Arcjet vs WebDecoy

Arcjet vs WebDecoy. Rate limiting SDK vs multi-signal bot detection. Complementary tools that work great together.

Arcjet and WebDecoy solve different problems and work great together. Arcjet excels at rate limiting, blocking volume-based attacks. WebDecoy excels at bot detection. Catching sophisticated automation regardless of request volume.

What Each Does

Arcjet: Rate Limiting SDK

User Request
    ↓
Arcjet SDK
    ├── Rate Limiting
    │   ├── Token bucket
    │   ├── Sliding window
    │   └── Fixed window
    ├── Shield Rules
    │   └── Common attack patterns
    └── Basic Bot Detection
        └── Known bot signatures
    ↓
Allow / Rate Limit / Block

Arcjet’s focus: Prevent abuse through rate limiting. Block users exceeding request thresholds.

Strengths: Easy integration, free tier, effective against volume-based attacks.

WebDecoy: Multi-Signal Bot Detection

User Request
    ↓
WebDecoy Detection Stack
    ├── TLS Fingerprinting (JA3/JA4)
    │   └── User-Agent mismatch detection
    ├── IP Enrichment
    │   ├── AbuseIPDB reputation plus VPN, proxy and datacenter detection
    │   └── Datacenter/VPN/Tor detection
    ├── Geographic Consistency
    │   └── Timezone/IP/Language correlation
    ├── Honeypot Detection
    │   ├── Decoy Links (hidden spider traps)
    │   └── Endpoint Decoys (fake API routes)
    ├── Behavioral Analysis (Bot Scanner)
    │   └── Mouse entropy, keystrokes, forms
    └── Vision AI Detection (FCaptcha)
        └── Signals designed for screenshot-driven agents
    ↓
Threat Score (0-100) → Allow / Challenge / Block

WebDecoy’s focus: Detect bots through multiple independent signals. Catch sophisticated automation that evades rate limits.

Strengths: Multi-signal detection, honeypots, vision AI detection, TLS fingerprinting.

Detection Comparison

CapabilityArcjetWebDecoy
Rate LimitingPrimary featureRate-limit rules in the Node SDK (rateLimit())
TLS FingerprintingBasicJA3 + JA4 with mismatch detection
HoneypotsNoDecoy Links + Endpoint Decoys
IP IntelligenceBasicAbuseIPDB reputation plus VPN, proxy and datacenter detection
Geographic ChecksNoTimezone/IP/Language consistency
Behavioral AnalysisNoMouse entropy, keystrokes, forms
Vision AI DetectionNoFCaptcha signals designed for screenshot-driven agents
AI Crawler DetectionBasic signaturesRegistry of 186 known bots and AI agents
Free TierYes (10K/month)Yes (1 property, 5,000 stored events/month)
SIEM IntegrationNoEvery paid plan (Splunk, CrowdStrike Falcon LogScale, Datadog)

Why You Need Both

What Arcjet Catches

Arcjet is effective against:

  • DDoS at application layer - Volume-based attacks
  • Brute force attacks - High-volume credential attempts
  • API abuse - Excessive requests from single sources
  • Basic bots - Known signatures

What Arcjet Misses

Sophisticated attackers evade rate limiting:

  • Rotating IPs - Distribute requests across proxies
  • Low-and-slow - Stay under rate limits
  • Residential proxies - Look like legitimate traffic
  • Distributed attacks - Many IPs, few requests each

A bot making 10 requests/minute across 100 rotating IPs won’t trigger rate limits.

What WebDecoy Catches

WebDecoy catches what rate limiting misses:

The snippets below are illustrative examples of the evidence involved, simplified for readability; they are not WebDecoy’s API output format.

TLS Fingerprinting

// Illustrative example: bot claims Chrome but has Playwright TLS fingerprint
{
  "tls": {
    "claimed": "Chrome/121",
    "actual": "Playwright",
    "mismatch": true,
    "score": +45
  }
}

Honeypots

// Bot follows hidden link no human sees
{
  "honeypot": {
    "decoy_link_triggered": true,
    "path": "/trap/a8f3d2e1",
    "score": +50
  }
}

IP Enrichment

// IP with a poor AbuseIPDB reputation, from a datacenter range
{
  "ip_enrichment": {
    "abuseipdb": { "score": 85 },
    "datacenter": true,
    "score": +35
  }
}

Vision AI Detection

// FCaptcha signals designed for an AI agent controlling a browser
{
  "vision_ai": {
    "screenshot_loop": true,
    "pixel_perfect_clicks": true,
    "classification": "vision_ai_agent"
  }
}

Using Both Together

The ideal setup uses Arcjet for rate limiting and WebDecoy for detection:

import Arcjet from '@arcjet/node';
import { WebDecoy } from '@webdecoy/node';

const aj = new Arcjet({ key: process.env.ARCJET_KEY });
const webdecoy = new WebDecoy({ apiKey: process.env.WEBDECOY_KEY });

app.post('/api/login', async (req, res) => {
  // Layer 1: Rate limiting (Arcjet)
  const arcjetDecision = await aj.protect(req, {
    rules: [
      rateLimit({ max: 5, window: '1m' }),  // 5 attempts per minute
    ]
  });

  if (arcjetDecision.isDenied()) {
    return res.status(429).json({
      error: 'Too many requests',
      retryAfter: arcjetDecision.headers['Retry-After']
    });
  }

  // Layer 2: Bot detection (WebDecoy)
  // Calling protect() directly: your code decides what to do with the verdict.
  const { allowed, detection } = await webdecoy.protect({
    method: req.method,
    path: req.path,
    ip: req.ip,
    user_agent: req.get('user-agent'),
    headers: req.headers,
    timestamp: Date.now(),
  });

  if (!allowed) {
    console.log('Bot blocked:', {
      threat_level: detection.threat_level,
      bot_type: detection.bot_type,
      confidence: detection.confidence
    });
    return res.status(403).json({ error: 'Access denied' });
  }

  if (detection.decision === 'challenge') {
    return res.redirect('/captcha');
  }

  // Process legitimate login
  // ...
});

This gives you:

  • Arcjet: Stops volume-based attacks immediately
  • WebDecoy: Flags sophisticated bots that stay under rate limits

Block the Actor, Not the IP

Arcjet runs its bot rules inside your application, judging each request in-process. But a rotating scraper is still evaluated one request at a time, and the block stays inside your app.

