Sign In

Arcjet logo

Arcjet

Runtime security for AI agents, coding agents and web apps

4.3 Editor rating
#1 in Cybersecurity Rank
50
AppsInsight Score Average
Free plan Paid from $25 15-day trial Founded 2023 11-50 employees Cybersecurity
Also listed in AI Agents API Tools
  • Trusted by 10,000+ buyers worldwide
  • 500+ verified reviews from real users
  • Updated weekly fresh & accurate data
  • Independent editorial research 100% unbiased

What is Arcjet?

Runtime security for AI agents, coding agents and web apps Arcjet is a security platform for code that makes decisions on its own.

Arcjet screenshot

Our verdict

Arcjet puts the allow-or-block decision inside your application and agent code instead of at a network edge, which means rules can see user, session and tool-call context. It covers prompt injection, PII leaks, bots and abuse in one SDK, supports a long list of frameworks, and has a 15-day trial followed by a free tier.

Reviewed by Ashley Richmond Chief Marketing Officer at AppsInsight Last updated October 6, 2026

Full review

Arcjet is a security platform for code that makes decisions on its own. Founded by David Mytton in 2023 and headquartered in San Francisco with an office hub in New York, it started as a developer-first way to add bot protection, rate limiting and a web application firewall (WAF) inside application code. Its current pitch is wider: runtime security for AI agents, whether those are coding agents such as Claude Code, Cursor, GitHub Copilot, OpenAI Codex and Muse Code, or custom agents written in JavaScript, TypeScript, Python or Go.

What Arcjet actually does

For coding agents, Arcjet hooks into the events each tool already fires, so a policy can allow or block a tool call before it runs. Policies are written in OPA Rego. For custom agents, the SDKs let you ask which agents are running, whether an action should be allowed, and what happened afterwards. On top of

Arcjet is a security platform for code that makes decisions on its own. Founded by David Mytton in 2023 and headquartered in San Francisco with an office hub in New York, it started as a developer-first way to add bot protection, rate limiting and a web application firewall (WAF) inside application code. Its current pitch is wider: runtime security for AI agents, whether those are coding agents such as Claude Code, Cursor, GitHub Copilot, OpenAI Codex and Muse Code, or custom agents written in JavaScript, TypeScript, Python or Go.

What Arcjet actually does

For coding agents, Arcjet hooks into the events each tool already fires, so a policy can allow or block a tool call before it runs. Policies are written in OPA Rego. For custom agents, the SDKs let you ask which agents are running, whether an action should be allowed, and what happened afterwards. On top of that sit detections for prompt injection, PII and secrets, plus threat intelligence that checks the URLs, APIs and MCP servers an agent tries to reach.

The older web security features remain part of the same product: bot detection, rate limiting, Shield WAF, email validation, signup form protection and request filters. Because they run in your code rather than at the edge, rules can use real user and session context.

Pricing and setup

Plans are Individual at $25 per month, Startup at $299 per month and a custom Enterprise tier, each billed with usage fees: $5 per million web requests and $50 per million agent requests. Paid plans start with a 15-day trial, after which an account falls back to a free plan capped at 10,000 requests per month. Setup means installing an SDK for your framework (Next.js, Node.js, Express, FastAPI, Flask, SvelteKit and a dozen more) or connecting the MCP server, so expect developer time rather than a point-and-click install.

Who should look at it

Engineering and security teams shipping AI features that touch real data and real tools. Arcjet says it has completed a SOC 2 Type 2 examination, with the report available in its Trust Center.

Who it's for

Best for

  • Developer teams shipping AI agents or AI-powered features who need guardrails against prompt injection
  • data leaks and runaway token spend
  • and who are happy to integrate an SDK.

Not ideal for

  • Teams that want a no-code security dashboard with no engineering work
  • or buyers who need one flat price with no usage fees.

How we tested

AppsInsight desk research, 5 October 2026. We read Arcjet's homepage, pricing page, About page and docs, and checked prices against the official pricing page on that date. We did not run a hands-on production deployment. Claims about compliance and customer numbers are Arcjet's own.

Security & compliance

SOC 2 Type 2 (Security, Availability, Confidentiality)

At a glance

PricingFree+Paid
Starting price$25
Free planYes
Free trialYes (15 days)
Pricing pageView pricing
PlatformsAPI / SDK, CLI / Terminal
APIYes
CompanyArcjet Labs, Inc.
Apps Insight Score50/100
ImplementationMedium
Learning curveIntermediate
ComplianceSOC 2 Type 2 (Security, Availability, Confidentiality)

Why this app scored 50/100

Editorial Review 26/30
  • Product quality 8/10 8/10
  • Ease of use 3.5/5 4/5
  • Feature depth 4.5/5 5/5
  • Innovation 4.5/5 5/5
  • Value for money 2/3 2/3
  • Recommendation confidence 1.5/2 2/2
Trust & Verification 10/25
  • AppsInsight badge installed Badge not installed 0/15
  • HTTPS website HTTPS 1/1
  • Business support email Provided 1/1
  • Privacy policy published Provided 2/2
  • Terms of service published Provided 1/1
  • Security certifications SOC 2 Type 2 (Security, Availability, Confidentiality) 2/2
  • Knowledge base / help center Provided 2/2
  • Social profiles linked 4 profiles linked 1/1
Community 0/20
  • Verified reviews & rating 0 reviews (5 needed) 0/15
  • Recent reviews No reviews yet 0/5
Product Profile 11/20
  • Detailed description 338 words 2/3
  • Screenshots 2 screenshots 1/3
  • Demo video No demo video 0/2
  • FAQ 6 items 1/2
  • Feature list 9 items 1/2
  • Pricing published Plan tiers published 3/3
  • Pros & cons Pros & cons listed 1/1
  • Integrations 1 integration 0/2
  • API available Yes 1/1
  • Company details 3 of 3 details filled 1/1
Freshness 3/5
  • Listing recently updated Updated 0 days ago 3/3
  • Recent changelog entry No changelog entries 0/2

Editorial points are assigned by AppsInsight editors and cannot be purchased or influenced.

