
Arcjet is a runtime security platform that ships inside the AI code you are already writing. Where traditional WAFs sit at the edge, Arcjet sits next to agent tool calls: detect prompt injection, authorize what an agent is allowed to do, redact sensitive data, and throttle bots or spend before a model-driven action hits production. The pitch after its strong Product Hunt launch around 21 September 2026 is simple — observe, enforce, audit.
Developers wrap tools with guard() (or SDK rules), map trusted application context as inputs, and get an ALLOW or DENY decision before email, refunds, database writes or web fetches execute. Security teams can define versioned remote policies (including Rego / OPA-style rules) by label without redeploying app code, while local detectors cover PII that should never leave the process. It also covers classic request protection alongside agent-specific guards.
Editor score ~4.4/5 in Coding. Pricing starts with a free trial, then roughly $25/month and a higher ~$299/month tier (confirm live numbers). Choose Arcjet if you are putting agents into production with consequential tools; skip it if you only run read-only chatbots with no side effects.
| Plan | Price | What's Included |
|---|---|---|
| Trial | $0 | 15-day free trial — confirm on arcjet.com |
| Starter | ~$25/month | Runtime security building blocks — verify current quotas |
| Business | ~$299/month | Higher limits for production apps — check site for details |
Human-verified · How we score →