Protect
  description: 'Bot Protect is DataDome''s core bot management product, scoring

    every request against the platform''s threat intelligence and

    machine-learning models to classify and block automated traffic

    (scraping, credential stuffing, inventory hoarding, fake account

    creation, content theft) without adding latency to good traffic.

    '
  humanURL: https://datadome.co/products/bot-protect/
  baseURL: https://datadome.co
  tags:
  - Bot Management
  - Scraping
  - Credential Stuffing
  - ML
  properties:
  - type: ProductPage
    url: https://datadome.co/products/bot-protect/
  - type: Documentation
    url: https://docs.datadome.co/
- aid: datadome:account-protect
  name: DataDome Account Protect
  description: 'Account Protect targets account takeover, fake account creation,

    and post-login abuse using behavioral, device, and credential

    signals layered on top of the Bot Protect decisioning core.

    '
  humanURL: https://datadome.co/products/account-protect/
  baseURL: https://datadome.co
  tags:
  - ATO
  - Account Protection
  - Fraud
  properties:
  - type: ProductPage
    url: https://datadome.co/products/account-protect/
  - type: Documentation
    url: https://docs.datadome.co/
- aid: datadome:ad-protect
  name: DataDome Ad Protect
  description: 'Ad Protect filters invalid traffic from ad-supported properties

    and protects publishers and advertisers from automated click and

    impression fraud, leveraging the same signal pipeline as Bot

    Protect.

    '
  humanURL: https://datadome.co/products/ad-protect/
  baseURL: https://datadome.co
  tags:
  - Ad Fraud
  - IVT
  - Click Fraud
  properties:
  - type: ProductPage
    url: https://datadome.co/products/ad-protect/
  - type: Documentation
    url: https://docs.datadome.co/
- aid: datadome:page-protect
  name: DataDome Page Protect
  description: 'Page Protect provides client-side security and Magecart / formjacking

    defense, inventorying third-party scripts and detecting unauthorized

    data exfiltration from sensitive pages such as checkout and account.

    '
  humanURL: https://datadome.co/products/page-protect/
  baseURL: https://datadome.co
  tags:
  - Client-Side Security
  - PCI DSS 4
  - Magecart
  - Supply Chain
  properties:
  - type: ProductPage
    url: https://datadome.co/products/page-protect/
  - type: Documentation
    url: https://docs.datadome.co/
- aid: datadome:agentic-trust
  name: DataDome Agentic Trust
  description: 'Agentic Trust is DataDome''s product for managing AI-agent traffic,

    letting customers identify, authenticate, and govern interactions

    from autonomous agents and LLM-driven crawlers against their web

    and API surfaces.

    '
  humanURL: https://datadome.co/products/agentic-trust/
  baseURL: https://datadome.co
  tags:
  - AI Agents
  - LLM
  - Agentic Traffic
  - Governance
  properties:
  - type: ProductPage
    url: https://datadome.co/products/agentic-trust/
  - type: Documentation
    url: https://docs.datadome.co/
- aid: datadome:ddos-protect
  name: DataDome DDoS Protect
  description: 'DDoS Protect mitigates application-layer denial-of-service attacks

    using the same edge-distributed signal pipeline as Bot Protect,

    defending APIs and web properties against high-volume automated

    campaigns.

    '
  humanURL: https://datadome.co/products/ddos-protect/
  baseURL: https://datadome.co
  tags:
  - DDoS
  - Layer 7
  - Availability
  properties:
  - type: ProductPage
    url: https://datadome.co/products/ddos-protect/
  - type: Documentation
    url: https://docs.datadome.co/
- aid: datadome:js-tag
  name: DataDome JavaScript Tag
  description: 'The DataDome JS tag collects browser, device, and behavioral

    signals that are forwarded to the DataDome decisioning service.

    The tag is configured per property and loaded asynchronously to

    avoid impacting page performance.

