Application security that runs inside your code

Runtime protection for HTTP routes, agent tools & AI workflows

Start with a prompt

1. Run: npx skills add arcjet/skills
2. Add Arcjet protection to my app

Installed where you already work

Your coding agent uses Arcjet's skills to write framework-native SDK code. Security lives with the code, in the same pull request.

Enforced with full application context

Arcjet runs inline — with identity, session, route, and spend context that no proxy or gateway can see. Across HTTP endpoints, agent tool calls, queues, and workflow steps.

Governed by your team

Your agent analyzes traffic, explains denials, and proposes rule changes. You review and approve before anything changes in production.

Proxies and WAFs can't see AI features

Unauthorized tool calls

Agents issue refunds, expose data, escalate privileges. The prompt looks harmless. The tool call causes the damage.

Data exfiltration

Sensitive data leaks through tool outputs, prompts, and model context — paths that never cross a proxy or an HTTP boundary.

Cost explosion

Automated traffic and runaway agent loops burn through token budgets. Without inline visibility, you can't stop it before the bill lands.

What Arcjet protects Runtime security built into your app

AI endpoint abuse protection

Enforce per-user and per-org token budgets. Block automation before it reaches inference.

const aj = arcjet({
  characteristics: ["userId", "orgId"], // User/org scope
  rules: [
    detectBot({ ... }), // Block scrapers and automation
    tokenBucket({ ... }), // enforce token budgets
  ],
});

const decision = await aj.protect(req, {
  userId: user.id,
  orgId: user.orgId,
  requested: estimatedTokens, // token cost for LLM call
});

Prompt injection detection

Catch hostile prompts in user input and tool outputs before they reach the model.

const aj = arcjet({
  rules: [detectPromptInjection({ mode: "LIVE" })],
});

// Detect prompt — block before inference
const decision = await aj.protect(req, {
  detectPromptInjectionMessage: userMessage,
});

if (decision.isDenied() && decision.reason.isPromptInjection()) {
  return new Response("Forbidden", { status: 403 });
}

AI data loss prevention

Strip sensitive data before it reaches model context, logs, or third-party tools.

const aj = arcjet({
  rules: [
    sensitiveInfo({
      mode: "LIVE",
      deny: ["EMAIL", "CREDIT_CARD_NUMBER"],
    }),
  ],
});

// Catch before passing to LLM
const decision = await aj.protect(req, {
  sensitiveInfoValue: userMessage,
});

if (decision.isDenied() && decision.reason.isSensitiveInfo()) {
  return new Response("Sensitive data blocked", { status: 403 });
}

Agent tool controls

Scope what agents can call — by identity, role, and route — with the same rules you write for human users.

const aj = arcjet({
  characteristics: ["agentId"],
});

// Per-request
const ajForAdmin = aj.withRule(
  tokenBucket({ rate: 1000, interval: "1m", capacity: 1000 })
);
const ajForMember = aj.withRule(
  tokenBucket({ rate: 100, interval: "1m", capacity: 100 })
);

let decision;
if (role === "admin") {
  decision = ajForAdmin.protect(req, { agentId: agent.id });
} else {
  decision = ajForMember.protect(req, { agentId: agent.id });
}

if (decision.isDenied()) {
  return new Response("Unauthorized", { status: 403 });
}
}

Runtime security that ships with your code

Start with a prompt

1. Run: npx skills add arcjet/skills
2. Add Arcjet protection to my app