WebDecoy treats a rotating adversary as a single actor. It correlates every request into a persistent identity built from composite fingerprints: JA4 (the TLS handshake, which a proxy can’t rewrite), device signals, and cryptographic agent identity. So one scraper cycling through thousands of residential IPs collapses into one actor instead of thousands of anonymous hits.

Then enforcement follows the actor, and it can move above your app: when an actor is a confirmed rotator with a non-browser JA4, a Block actor at WAF response action can push a JA4-based rule into your own AWS WAF, or into Cloudflare if your zone has Bot Management (Cloudflare’s Enterprise add-on), so the block follows the actor across the IPs it rotates to, at your edge rather than in your application. It is never built from a browser-like fingerprint real users could share. Automatic blocking from detections is held off until scores are calibrated, so today you review and apply blocks yourself.

Deep dive: Defeat IP Rotation: Block Bots by JA4 at the WAF

Pricing Comparison

Arcjet

  • Free: 10,000 requests/month
  • Pro: $25/month (100K requests)
  • Business: Custom pricing

WebDecoy

PlanPricePropertiesStored eventsFeatures
Free$01 property5,000 stored events/moContinuous detection, seven days of detail
Starter$20/mo3 properties50,000 stored events/mo90-day history, webhooks, basic response actions
Pro$99/mo10 properties500,000 stored events/moFull enrichment, persistent actor identity, integrations, enforcement
Agency$299/mo25 properties2,000,000 pooled stored events/moClient reporting and everything in Pro

WebDecoy keeps detection running on every tier. See the current pricing page for the source of truth.

Combined Cost

For comprehensive protection:

  • Arcjet Pro: $25/month (rate limiting)
  • WebDecoy Starter: $20/month (bot detection)
  • Total: $45/month for both layers (or $25/month on WebDecoy’s Free plan)

When to Choose Each

Arcjet Only If:

  • Rate limiting is your only need
  • You want to start with a free tier
  • Basic bot signatures are sufficient
  • Budget is very constrained

WebDecoy Only If:

  • You already have rate limiting (CDN, WAF, etc.), or the Node SDK’s rate-limit rules are enough
  • Sophisticated scrapers are your primary threat
  • You need vision AI detection
  • You want honeypot-based detection

Both If:

  • You want comprehensive protection
  • You face both volume and sophistication threats
  • Defense in depth is worth about $45/month

Real-World Scenario

Threat: Credential stuffing attack with rotating residential proxies.

Arcjet alone:

  • Each IP makes 3 requests (under 5/minute limit)
  • 1000 IPs = 3000 attempts
  • Result: Attack succeeds under rate limits

WebDecoy alone:

  • TLS fingerprint: Automation detected ✅
  • Honeypot: Login form honeypot filled ✅
  • Behavioral: Keystroke timing anomaly ✅
  • Result: Flagged (blocked if you run the SDK in enforce mode); the Node SDK’s rate-limit rules can also cap volume

Both together:

  • Arcjet: Catches any IP exceeding limits
  • WebDecoy: Catches automation under limits
  • Result: Comprehensive protection

What WebDecoy Provides

  1. Multi-Signal Detection - TLS + IP + Geo + Behavioral + Honeypots
  2. Vision AI Detection - FCaptcha has signals designed to detect screenshot-driven agents such as GPT-4V, Claude Computer Use and Operator
  3. Honeypot Technology - Decoy Links and Endpoint Decoys
  4. IP Enrichment - AbuseIPDB reputation plus VPN, proxy and datacenter detection
  5. TLS Fingerprinting - JA3/JA4 with User-Agent mismatch detection
  6. Transparent Detection - See exactly which signals triggered
  7. SIEM Integration - Splunk, CrowdStrike Falcon LogScale and Datadog on every paid plan

Get Started

Try WebDecoy: Start Your Free Trial and add bot detection to your Arcjet rate limiting.

Using Arcjet already? WebDecoy complements it perfectly. View Integration Docs

Questions? Contact us to discuss your security stack.

Frequently Asked Questions

What's the main difference between Arcjet and WebDecoy?

Arcjet focuses on rate limiting and basic bot protection. WebDecoy provides comprehensive bot detection with honeypots, TLS fingerprinting, behavioral analysis, IP enrichment, and vision AI detection. Different tools that complement each other well.

Can I use Arcjet and WebDecoy together?

Yes, they're highly complementary. Arcjet handles rate limiting and volume-based attacks. WebDecoy catches sophisticated bots that stay under rate limits through multi-signal detection.

Which has a free tier?

Both do. Arcjet offers a free tier with 10,000 requests/month. WebDecoy has a permanent Free plan (1 property, 5,000 stored events/month); paid plans start at $20/month.

Which is better for sophisticated scrapers?

WebDecoy. Sophisticated scrapers rotate IPs and stay under rate limits to evade Arcjet. WebDecoy catches them through honeypots, TLS fingerprinting, and behavioral analysis regardless of request volume.

Need help choosing a bot protection solution?

Our team can help you compare options and find the right fit for your needs.

Talk to an Expert