Multi-Layer Bot Detection Platform
WebDecoy combines honeypot deception, behavioral analysis, and an edge sensor with deliberately different blind spots, then resolves every detection to one actor identity and lets you decide what happens next.
ONE REQUEST. ONE LASTING DECISION.
See the whole defense loop.
A bot touches your app once. WebDecoy turns that request into an identity with evidence. Approve a block, or let an enforcement rule you configured apply it, and the return visit is refused.
REQUEST Unknown client reaches your application.
OBSERVE The SDK captures behavior and fingerprints from the request.
IDENTIFY Ingest resolves the signals to one persistent bot identity.
ENFORCE You approve the block, or an enforcement rule you configured applies it at the app or edge.
BLOCKED With the block in place, the same actor returns and is refused.
- 01Unknown botGET /pricing
- 02Your appSDK observes
- 03WebDecoy ingestSignals arrive
- 04Actor identifiedAutomation · 94 risk
- 05Block approvedBy you or a rule you set
AI Journey Insights
Understand what automated traffic is after
Turn an actor’s observed requests into a clear starting point for investigation. AI identifies likely collection targets and supported access patterns; measured behavior shows breadth, concentration, and timing.
Open Actors → Journey, read the takeaway, and expand a finding to inspect its matching requests. Every sample shows its scope, and unclear patterns stay undetermined. Analysis runs on demand, with saved results reused.
From an observed journey
This sample reaches 45 distinct targets, mostly requesting each once.
- Breadth
- 45 distinct targets
- Busiest target
- 4 of 48 requests
36 of the 48 requests used article or documentation routes. Expand the evidence to see which requests matched.
Behavioral Analysis Engine
Go beyond honeypots with real-time behavioral analysis. Bot Scanner detects headless browsers and automation frameworks that evade traditional detection methods.
Headless Detection
Detect Puppeteer, Playwright, Selenium, and Nightmare using browser fingerprinting and automation signals.
TLS Fingerprinting
JA4 TLS fingerprints reveal the true client behind a disguised user agent, and become the actor identity that follows a bot across every IP it rotates through.
Behavioral Signals
Mouse entropy, interaction timing, and scroll patterns distinguish real users from automation scripts.
IP Enrichment
AbuseIPDB reputation plus VPN, proxy and datacenter detection, with MaxMind GeoIP location.
AI Traffic Exchange
See what AI crawlers take, what ChatGPT, Claude, Gemini, Perplexity and others send back, and the ratio between them. A referral is only counted when the visit carries a header naming the AI platform, and platforms frequently strip it, so referrals are a floor and the ratio an upper bound. Freeze the result as a shareable report.
<!-- One line to install Bot Scanner -->
<script
async
src="https://cdn.webdecoy.com/bot-detection/v1/bot-detection.min.js"
data-aid="your-property-uuid"
data-sid="your-scanner-uuid"
></script>
// Prefer server-side? Use the Node SDK instead.
npm install @webdecoy/node
import { WebDecoy, tripwire, honeytoken } from '@webdecoy/node';The Crawlers a Page Tag Can Never See
Googlebot’s crawl pass is plain HTTP with no DOM. GPTBot and ClaudeBot never run JavaScript at all. Cloudflare and Netlify edge sensors observe those requests before your origin. Netlify can also validate clearance on the protected paths you choose.
Sees the Crawl Pass
Googlebot’s crawl pass, GPTBot, ClaudeBot, CCBot, PerplexityBot, ByteSpider, Amazonbot, and curl (plus your robots.txt and sitemap fetches).
Impersonation at the Edge
Chrome always sends sec-ch-ua on a navigation. A request claiming Chrome without it is lying: a check impossible from JavaScript, because the impersonator never runs any.
One-Click Install
Connect Cloudflare, pick a zone, deploy. Preflight refuses route conflicts and grey-cloud zones rather than silently no-op’ing. Uninstall is one click too.
Fails Open by Design
The origin response returns unconditionally; the beacon is never awaited on the response path, and an adversarial test suite proves it stays up when everything downstream fails.
Now available: Netlify monitoring and clearance enforcement. Install the extension, verify reporting, and start in Monitor before protecting selected paths.
Verify Agents. Catch Impersonators. Grade Humans.
A user-agent string is a claim, and claims are free. WebDecoy makes a crawler earn the allowlist: published IP ranges with forward-confirmed reverse DNS today, cryptographic signatures as operators adopt them.
