Updated 16 September 2026
01 · what this page is, and what it avoids
What this page is, and what it avoids
This page makes no claim about what Arcjet does or does not do. Their capabilities change, their documentation is public, and a claim written here would be out of date before it was useful — and wrong in the direction that suits us, which is how these pages usually go.
What follows is the set of questions worth asking of either product, and a plain statement of where Botscope is the weaker choice.
02 · what to look for in either
What to look for in either
Where does it sit? An SDK runs inside the application it protects, so its decisions live next to your routes and are written in the same language as the rest of your logic. Botscope classifies at your origin, after the edge has done whatever it does, which is why it sees what actually arrived rather than what was let through.
Can one decision be explained? Ask to see a single verdict with the signals behind it. If the answer is a score, the follow-up is what you tell a customer who was stopped by it.
What does it cost to find out? Whether you can answer either question above without a sales process is itself an answer.
Who is it for? if you want per-route rules expressed in code and reviewed in pull requests, that is an SDK's shape and not a classifier's.
03 · where arcjet is the better choice
Where Arcjet is the better choice
Decisions where your logic already is
Rules next to the route they protect, versioned with the code and testable in CI, is a genuinely better arrangement when the rule depends on what the route does.
Nothing to install outside the app
No agent, no DNS, no file in the document root — for a team that deploys a single application, that is one fewer moving part.
04 · where botscope is the one to pick
Where Botscope is the one to pick
When the site is not one application — a WordPress install, a shop, several services behind one domain — or when the record of a decision needs to outlive the request and be readable by somebody who does not have the codebase open.
Questions
Can I run both?
Usually yes, and often that is the right answer. Botscope classifies at the origin and does not sit in the request path, so it does not conflict with something running in front of it. What it adds is the record of what got through.
Why does this page not list their weaknesses?
Because we would be choosing which weaknesses to list, and you would have no way to check. The questions above are ones you can put to both vendors and compare the answers yourself.
How do I try Botscope without committing to anything?
The free tier is 100,000 events a month with no card and every feature on, and new sites start in observation mode — everything classified and recorded, nothing blocked. You can answer "what is actually reaching me" before deciding whether to act on it.
What does Botscope not do at all?
It is not a WAF, it is not DDoS protection, and it shows no CAPTCHA. It classifies requests and records why; it does not absorb volume and it does not replace whatever you run at the edge.
See which of these reach your site
Free plan, no card: 100,000 events a month with every feature on. Nothing is blocked until you turn enforcement on.