Skip to content
@arcjet

Arcjet

The AI agent runtime security platform
Arcjet Logo

Arcjet

Arcjet is the AI agent runtime security platform. Discover the agents running in your organization, enforce policy across every action, prompt, and tool call, and keep the evidence to prove what happened. Detect prompt injection, authorize agent tool calls, redact PII, and block bots and abuse.

Arcjet protects several entry points:

  • Coding agents - apply policies and enforce security controls directly within the development environment. Protect prompts from injection, redact sensitive data, and ensure that agent actions comply with organizational policies. Supported coding agents include: Claude Code and GitHub Copilot.
  • Custom agents - tool calls, queue consumers, agentic pipelines, and anywhere else you process untrusted input in custom agents you've built and deployed yourself. Protect HTTP requests from bots and abuse, and enforce security policies consistently across all agent interactions. Supported AI agent frameworks include: Claude Agent SDK, Claude Managed Agents, CrewAI, Genkit, Google ADK, LangChain, LangGraph, Mastra, OpenAI Agents, Strands Agents, TanStack AI, Vercel AI SDK, Vercel Eve.
  • Web applications - protect HTTP routes, API endpoints, and middleware within web applications. Bot protection, email validation, WAF, and other security building blocks applied directly in-code. Supported languages and frameworks include: Astro, Bun, Deno, Fastify, NestJS, Next.js, Node.js, Express, Hono, Nuxt, Python, FastAPI, Flask, React Router, Remix, SvelteKit, Go.

Getting started

Built for teams shipping AI features and agents that access data, call tools, or take actions in production.

  1. Sign up for an account at arcjet.com or use agent registration.
  2. Follow the quick start for your platform.

Support

Join our Discord server or email [email protected]

Pinned Loading

  1. arcjet-js arcjet-js Public

    Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data redaction, bot protection, and rate limiting. Drop it into your JS/TS code.

    TypeScript 684 32

  2. arcjet-py arcjet-py Public

    Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data redaction, bot protection, and rate limiting. Drop it into your Python code.

    Python 32 2

  3. example-nextjs example-nextjs Public template

    An example Next.js application protected by Arcjet.

    TypeScript 58 10

  4. arcjet-docs arcjet-docs Public

    Arcjet's documentation.

    MDX 16 8

  5. gravity gravity Public

    Gravity is a host generator for WebAssembly Components. It currently targets Wazero, a zero dependency WebAssembly runtime for Go.

    Rust 94 7

  6. well-known-bots well-known-bots Public

    List of well-known bots and user-agent patterns to detect them

    TypeScript 80 3

Repositories

Showing 10 of 56 repositories
  • arcjet-docs Public

    Arcjet's documentation.

    arcjet/arcjet-docs's past year of commit activity
    MDX 16 CC-BY-4.0 8 5 1 Updated Sep 26, 2026
  • arcjet-js Public

    Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data redaction, bot protection, and rate limiting. Drop it into your JS/TS code.

    arcjet/arcjet-js's past year of commit activity
    TypeScript 684 Apache-2.0 32 6 1 Updated Sep 26, 2026
  • arcjet-py Public

    Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data redaction, bot protection, and rate limiting. Drop it into your Python code.

    arcjet/arcjet-py's past year of commit activity
    Python 32 Apache-2.0 2 2 0 Updated Sep 26, 2026
  • example-tanstack-start Public

    An example TanStack Start application protected by Arcjet

    arcjet/example-tanstack-start's past year of commit activity
    TypeScript 7 Apache-2.0 0 0 0 Updated Sep 24, 2026
  • example-tanstack-agent Public

    An example TanStack AI application protected by Arcjet

    arcjet/example-tanstack-agent's past year of commit activity
    TypeScript 0 Apache-2.0 0 0 0 Updated Sep 24, 2026
  • example-sveltekit Public template

    An example SvelteKit application protected by Arcjet

    arcjet/example-sveltekit's past year of commit activity
    Svelte 0 Apache-2.0 0 0 0 Updated Sep 24, 2026
  • example-strands-agent Public

    An example Strands Agents application protected by Arcjet

    arcjet/example-strands-agent's past year of commit activity
    TypeScript 0 Apache-2.0 0 0 0 Updated Sep 24, 2026
  • example-react-router-middleware Public

    An example React Router application demonstrating Arcjet protection using React Router v8 middleware.

    arcjet/example-react-router-middleware's past year of commit activity
    TypeScript 0 Apache-2.0 0 0 0 Updated Sep 24, 2026
  • example-react-router Public

    An example React Router application protected by Arcjet

    arcjet/example-react-router's past year of commit activity
    TypeScript 0 Apache-2.0 1 0 0 Updated Sep 24, 2026
  • example-openai-agent Public

    An example OpenAI Agents application protected by Arcjet

    arcjet/example-openai-agent's past year of commit activity
    TypeScript 0 Apache-2.0 0 0 0 Updated Sep 24, 2026