AI Protection
Check requests to your model routes and calls to your MCP tools before the model or tool runs. The SDKs run in your backend, so a denied request never reaches inference or tool execution.
Request to /api/chat
or call to an MCP tool
↓
WebDecoy check (in your server)
quotas · concurrency · budgets
↓
allowed → model or tool runs
denied → model or tool never runsIllustrative flow. Start in observe mode, then enforce.
Beta
AI Protection is in beta. Installing it requires a code change in your backend: you add an SDK to the route or MCP server you want to protect. It adds checks in front of your model and tools. It does not replace your authentication or authorization.
Your site’s visitors, or your own AI features
WebDecoy already shows you which AI crawlers visit your website. AI Protection covers something else: the AI features you build and run yourself.
AI crawler visibility
Bots and AI crawlers visiting your website, seen by the browser tag, edge sensor and decoys.
See AI Traffic →AI Protection
Requests to your model and chat routes, and calls to your MCP tools, checked by a server-side SDK before the model or tool runs.
Checked before inference or tool execution
The decision is made in your code path, ahead of the expensive or sensitive part.
Runs in your backend
The check happens in your server code before inference or tool execution. A denied request never reaches the model or the tool.
Observe first, then enforce
Start in observe mode to see what the checks would decide, then switch a control to enforce when you are ready.
Failure behavior per control
Choose for each control: fail open to keep serving if a check cannot complete, or fail closed to keep a hard limit.
Cancellation stops the work
When a request is cancelled, the protected work it started is stopped too.
Limits shared across replicas
Limits are shared across every replica of your service, so running more instances does not multiply a caller’s allowance.
Model budgets are tracked per attempt: the SDK reserves budget before the call and settles the confirmed usage after it.
Account and session quotas
Quotas keyed to the account or session making the request.
Concurrency
Cap how many protected requests a caller can have in flight at once.
Weighted tool work
Give heavier tools a larger weight so a limit reflects the work they do.
Per-attempt model budgets
Each model attempt reserves budget before the call and settles the confirmed usage afterwards.
A check before every tool call
The Node MCP adapter works with Streamable HTTP servers. Before each tool call it checks per-tool authentication, your application’s authorization, and any limits you set.
If a caller or a tool needs to stop, pause it from the dashboard.
Before each tool call
Per-tool authentication
Application authorization
Optional limits
Caller and tool pauses set from the dashboard
The MCP adapter is available for Node. Go and Python cover request admission.
See every decision
Follow a request from the check to the model attempt or tool call it allowed.
Decisions
What each check allowed or denied.
Detector checks
The individual checks that ran for a request.
Model attempts
Each attempt to call a model.
Tools
Activity for each MCP tool you protect.
Caller timelines
One caller’s requests and tool calls in order.
Tool result to action
A link from any MCP tool result to that exact action in the dashboard.
Wire it in, then check it
The install doctor detects your project layout and wires the route for you, with a plan you review, apply, and can roll back.
It then runs synthetic calls against your setup. No paid model is needed.
Behavior checked with synthetic calls
- Allowed
- Forbidden
- Cross-tenant
- Cancellation
- Outage
Prompts are not required
Prompts and model responses are not needed in detection or usage payloads.
Caller identities are pseudonymous. They can be correlated across requests so limits and timelines work, but they are not anonymous.
Public, Apache-2.0 SDKs
Read the code that runs in your backend. Every AI Protection SDK is public and licensed under Apache-2.0.
SDKs
Pick the one that matches your backend.
Node.js and Next.js
Request admission, the MCP adapter (Streamable HTTP), and an experimental Cloudflare Workers adapter.
WebDecoy/ai-protection
Go
Request admission for model and chat routes.
WebDecoy/ai-protection-go
Python (FastAPI)
Request admission for model and chat routes.
WebDecoy/ai-protection-python
Frequently asked questions
What AI Protection does, and what it does not.
How is AI Protection different from AI crawler visibility?
AI crawler visibility is about bots visiting your website. AI Protection is about your own AI features: requests to your model or chat routes and calls to your MCP tools. Server-side SDKs check each request or tool call before the model or tool runs.
Does installing it require a code change?
Yes. AI Protection runs in your backend, so you add an SDK to the route or MCP server you want to protect. The install doctor can detect your project layout and wire the route with a reviewable plan that you apply or roll back.
Which languages are supported?
Request admission is available for Node.js and Next.js, Go, and Python (FastAPI), with an experimental Cloudflare Workers adapter. The MCP adapter is available for Node and supports Streamable HTTP.
What happens if WebDecoy cannot be reached?
You decide per control. Fail open keeps your feature serving. Fail closed keeps a hard limit in place. The install doctor checks outage behavior with synthetic calls so you can see what your configuration does.
Do you need our prompts or model responses?
No. Prompts and model responses are not needed in detection or usage payloads. Caller identities are pseudonymous: they can be correlated across requests, but they are not anonymous.
Does it replace our authentication or authorization?
No. AI Protection adds checks in front of your model and tools. Keep your existing authentication and authorization. For MCP tools, the Node adapter checks per-tool authentication and application authorization before each call.
Is it production ready?
AI Protection is in beta. The SDKs are public and Apache-2.0 licensed. Start in observe mode, review the decisions in the dashboard, and enforce when you are comfortable with what you see.
Protect your first AI route
Follow the setup guide to add an SDK to one route or MCP server, run it in observe mode, and review the decisions before you enforce.