IP Range + Forward rDNS
The primary path, and the one Google itself recommends: published IP ranges plus reverse DNS that must forward-confirm back to the source IP.
Agent Impersonation
Fake GPTBot, Googlebot from a datacenter or VPN host, a crawler whose rDNS points elsewhere. Each becomes a tripwire-grade detection.
Signature Verification
RFC 9421 Web Bot Auth signatures checked against the operator’s published key directory. Few operators sign today, but the verification is in place for when they do.
Graded Human Trust
Clearance tokens carry a trust level (clean, human-likely, attested-human), and routes can require a minimum grade.
Core Detection Features
AI Bot Detection
Identify GPTBot, ClaudeBot, Perplexity, and 20+ other AI scrapers, then prove it. A signature or a published IP range earns "verified"; a matching user agent alone earns nothing.
Verified Agents
See every AI agent that touched your site, how its identity was established, and who tried to impersonate it, with per-agent allow and deny overrides.
Custom Honeypots
Create invisible decoy links specifically designed to attract bots while remaining invisible to real users. Customize paths, content, and triggers.
Zero-Setup Hosting, BYO Domain Optional
Start instantly on the WebDecoy shared domain: no DNS, no setup. Or bring your own domain with a simple CNAME/A record when you want decoys under your own brand.
Instant Response Actions
Trip a decoy and the bot loses its session clearance on every IP it rotates to. Auto-expiring rules in your Cloudflare or AWS WAF can stop datacenter bots at the edge you already own.
Data Poisoning
Return false or misleading data to bots. Train their models on intentionally bad data to reduce their effectiveness.
Endpoint Decoys
Deploy API honeypots that mimic real endpoints. Detect SQL injection, credential stuffing, and API enumeration attempts. Real users have no reason to call an endpoint that does not exist.
Geographic Consistency
Analyze timezone, language, and GeoIP data to detect VPNs and proxies. Score visitor consistency and flag location spoofing in real-time.
AI Traffic Exchange
See what AI crawlers take from your site and what ChatGPT, Claude, Gemini and Perplexity send back. Referrals are a floor, because platforms often strip the header that identifies them.
Endpoint Decoys: API Honeypot Protection
Advanced API security that catches attackers before they reach your real infrastructure. Deploy fake endpoints that detect and analyze malicious API traffic in real-time.
Attack Detection
Automatically detect and categorize attack patterns:
- Critical SQL Injection
- Critical Command Injection
- Critical XXE Attacks
- High XSS & Path Traversal
Forensic Capture
Full attack payload analysis:
- Request body capture
- HTTP method tracking
- Authorization header detection
- Content-type analysis
Zero False Positives
Only real attackers trigger detections:
- Endpoints don't exist in your app
- Legitimate users never find them
- Only scanners & attackers trigger
- AbuseIPDB integration
Real-Time Analytics Dashboard
Monitor all bot detection activity in real-time. See which bots visit your site, when they visit, what they access, and take immediate action.
Detection Timeline
View bot activity over time with interactive charts and graphs
Bot Distribution
See which bots are targeting you most frequently
Geographic Analysis
Track bot activity by location and IP address
Integrations
Connect WebDecoy to your security stack. Block bots at the edge, forward detection events to your SIEM, and alert your team.
CDN & Edge
- Cloudflare WAF
- Fastly
Cloud WAF
- AWS WAF
- Cloudflare Firewall
- JA4 actor rules + IP blocks
Observability
- Datadog
- Splunk (HEC)
- CrowdStrike LogScale
Automation
- Vercel Edge
- Custom Webhooks
- REST API
MITRE ATT&CK Mapping
WebDecoy maps each detection to a MITRE ATT&CK tactic, so your SOC team can file bot activity under the same framework as the rest of its alerts.
- Reconnaissance (TA0043) - Web crawling, AI bot detection
- Credential Access (TA0006) - Brute force, credential stuffing
- Execution (TA0002) - SQL injection, command injection
- Discovery (TA0007) - Path traversal, API enumeration
{
"event": "detection",
"timestamp": "2026-07-15T10:30:00Z",
"detection": {
"id": "det_abc123",
"decoy_id": "decoy_uuid",
"organization_id": "org_xyz789",
"ip_address": "192.168.1.100",
"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64)...",
"bot_score": 92,
"timestamp": "2026-07-15T10:30:00Z",
"rules_enforced": true,
"source": "decoy_link"
},
"metadata": {}
}
// The payload is compact. Fetch the full detection,
// including its MITRE tactic, from the API by detection.id.Team and Account Features
Team Management
Invite team members with role-based access. Granular permissions for viewing data, managing settings, and billing.
