---
title: Firewall API
description: Manage firewall rules and configuration programmatically.
url: "https://vercel.com/kb/firewall-api"
published: 2025-11-06
last_updated: 2025-11-06
install_vercel_plugin: npx plugins add vercel/vercel-plugin
---

# Firewall API

Manage firewall rules and configuration programmatically.

## All Firewall API guides

- [Vercel WAF vs Cloudflare WAF](/kb/guide/vercel-waf-vs-cloudflare-waf): A detailed guide to Vercel WAF vs Cloudflare WAF: framework-aware rules, sub-300ms propagation, BotID bot detection, OWASP paranoia levels, leaked credential lookup, and when to choose each product for your web application.
- [Challenge cURL requests](/kb/guide/challenge-curl-requests): Learn how to challenge curl requests with the Vercel WAF API.
- [Deny traffic from a set of IP addresses](/kb/guide/deny-traffic-from-a-set-of-ip-addresses): Learn how to block specific IP addresses with the Vercel WAF API.
- [Deny non-browser traffic or blocklisted ASNs](/kb/guide/deny-non-browser-traffic-or-blocklisted-asns): Learn how to block traffic from known threats with the Vercel WAF API.
- [Challenge cookie-less requests on a specific path](/kb/guide/challenge-cookieless-requests-on-a-specific-path): Learn how to challenge specific requests with the Vercel WAF API.

## Explore other topics in the Vercel Knowledge Base

- [Jev from TypeSafe AI](/kb/jev-from-typesafe-ai): Jev is TypeSafe AI's System One model for fast, typed decisions. It evaluates supplied context and returns choices, scores, and probabilities that applications can use to classify requests, route tasks, and assess proposed actions without generating prose.
- [Vercel Sandbox](/kb/vercel-sandbox): The compute primitive designed to safely run untrusted or user-generated code on Vercel.
- [FDE Field Notes](/kb/fde): Insights from our work with customers. Explore the patterns, diagnostics, and recommendations Vercel’s Forward Deployed Engineers use in production.
- [Software Factory](/kb/software-factory): Software factories put an agent on every stage of your development loop: triage, planning against a live repo checkout, implementation verified with your own checks, and independent review. Work items become draft PRs while you keep the judgment calls.
