WebDecoy Is Now on the Shopify App Store
WebDecoy is live on Shopify. Detect bot traffic, investigate risky orders, track AI crawlers and referrals, and choose your response with Shopify Flow.
integrationWebDecoy now reads your Fastly logs to find crawlers that never run JavaScript, and blocks addresses in a Fastly ACL. No application code.
WebDecoy’s Fastly integration now does detection and protection. It reads the requests your Fastly service answers, reports the automated ones, and blocks addresses in a Fastly Access Control List (ACL). Both halves are configuration in your Fastly service. Nothing is installed in your application.
Until now, Fastly was only a place to push blocks. That was half a product. A block list is only as good as what fills it, and a browser tag cannot see a client that never runs JavaScript: AI crawlers, scrapers, curl, headless scripts. Fastly sees every one of them, so Fastly is now also where WebDecoy looks.
Fastly can post a log line for every request to an HTTPS endpoint. WebDecoy gives you that endpoint, a secret header and a log format. Each line carries the client address, user agent, path, status, cache result and the JA4 TLS fingerprint, which identifies the client software even when the user agent lies.
WebDecoy classifies each request:
Because the log is sent after Fastly has answered, detection never sits in your request path and never changes a response.
On our own test service, a stranger’s curl from a hosting network found the brand-new domain within minutes, before we had told anyone it existed. It was reported as a crawler.
Blocking uses a Fastly ACL and one line of VCL that you control:
if (client.ip ~ webdecoy_blocklist) {
error 403 "Forbidden";
}From the Fastly page in WebDecoy, choose Block an address, give it a duration and a reason, and apply it. WebDecoy adds the ACL entry and then reads it back from Fastly to confirm that Fastly holds it. When the block expires, WebDecoy removes it again: a Fastly ACL entry has no expiry of its own. Every change is listed with its state, its author and its reason, so a block made at 2 a.m. can still be explained a month later.
ACL entries take effect without a new service version, so a block applies within seconds. In our end-to-end test, the blocked address got 403 on the next request and 200 about a minute after we removed the block.
Automatic blocking from detections acts only on detections whose score has been calibrated. Until then, you decide what gets blocked.
One limit to know: a Fastly ACL holds addresses only, and your VCL decides where it is consulted. A block applies everywhere that service consults the ACL, not to one hostname. WebDecoy says so next to every block rather than letting you assume otherwise.
global scope, for all services or only the ones WebDecoy should manage.curl -A "WebDecoy-Test/1.0" https://your-site.example/A detection labeled Test appears once Fastly delivers the log. The first delivery after activating can take a few minutes, after which Fastly sends batches every few seconds.
The Fastly setup guide has every field, including the log format to paste.
Fastly joins Cloudflare, Netlify and Vercel as a platform where WebDecoy both detects and protects at the edge. If your site runs on Fastly, you can now see the traffic your analytics never shows, and act on it where it arrives.
Connect Fastly in WebDecoy or read the setup guide.
No. Detection uses a Fastly HTTPS logging endpoint, which is configuration in your Fastly service. Blocking uses a Fastly ACL and a one-line VCL snippet. Nothing is installed in your application.
No. Fastly sends the log after it has answered the request, so WebDecoy is never in the request path. Log streaming changes no response; only the ACL block does, and only for addresses you have blocked.
No. Every request in the stream is classified, the automated ones are reported to your dashboard, and the rest are counted and dropped. Ordinary visitors are never stored.
No. A Fastly ACL holds addresses only, and your VCL decides where it is consulted, so a block applies everywhere that service consults the ACL. WebDecoy says so next to every block.
You do not need it. Fastly's dashboard shows ACL names, not IDs, so WebDecoy asks for the name and looks up the ID with your API token when you save.
WebDecoy is live on Shopify. Detect bot traffic, investigate risky orders, track AI crawlers and referrals, and choose your response with Shopify Flow.
integrationConnect Claude, ChatGPT or Codex to WebDecoy. Install bot detection in your app, prove it works, and ask what bots hit your site, from your assistant.
integrationWebDecoy's Netlify extension now protects selected paths. Install the sensor, enable clearance checks, verify the deployment, and roll out in Monitor mode.
integrationLike this post? Share it with your friends!
Get a personalized demo from our team.