Actor Enforcement Management
Manage both enforcement layers in one place: decoy-revoked session clearance for browser actors, and composite fingerprint rules (never a bare JA4) pushed to your Cloudflare or AWS WAF for datacenter bots. Every rule auto-expires and is reversible.
Enforcement Audit Trail
Enforcement changes are recorded, so you can see what was denied, approved, or dismissed and when.
Digest Emails
A periodic digest summarizing what your sensors saw, instead of an email for every detection.
Security Basics
TLS on every endpoint that receives detection data, storage encrypted at rest by our infrastructure providers, and data separated by organization. See our DPA for the full list.
A Queue of Judgments, Not a Config Screen
Enforcement that starts blocking the moment you enable it is a leap of faith. WebDecoy builds the deny-list while still in monitor mode, so by the time you turn enforcement on you are acting on a list you have already read.
Monitor Builds the List
A decoy hit in monitor mode writes a pending deny-list entry that affects nothing: never minting, never the edge config. The list fills up while you are still watching.
Evidence, Not a Score
Every row explains itself in one sentence: which decoy fired, which path, how it was reachable, when. Approve or dismiss, and dismiss is as prominent as deny.
Enforce Is a Gate
Review browser verification, protected paths, and the deployed validator in Enforcement. Readiness checks identify missing setup before Enforce is available. Netlify uses its injected validator; provider WAF actions are a separate integration.
Honest Counters
Every number rendered as an outcome is an event count (mint attempts actually refused, requests actually challenged), never a row count dressed up as a result.
Protect the paths you choose. Clearance validators on Cloudflare, Netlify, and AWS CloudFront can require verification on scoped paths, including requests from clients that never run JavaScript. Provider WAF rules are a separate response option. Compare platform capabilities before configuring a policy.
Automated Threat Response
Once a judgment is approved, your response actions carry it out. Revoke the actor's session clearance, block datacenter bots at the edge, alert your team, and feed your SIEM.
Edge Blocking
Push a composite actor signature to Cloudflare or AWS WAF: challenge first, block last, auto-expiring. The safe, cheap layer for datacenter and scripted bots; session clearance handles the residential rotators no rule can catch.
Monitor first, enforce when ready
Webhook Alerts
Send detection alerts to Slack, or HMAC-signed detection events to any HTTPS endpoint you control. Trigger your own playbooks from there.
HMAC-SHA256 signed payloads
SIEM Integration
Forward detection events to Splunk (HEC), CrowdStrike Falcon LogScale, or Datadog Logs, or to anything else through webhooks. Each detection is mapped to a MITRE ATT&CK tactic.
Structured JSON events
Data Poisoning
Set a decoy to serve fake or misleading content to whatever requests it. Pollute scraped datasets with intentionally bad data.
Configured per decoy
Smart Redirects
Set a decoy to redirect whatever requests it to a URL you choose.
Configured per decoy
SDK & API
Full REST API and JavaScript SDK for custom integrations. Build automated workflows that match your security policies.
npm: @webdecoy/node
Supported AI Bots
We detect a wide range of AI scrapers and bots. Our detection engine combines behavioral analysis with user agent verification to catch bots that bypass robots.txt.
- GPTBot (OpenAI)
- ClaudeBot (Anthropic)
- Perplexity
- GoogleBot (Research)
- Bingbot
- Applebot
- Metabot
- And 15+ others
Product Updates
Explore product announcements for setup instructions, examples, and the limits of each feature.
WebDecoy MCP Server for AI Assistants
Connect Claude, ChatGPT, Codex or another MCP client to install WebDecoy for your stack and ask whether protection is enforced. Read-only by default, on every plan.
Netlify Monitoring and Enforcement
Observe crawler traffic at the edge and configure clearance checks for selected paths. Start in Monitor mode before enabling enforcement.
Investigate likely collection targets and access patterns, with measured sample behavior and links to the supporting requests.
Compare observed AI crawls and referrals in a shareable snapshot, with the measurement window and attribution limits included.
Questions about our bot detection capabilities?
Our team can help you understand how WebDecoy fits your specific security needs.
Talk to an Expert