    '
  humanURL: https://docs.datadome.co/docs/integration-js-tag
  baseURL: https://js.datadome.co
  tags:
  - JavaScript Tag
  - Client Signals
  - Frontend
  properties:
  - type: Documentation
    url: https://docs.datadome.co/docs/integration-js-tag
- aid: datadome:server-modules
  name: DataDome Server Modules & SDKs
  description: 'DataDome ships 40+ server-side integrations (web servers, CDNs,

    application frameworks, API gateways) that forward each request

    to the DataDome decisioning service and apply the returned verdict.

    These cover Nginx, Apache, IIS, OpenResty, HAProxy, Cloudflare

    Workers, AWS CloudFront, Fastly, Bunny, Node.js, Python ASGI, Go,

    Ruby, Java, ASP.NET Core, Kong, Apigee, Tyk, and Traefik.

    '
  humanURL: https://docs.datadome.co/docs/integration-overview
  baseURL: https://docs.datadome.co
  tags:
  - Server SDK
  - CDN
  - API Gateway
  - Reverse Proxy
  properties:
  - type: Documentation
    url: https://docs.datadome.co/docs/integration-overview
  - type: GitHubOrganization
    url: https://github.com/DataDome
- aid: datadome:mobile-sdks
  name: DataDome Mobile SDKs
  description: 'Native iOS and Android SDKs (with React Native and Flutter

    wrappers) integrate with common HTTP libraries (OkHttp, Alamofire,

    Axios, Dio) so DataDome verdicts can be applied to mobile API

    traffic, not just web requests.

