Skip to content

Install AI Protection

1. Select your application and create a key

Section titled “1. Select your application and create a key”

Open AI Protection and select the property for your application. Copy the property ID from Connect this application.

In API keys, create a key scoped to that property with Write Detections permission. Store the key in your server’s secret configuration. Never include it in browser JavaScript or a mobile client.

Requires Node.js 22.22.3 or newer.

Terminal window
npm install @webdecoy/[email protected]

Follow the Next.js integration guide for the route wrapper, trusted client IP, and streaming lifecycle.

Requires Go 1.26.1 or newer.

Terminal window
go get github.com/WebDecoy/[email protected]

Follow the Go integration guide.

Requires Python 3.11+ and asyncio.

Terminal window
python -m pip install 'webdecoy-ai-protection[fastapi]==0.1.0a1'

Omit [fastapi] for the core async client. Follow the FastAPI integration guide. The repository includes a deterministic local streaming example that does not call a paid model.

Use https://ai-protection.webdecoy.com as the SDK base URL. This is an API endpoint; opening its root in a browser may return 404. Customers do not need to deploy this service or configure a custom DNS record.

Setting Node.js Go Python
Base URL webdecoyUrl BaseURL base_url
Property ID propertyId PropertyID property_id
Server API key webdecoyKey APIKey api_key
Observation mode protectionMode: 'observe' Mode: protection.Observe mode="observe"

Create one shared client per application process and reuse it. Use a fixed route template such as /api/chat, not a raw URL containing user IDs or query strings. Derive client IP from your trusted ingress configuration; do not trust arbitrary forwarded headers.

Integrate after authentication, authorization, and input validation, immediately before the model would run:

  1. Pass trusted server context into local rules and optional account controls.
  2. Ask the SDK for admission, or use the framework wrapper that enforces the decision.
  3. Start inference only when admitted. Defer the model call inside the protected callback.
  4. Propagate cancellation to the provider. Keep concurrency leases active until all protected work and streaming finish.
  5. Report the application outcome. For budgets, wrap each individual model attempt and provide confirmed final usage when available.

Use the SDK-specific guide for executable code: the wrappers and completion hooks differ by runtime. Quotas, concurrency, and budgets are opt-in integrations; installing the package or changing the dashboard detector mode does not activate them.

Send an authenticated test request and refresh AI Protection. Check that a stored AI check and application decision appear for the correct property. A successful HTTP response alone does not prove cloud protection was available: inspect degraded coverage too.

Keep cloud detector failures allowed through initially. If WebDecoy detection is unavailable, legitimate requests can continue with degraded coverage; local application rules keep their own policies.

After reviewing results, enable cloud enforcement in both the SDK and the dashboard, if your account permits it. Configure quota, concurrency, and budget modes separately. Use the verification checklist before expanding the rollout.