Install AI Protection
1. Select your application and create a key
Section titled “1. Select your application and create a key”Open AI Protection and select the property for your application. Copy the property ID from Connect this application.
In API keys, create a key scoped to that property with Write Detections permission. Store the key in your server’s secret configuration. Never include it in browser JavaScript or a mobile client.
2. Install the SDK in your backend
Section titled “2. Install the SDK in your backend”Node.js / Next.js
Section titled “Node.js / Next.js”Requires Node.js 22.22.3 or newer.
Follow the Next.js integration guide for the route wrapper, trusted client IP, and streaming lifecycle.
Requires Go 1.26.1 or newer.
Follow the Go integration guide.
Python / FastAPI
Section titled “Python / FastAPI”Requires Python 3.11+ and asyncio.
python -m pip install 'webdecoy-ai-protection[fastapi]==0.1.0a1'Omit [fastapi] for the core async client. Follow the FastAPI integration guide. The repository includes a deterministic local streaming example that does not call a paid model.
3. Configure the connection
Section titled “3. Configure the connection”Use https://ai-protection.webdecoy.com as the SDK base URL. This is an API endpoint; opening its root in a browser may return 404. Customers do not need to deploy this service or configure a custom DNS record.
| Setting | Node.js | Go | Python |
|---|---|---|---|
| Base URL | webdecoyUrl |
BaseURL |
base_url |
| Property ID | propertyId |
PropertyID |
property_id |
| Server API key | webdecoyKey |
APIKey |
api_key |
| Observation mode | protectionMode: 'observe' |
Mode: protection.Observe |
mode="observe" |
Create one shared client per application process and reuse it. Use a fixed route template such as /api/chat, not a raw URL containing user IDs or query strings. Derive client IP from your trusted ingress configuration; do not trust arbitrary forwarded headers.
4. Wrap the AI route
Section titled “4. Wrap the AI route”Integrate after authentication, authorization, and input validation, immediately before the model would run:
- Pass trusted server context into local rules and optional account controls.
- Ask the SDK for admission, or use the framework wrapper that enforces the decision.
- Start inference only when admitted. Defer the model call inside the protected callback.
- Propagate cancellation to the provider. Keep concurrency leases active until all protected work and streaming finish.
- Report the application outcome. For budgets, wrap each individual model attempt and provide confirmed final usage when available.
Use the SDK-specific guide for executable code: the wrappers and completion hooks differ by runtime. Quotas, concurrency, and budgets are opt-in integrations; installing the package or changing the dashboard detector mode does not activate them.
5. Verify, then enable enforcement
Section titled “5. Verify, then enable enforcement”Send an authenticated test request and refresh AI Protection. Check that a stored AI check and application decision appear for the correct property. A successful HTTP response alone does not prove cloud protection was available: inspect degraded coverage too.
Keep cloud detector failures allowed through initially. If WebDecoy detection is unavailable, legitimate requests can continue with degraded coverage; local application rules keep their own policies.
After reviewing results, enable cloud enforcement in both the SDK and the dashboard, if your account permits it. Configure quota, concurrency, and budget modes separately. Use the verification checklist before expanding the rollout.