    '
  humanURL: https://docs.datadome.co/docs/integration-mobile-sdk
  baseURL: https://docs.datadome.co
  tags:
  - Mobile SDK
  - iOS
  - Android
  - React Native
  - Flutter
  properties:
  - type: Documentation
    url: https://docs.datadome.co/docs/integration-mobile-sdk
  - type: GitHubOrganization
    url: https://github.com/DataDome
- aid: datadome:datadome-account-api
  name: DataDome Account API
  description: The Account API from DataDome — 4 operation(s) for account.
  humanURL: https://datadome.co/products/bot-protect/
  baseURL: https://datadome.co
  tags:
  - Account
  properties:
  - type: OpenAPI
    url: openapi/datadome-account-api-openapi.yml
- aid: datadome:datadome-accountprotect-api
  name: DataDome AccountProtect API
  description: The AccountProtect API from DataDome — 1 operation(s) for accountprotect.
  humanURL: https://datadome.co/products/bot-protect/
  baseURL: https://datadome.co
  tags:
  - AccountProtect
  properties:
  - type: OpenAPI
    url: openapi/datadome-accountprotect-api-openapi.yml
- aid: datadome:datadome-customrules-api
  name: DataDome CustomRules API
  description: The CustomRules API from DataDome — 2 operation(s) for customrules.
  humanURL: https://datadome.co/products/bot-protect/
  baseURL: https://datadome.co
  tags:
  - CustomRules
  properties:
  - type: OpenAPI
    url: openapi/datadome-customrules-api-openapi.yml
- aid: datadome:datadome-endpoints-api
  name: DataDome Endpoints API
  description: The Endpoints API from DataDome — 2 operation(s) for endpoints.
  humanURL: https://datadome.co/products/bot-protect/
  baseURL: https://datadome.co
  tags:
  - Endpoints
  properties:
  - type: OpenAPI
    url: openapi/datadome-endpoints-api-openapi.yml
- aid: datadome:datadome-priorities-api
  name: DataDome Priorities API
  description: The Priorities API from DataDome — 3 operation(s) for priorities.
  humanURL: https://datadome.co/products/bot-protect/
  baseURL: https://datadome.co
  tags:
  - Priorities
  properties:
  - type: OpenAPI
    url: openapi/datadome-priorities-api-openapi.yml
- aid: datadome:datadome-templates-api
  name: DataDome Templates API
  description: The Templates API from DataDome — 2 operation(s) for templates.
  humanURL: https://datadome.co/products/bot-protect/
  baseURL: https://datadome.co
  tags:
  - Templates
  properties:
  - type: OpenAPI
    url: openapi/datadome-templates-api-openapi.yml
- aid: datadome:datadome-trustedproxies-api
  name: DataDome TrustedProxies API
  description: The TrustedProxies API from DataDome — 2 operation(s) for trustedproxies.
  humanURL: https://datadome.co/products/bot-protect/
  baseURL: https://datadome.co
  tags:
  - TrustedProxies
  properties:
  - type: OpenAPI
    url: openapi/datadome-trustedproxies-api-openapi.yml
- aid: datadome:datadome-verifiedmodels-api
  name: DataDome VerifiedModels API
  description: The VerifiedModels API from DataDome — 1 operation(s) for verifiedmodels.
  humanURL: https://datadome.co/products/bot-protect/
  baseURL: https://datadome.co
  tags:
  - VerifiedModels
  properties:
  - type: OpenAPI
    url: openapi/datadome-verifiedmodels-api-openapi.yml
features:
- name: Real-Time Decisioning
  description: Per-request verdicts returned in sub-millisecond windows at the edge.
- name: Wide Integration Footprint
  description: 40+ server-side and edge integrations covering web servers, CDNs, frameworks, and API gateways.
- name: Mobile SDK Coverage
  description: iOS, Android, React Native, and Flutter SDKs extend protection to native mobile traffic.
- name: Threat Intelligence Network
  description: Shared signals across the DataDome customer base power continuously updated bot intelligence.
- name: Agentic Trust
  description: Dedicated controls for governing AI-agent and LLM-driven traffic.
- name: PCI DSS 4 Client-Side Coverage
  description: Page Protect supports compliance with PCI DSS 4.0 client-side script governance requirements.
useCases:
- name: Bot and Scraping Defense
  description: Block credential stuffing, scraping, inventory hoarding, and fake-account creation on web and APIs.
- name: Account Takeover Prevention
  description: Detect and block ATO attempts at login and post-login flows.
- name: Ad Fraud Mitigation
  description: Filter invalid traffic from ad-funded properties.
- name: Client-Side Supply Chain Security
  description: Inventory and govern third-party scripts on sensitive pages.
- name: AI Agent Governance
  description: Identify, authenticate, and rate-limit autonomous agent traffic.
- name: DDoS Mitigation
  description: Defend against application-layer denial-of-service attacks.
integrations:
- name: Nginx
- name: Apache
- name: IIS
- name: HAProxy
- name: Cloudflare Workers
- name: AWS CloudFront
- name: Fastly
- name: Kong
- name: Apigee
- name: Tyk
- name: Traefik
- name: Node.js
- name: Python ASGI
- name: Go
- name: Ruby
- name: Java
- name: ASP.NET Core
authentication:
- type: APIKey
  description: DataDome dashboard-issued API keys for server-side modules.
- type: SignedSensor
  description: Signed payloads exchanged between the JS tag/mobile SDK and DataDome decisioning.
common:
- type: AgenticAccess
  url: agentic-access/datadome-agentic-access.yml
- type: DomainSecurity
  url: security/datadome-domain-security.yml
- type: Authentication
  url: authentication/datadome-authentication.yml
- type: Website
  url: https://datadome.co/
- type: Products
  url: https://datadome.co/products/
- type: Documentation
  url: https://docs.datadome.co/
- type: APIReference
  url: https://docs.datadome.co/reference
- type: Blog
  url: https://datadome.co/blog/
- type: GitHubOrganization
  url: https://github.com/DataDome
- type: LinkedIn
  url: https://www.linkedin.com/company/datadome/
- type: Twitter
  url: https://twitter.com/datadome
- type: Status
  url: https://status.datadome.co/
- type: Contact
  url: https://datadome.co/contact/
- type: LlmsText
  url: https://docs.datadome.co/llms.txt
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com