Arcjet guards your app. Doorman reads the message.
Arcjet gives developers security as code: rate limits, bot rules, email validation, a WAF and guardrails for AI agents. Its signup protection checks who and how fast, not what they wrote. A real person with a valid email pitching you passes. Doorman reads that part.
Free for 1,000 checks a month. Paid plans from $12. No card required.
Example: Doorman screening sign-ups and checkout, each judged in under half a second and delivered or kept out with the reason.
Sound familiar?
Valid emails still pitch
A real address with valid MX records can still be an agency pitch or a throwaway intent.
Code in every app
Protection lives in your application through an SDK.
Signals, not meaning
Bot, email and velocity signals don't say what a message is asking for.
Doorman and Arcjet, side by side
| Question | Doorman | Arcjet |
|---|---|---|
| What it checks | What the submission says, against what you sell | Bots, email validity and rate limits; also WAF and AI-agent rules |
| A human pitch from a valid email | Kept out, with the line that gave it away | Passes signup protection |
| Why something was blocked | The exact sentence, in plain language | Allow or deny with the rule and values that decided it |
| Setup | A form URL, one API call, or your coding agent | An SDK in your app code |
| Price | Free for 1,000 checks a month; Pro $12 for 25,000 | Free up to 10,000 requests a month; Individual $25 a month plus usage |
Their plans and behaviour as published on their own sites, checked 29 September 2026. Sources: arcjet.com/pricing, docs.arcjet.com/signup-protection.
Which one is right for you?
Choose Doorman if
- The junk is in what people write: pitches, fake sign-ups with real addresses, abuse
- You want protection without an SDK in your code
- Your forms are on Webflow, Framer or a static site
Choose Arcjet if
- You want rate limiting, bot rules, a WAF and email validation as code across your whole app
- You're securing AI agents and LLM calls
- You want security rules in your codebase
They fit together: Arcjet for rate limits and bots across the app, Doorman on the forms to read what gets through.
Up and running today
- Sign up: no sales call, no contract: free for 1,000 checks a month, then $12.
- One call: doorman.check before you create the account or capture the order.
- Or ask your agent: copy one prompt into Claude Code, Codex or Cursor and it wires it in.
- Start safely: watch mode tags what it would have dropped before anything is blocked.
const r = await doorman.check({
kind: "checkout",
email: order.email,
order: { items: "5× Gift card $100", total_usd: 500 },
signals: { card_country: "US", ip_country: "NG", attempts: 4, account_age_days: 0 },
});
// r.action: "deliver" → capture · "hold" → review · "drop" → cancelChecked, not guessed
Every decision comes from Doorman's models reading the submission, in milliseconds, with the reason attached.
Labelled test set: 104 invented but labelled contact-form and checkout submissions, judged live; latency is the median of those checks. Questions were not tuned to the set.
Questions
Does Doorman do rate limiting?
Hosted endpoints are rate limited per IP and per form, but Doorman isn't a general rate limiter or WAF for your app.
Can I call it from my code like Arcjet?
Yes: one doorman.check call from a route handler or server action, with a typed Node SDK.
Does it validate email addresses?
Disposable and throwaway addresses count against a sign-up, and Doorman judges the whole submission, not the address alone.
How much does it cost?
Free for 1,000 checks a month. Pro is $12 a month for 25,000 and Business is $49 a month for 250,000. Every plan gets the same models. See pricing.
Try it on your own forms
Free for your first 1,000 checks every month. Start in watch mode and see every call before you trust it.