Integrations

Built for

How Arcjet compares

FeatureArcjetiFixAiNivoli Edge
Rating4.3 / 53.8 / 53.7 / 5
PricingFree+PaidFree+PaidFree+Paid
Starting price$25——
Free planIncludedIncludedIncluded
Free trialYes (15 days)NoYes (14 days)
PlatformsAPI / SDK, CLI / Terminal—Web app, Self-hosted / On-premise, WordPress plugin
Best forDeveloper teams shipping AI agents or AI-powered features who need guardrails against prompt injection, data leaks and runaway token spend, and who are happy to integrate an SDK.Teams deploying AI agents with real authority over money, data or customers, engineering leads who need audit evidence they can defend, and enterprises that want agent governance without building an eval harness.Public-facing WordPress publishers; site owners maintaining a secure license mailbox; agencies with up to ten sites needing pooled reports; teams willing to validate origin routing and cache exclusions

Arcjet vs iFixAi Arcjet vs Nivoli Edge

Key features

Prompt injection detection
Scans the text an agent is about to process and flags injection attempts before they reach the LLM, database or tool.
Sensitive information detection
Screens inputs for PII and secrets, and can redact sensitive findings from retained evidence.
Coding agent policies
Enforces policy on Claude Code, GitHub Copilot, Cursor, OpenAI Codex and Muse Code through the hooks each tool already fires, with policies written in OPA Rego.
Custom agent guards
SDKs for JavaScript, TypeScript, Python and Go to authorize tool calls and record what an agent did and why.
Real-time threat intelligence
Checks external requests an agent makes against malicious URLs, APIs, MCP servers and malware before they go out.
Bot protection, rate limiting and Shield WAF
Classic application security that runs in code, so rules can use real identity and session context.
Email validation and signup form protection
Blocks disposable or invalid addresses and abusive signups at registration.
MCP server and remote rules
Create rules in dry-run mode, check the impact, then promote them to live without redeploying code.
SIEM export
On Enterprise, send decisions to Datadog, Splunk, SentinelOne, Panther or Amazon S3 for alerting and retention.

Key benefits

  • Decisions are made in code with real user and session context
  • One SDK covers agent security and classic web protection
  • Dry-run mode lets you test a rule before it blocks anything

Pricing

Free planPaid from $2515-day trial
Solo

Free (after trial)

$0 /mo

  • Account continues on a free plan after the 15-day trial. Hard cap of 10
  • 000 requests per month
  • no overage billing.
Solo

Individual

$25 /mo

  • 1 team member. 1 hour log retention. Email support. 15-day trial. Usage fees apply.
Team

Startup

$299 /mo

  • 2 team members. 24 hour log retention. Email and Slack support. 15-day trial. Usage fees apply.
Enterprise

Enterprise

Custom /mo

  • Unlimited team members. SIEM export. Priority support. Book a demo. Usage fees apply.

View official pricing

Pros & Cons

Pros

  • SDKs for more than a dozen frameworks, including Next.js, Node.js, Express, FastAPI, Flask and SvelteKit
  • Covers both coding agents and custom agents with the same policy engine
  • 15-day trial, then an account continues on a free plan with 10,000 requests per month
  • Completed a SOC 2 Type 2 examination, per its own About page
  • Docs at docs.arcjet.com and a public GitHub organisation with SDKs and agent skills

Cons

  • Usage fees ($5 per 1M web requests, $50 per 1M agent requests) are added on top of the plan price
  • Individual plan has one team member and one hour of log retention
  • Needs engineering time to integrate, so it is not a point-and-click tool
  • Enterprise pricing is custom and only available through a demo

Screenshots & media

Arcjet alternatives

View all alternatives

User reviews

No reviews yet. Be the first to review this app.

Write a review

Already have an account? Log in to track your reviews.

Frequently asked questions

What does Arcjet do?
Arcjet is a runtime security platform for AI agents and web applications. It detects prompt injection and PII leaks, enforces policy on coding agents and custom agents, and provides bot protection, rate limiting and a WAF inside application code.
How much does Arcjet cost?
Individual is $25 per month and Startup is $299 per month, each with a 15-day trial. Enterprise is custom. Usage fees apply on every plan: $5 per million web requests and $50 per million agent requests.
Is there a free plan?
Yes. When the 15-day trial ends, an account continues on a free plan limited to 10,000 requests per month. The limit is a hard stop, so you are not billed for going over it.
Which coding agents does Arcjet support?
Its docs list Claude Code, Cursor, GitHub Copilot, Muse Code and OpenAI Codex, enforced through the hooks each tool already provides.
Does Arcjet support open source projects?
Arcjet's pricing page says many open source projects use the Individual plan, which suits non-commercial, community-maintained work.
Is Arcjet SOC 2 compliant?
Arcjet says it has completed a SOC 2 Type 2 examination covering Security, Availability and Confidentiality, with the report in its Trust Center.