---
title: "Arcjet Next.js Example App"
description: "Rate limiting and bot detection for Next.js"
url: "https://vercel.com/templates/next.js/arcjet-next-js-example-app"
links:
  repository: "https://github.com/arcjet/example-nextjs"
  demo: "https://example.arcjet.com/"
  deploy: "https://vercel.com/new/clone?demo-title=Arcjet+Next.js+Example+App&demo-description=Rate+limiting+and+bot+detection+for+Next.js&demo-url=https%3A%2F%2Fexample.arcjet.com%2F&demo-image=%2F%2Fimages.ctfassets.net%2Fe5382hct74si%2F5Fj7Rji8BA2aIC5eDS1h3h%2Fe06076a22b11f791eca25bf2cea2d9e5%2Farcjet_template.jpg&project-name=Arcjet+Next.js+Example+App&repository-name=arcjet-next-js-example-app&repository-url=https%3A%2F%2Fgithub.com%2Farcjet%2Fexample-nextjs&from=templates&integration-ids=oac_1GEcKBuKBilVnjToj1QUwdb8"
---

# Arcjet Next.js Example App

Rate limiting and bot detection for Next.js

<!-- markdownlint-disable MD033 MD041 -->
<a href="https://arcjet.com" target="_arcjet-home">
  <picture>
    <source media="(prefers-color-scheme: dark)" srcset="https://arcjet.com/logo/arcjet-dark-lockup-voyage-horizontal.svg">
    <img src="https://arcjet.com/logo/arcjet-light-lockup-voyage-horizontal.svg" alt="Arcjet Logo" height="128" width="auto">
  </picture>
</a>

[![Deploy with Vercel][vercel_button]][vercel_deploy]
&nbsp; &nbsp;
[![Deploy to Netlify][netlify_button]][netlify_deploy]

# Arcjet example app

[Arcjet](https://arcjet.com) helps developers protect their apps in just a few
lines of code. Bot detection. Rate limiting. Email validation. Attack
protection. Data redaction. A developer-first approach to security.

This is an example Next.js application demonstrating the use of multiple
features. It is deployed at
[https://example.arcjet.com](https://example.arcjet.com).

## Features

- [Signup form protection](https://example.arcjet.com/signup) uses Arcjet's
  server-side email verification configured to block disposable providers and
  ensure that the domain has a valid MX record. It also includes rate limiting
  and bot protection to prevent automated abuse.
- [Bot protection](https://example.arcjet.com/bots) shows how a page can be
  protected from automated clients.
- [Rate limiting](https://example.arcjet.com/rate-limiting) shows the use of
  different rate limit configurations depending on the authenticated user. A
  logged-in user can make more requests than an anonymous user.
- [Attack protection](https://example.arcjet.com/attack) demonstrates Arcjet
  Shield, which detects suspicious behavior, such as SQL injection and
  cross-site scripting attacks.
- [Sensitive info](https://example.arcjet.com/sensitive-info) protects against
  clients sending you sensitive information such as PII that you do not wish to
  handle.
- [Prompt injection detection](https://example.arcjet.com/prompt-injection)
  analyzes user prompts for injection attacks such as jailbreaks, role-play
  escapes, or instruction overrides.

## Run locally

1. [Register for a free Arcjet account](https://console.arcjet.com).

2. Install dependencies:

```bash
npm ci
```

3. Rename `.env.local.example` to `.env.local` and add your Arcjet key

4. Start the dev server

```bash
npm run dev
```

5. Open [http://localhost:3000](http://localhost:3000) in your browser.

## Need help?

Check out [the docs](https://docs.arcjet.com/), [contact
support](https://docs.arcjet.com/support), or [join our Discord
server](https://arcjet.com/discord).

## Stack

- App: [Next.js](https://nextjs.org/)
- Form handling: [React Hook Form](https://react-hook-form.com/) (see also [our
  full form protection
  example](https://github.com/arcjet/example-nextjs-form))
- Client-side validation: [Zod](https://zod.dev/)
- Security: [Arcjet](https://arcjet.com/)

## Contributing

All development for Arcjet examples is done in the
[`arcjet/examples` repository](https://github.com/arcjet/examples).

You are welcome to open an issue here or in
[`arcjet/examples`](https://github.com/arcjet/examples/issues) directly.
However, please direct all pull requests to
[`arcjet/examples`](https://github.com/arcjet/examples/pulls). Take a look at
our
[contributing guide](https://github.com/arcjet/examples/blob/main/CONTRIBUTING.md)
for more information.

[vercel_deploy]: https://vercel.com/new/clone?repository-url=https%3A%2F%2Fgithub.com%2Farcjet%2Fexample-nextjs&project-name=arcjet-example&repository-name=arcjet-example&developer-id=oac_1GEcKBuKBilVnjToj1QUwdb8&demo-title=Arcjet%20Example%20&demo-description=Example%20rate%20limiting%2C%20bot%20protection%2C%20email%20verification%20%26%20form%20protection.&demo-url=https%3A%2F%2Fgithub.com%2Farcjet%2Fexample-nextjs&demo-image=https%3A%2F%2Fconsole.arcjet.com%2Fimg%2Fexample-apps%2Fvercel%2Fdemo-image.jpg&integration-ids=oac_1GEcKBuKBilVnjToj1QUwdb8&external-id=arcjet-js-example◊
[vercel_button]: https://vercel.com/button
[netlify_deploy]: https://app.netlify.com/start/deploy?repository=https://github.com/arcjet/example-nextjs
[netlify_button]: https://www.netlify.com/img/deploy/button.svg

## Related Templates

### [Vercel Edge Middleware Rate Limit](https://vercel.com/templates/other/middleware-rate-limit)

Add rate limiting to your application with any frontend framework.

## Related Integrations

### [Arcjet](https://vercel.com/marketplace/arcjet)

Runtime security that ships with your code. AI security building blocks.

---

## Additional documentation

The [Vercel Knowledge Base](https://vercel.com/kb) contains guides and answers to common questions about Vercel, including deployment, framework configuration, domains, caching, and troubleshooting.
