Skip to content

Choose an installation method

You only need one detection source to start. Choose the source closest to where your traffic enters, get it reporting, and add another layer only when you need broader coverage.

Create a free accountFollow the quickstart
Your site Start with What it sees Typical setup
Traffic runs through Cloudflare Cloudflare edge sensor Every request at the edge, including non-JavaScript crawlers About 5 minutes
WordPress or WooCommerce WordPress plugin Server requests, browser signals, forms, login, and WooCommerce About 3 minutes
Node.js, Express, Fastify, or Next.js Node.js SDK Request metadata, local rules, tripwires, and app-level decisions About 10 minutes
Anything else Browser detection script Headless browsers, automation, browser agents, and LLM referrals About 2 minutes

CHOOSE YOUR FASTEST PATH

Install where your traffic already flows.

Pick one source now. You can layer in the others later for broader coverage.

Not sure? Compare coverage and choose from a decision table.

Capability Edge sensor Server SDK / plugin Browser script
Requests that never run JavaScript
Googlebot, GPTBot, ClaudeBot, curl
Real client IP and request headers Limited
Headless-browser artifacts Limited Limited
Browser behavior and integrity With browser client
Block or throttle before app logic At the edge In your app
One-line / one-click install WordPress: ✓

For the precise sensor-by-sensor matrix, read Detection coverage.

  1. Create your account and name the site you want to protect.
  2. Open Integrations and choose a detection source, or use the install recommendation in the dashboard setup checklist.
  3. Follow the source-specific install. WebDecoy keeps waiting for its first event and tells you when one arrives.
  4. Open Sensors to confirm the source is Reporting, Nothing reported yet, or Quiet.
  5. Use Send a test detection on the dashboard to trip the example decoy and prove the detection pipeline end to end.
WebDecoy Integrations page grouping detection sources and enforcement targets
The current Integrations screen. Detection sources are first because visibility comes before enforcement.

Most production sites eventually use two complementary layers:

  1. Edge or server detection to see every HTTP request, including clients without JavaScript.
  2. Browser detection to collect browser-integrity and behavior signals from clients that do execute JavaScript.

Add decoy links and tripwires when you want a high-confidence signal that depends on what the client did, not what its headers claimed. Then begin response in monitor mode before turning on blocking.

Already installed? Verify the source and fire a real test detection.