Skip to content
Dashboard

Vercel WAF upgrade brings persistent actions, rate limiting, and API control

Product

New Firewall capabilities reduce effects of DDoS attacks and enhance traffic control

Link to headingBringing new enhancements to Vercel Web Application Firewall

Block AI Bots - Firewall Rule

Add a custom rule to your project's Firewall to detect common AI bots. This rule defaults to 'Log.' Change it to 'Deny' to block these bots.

Add Firewall Rule

Link to headingAdding persistence to rule actions

With persistent actions enabled, edge requests are processed earlier in the lifecycle, bypassing both usage metrics and WAF evaluation entirely.With persistent actions enabled, edge requests are processed earlier in the lifecycle, bypassing both usage metrics and WAF evaluation entirely.
With persistent actions enabled, edge requests are processed earlier in the lifecycle, bypassing both usage metrics and WAF evaluation entirely.

Link to headingRate limiting to control request frequency

Granular rate limiting configuration to set actions, algorithms, time windows, request limits, and tracking keys, allowing precise control of traffic flow and safeguarding your APIs.Granular rate limiting configuration to set actions, algorithms, time windows, request limits, and tracking keys, allowing precise control of traffic flow and safeguarding your APIs.
Granular rate limiting configuration to set actions, algorithms, time windows, request limits, and tracking keys, allowing precise control of traffic flow and safeguarding your APIs.

Link to headingProgrammatic control with the Firewall API

Link to headingWhy Vercel’s approach is different

Rate Limit API Requests - Firewall Rule

Add a custom rule to your project's Firewall to rate limit API requests. This rule defaults to 'Log.' Change it to 'Deny' to actually block these requests.

Add Firewall Rule

Ready to deploy?