Skip to content

Know what is crawling your site.

Install one sensor now. WebDecoy turns raw bot traffic into verified agents, persistent actors, explainable detections, and response you control.
FREE PLAN, NO CARDFIRST SIGNAL IN MINUTESEDGE, SERVER, AND BROWSER COVERAGE
WebDecoy dashboard showing a world map of recent detections, threat-score totals, source filters, and a detection timeline
The live WebDecoy dashboard, using real detection data. Filter by source, site, and time range without losing the full threat picture.

CHOOSE YOUR FASTEST PATH

Install where your traffic already flows.

Pick one source now. You can layer in the others later for broader coverage.

Not sure? Compare coverage and choose from a decision table.

01 / INSTALL ONCE

Meet your stack where it is.

Start with Cloudflare, WordPress, Node.js, or a one-line browser tag. Every source reports into the same property, and the Sensors page tells you what is reporting, quiet, or missing.

Compare install methods
WebDecoy Integrations page grouping Node.js, WordPress, browser script, Cloudflare, AWS WAF, Fastly, and Vercel by job
Real app screen: integrations are grouped by detection source and enforcement target, so setup begins with the job you need done.

02 / UNDERSTAND THE TRAFFIC

Move from IPs to adversaries.

WebDecoy correlates detections into persistent actors, checks declared crawler identities, and shows the evidence behind every score. Filters stay shareable, so an investigation can move from one teammate to the next intact.

Learn the detections workflow
WebDecoy Detections page showing source, category, agent, IP address, persistent actor, and threat score columns
Real app screen: one view across edge workers, detection scripts, SDKs, WordPress, decoys, and tripwires.
SEERequests a page tag cannot.

Edge and server sensors reveal crawlers, HTTP libraries, and scanners that never execute JavaScript.

PROVEWhether an agent is genuine.

Web Bot Auth, reverse DNS, network ownership, and request evidence distinguish verified agents from impersonators.

RESPONDWithout handing over the wheel.

Begin in monitor mode, then challenge or block at your edge using policies you can explain and reverse.

03 / CLOSE THE LOOP

Turn a finding into a policy.

Scope only the routes that should be closed to automation. Real browsers earn clearance silently; clients that cannot satisfy the policy are refused at the edge. Every minimum is explicit before you turn enforcement on.

Design a response workflow
WebDecoy Enforcement policy page showing token-enforced routes and human-trust requirements
Real app screen: route-scoped enforcement with plain-language safety guidance before activation.