Talk to us
by AkamaiTechBag Intel Page

Akamai App & API Protector

Your WAF has sat in alert mode since launch. Nobody has time to tune it — Akamai App & API Protector inspects every request on Akamai’s edge — WAF, Layer 7 DDoS, bot visibility and API discovery — and Hybrid carries the same policy into clusters and VMs you run yourself.

WAF, L7 DDoS, bots and APIs in oneHybrid for apps off the edgeUp to 9 months free for new customers

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Akamai prints no list price; new customers can get up to 9 months free, add-ons included
Quote
Analysts
The Forrester Wave: Web Application Firewall Solutions, Q1 2025, ten vendors on 22 criteria
Forrester Leader
Deployment
On Akamai’s edge by default; Hybrid Protector runs the WAF inside clusters or VMs you control
Edge + Hybrid
India
Godrej’s customer story credits App & API Protector with 300+ applications in six months
Godrej, 300+ apps

Quick answer

Akamai App & API Protector is a WAAP that runs on Akamai’s edge: a WAF, Layer 7 DDoS defence, bot visibility and API discovery in one product, tuned by an Adaptive Security Engine that proposes policy changes. A Hybrid edition, announced April 2025, runs the WAF in your own Kubernetes or VMs. Pricing is quote-only, with up to 9 months free for new Akamai customers. Forrester named it a WAF Leader in Q1 2025. Read more ↓ Show less ↑
Part 01 · Orient

The Akamai platform family

This page covers Akamai App & API Protector — the WAAP, including its Hybrid edition. The rest:

Quick facts

30-second orientation
Product
Web application and API protection: WAF, L7 DDoS, bot visibility and API discovery
Maker
Akamai Technologies, Cambridge, Massachusetts; NASDAQ: AKAM; CEO Dr. Tom Leighton
Status
Sold today; a Hybrid edition for apps off Akamai’s edge was announced on 9 April 2025
Price
Quote-only; Akamai offers up to 9 months free to new Akamai customers, plus a trial form
Licence
Licensing unit not published; Advanced Security Management and Malware Protection are optional
Deployment
Akamai’s edge in front of your origin, or Hybrid Protector as a sidecar, AMI or OVA image
Tuning
Adaptive Security Engine suggests self-tuning changes you apply in one click
Analysts
Leader, The Forrester Wave: Web Application Firewall Solutions, Q1 2025
India
Godrej protected 300+ applications with it in six months; Bengaluru NOC and SOC since 2018
In India via
TechBag — app inventory, quote in INR with GST, tuning review after go-live
Part 02 · Learn

Understand WAAP before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is WAAP?

Web application and API protection puts a WAF, Layer 7 DDoS defence, bot controls and API discovery in front of every public app.

A hand-tuned WAF per app vs one self-tuning WAAP — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA hand-tuned WAF per appAkamai App & API Protector
Who tunes the rulesAn engineer reading logs after each complaintEngine suggestions, accepted in one click
Layer 7 floodsStatic rate limits guessed in advanceBehavioural baselines from your own traffic
Unknown APIsFound by an auditor, or an attackerDiscovered from traffic and registered
Apps off the CDNA second WAF with its own rulesHybrid Protector under the same policy
Policy changesConsole clicks with no review trailTerraform or CLI through your pipeline
What it is NOT—Full Bot Manager, Account Protector or a price list

The cheapest test is the free trial: onboard one hostname in alert mode, read a week of events, and see which rules would have fired.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where attacks are stopped

Edge

Inspection on Akamai’s edge servers

Your DNS points at Akamai, so every request to a site or API is inspected on edge servers before it reaches the origin; network-layer floods are dropped there outright.

02
How rules keep up

Engine

Adaptive Security Engine

Machine learning, real-time threat intelligence and input from 400+ Akamai researchers score each request and suggest customer-specific tuning that you accept in one click.

03
Where the edge cannot reach

Hybrid

App & API Protector Hybrid

A Protector engine runs as a sidecar on NGINX, Istio or Envoy, or as an AMI or OVA reverse proxy, so inspection happens inside infrastructure you control.

04
Where policy and telemetry live

Control

Akamai Control Center and APIs

Security configurations, rate policies and exceptions sit in Control Center; Web Security Analytics shows events, and APIs, CLI and Terraform match every UI action.

Inspection on Akamai’s edge — with a Hybrid Protector for apps the edge never sees, under one Control Center policy.

Part 03 · Evaluate

Nine capabilities. Detect, mitigate, operate.

App & API Protector puts WAF, L7 DDoS, bot and API defence in front of every public app, and tunes itself with your approval.

Detect
WAF

Injection, XSS, SSRF and more

Rules cover SQL injection, cross-site scripting, local file inclusion and server-side request forgery, mapped to both OWASP Top 10 lists.

Detect
API discovery

APIs found in your own traffic

Known, unknown and changing APIs are discovered from web traffic with endpoints and profiles, then registered for protection in a few clicks.

Detect
Reputation

Bad clients, scored hourly

Client Reputation scores IPs on their past behaviour across Akamai customers; it comes with the Advanced Security Management module.

Mitigate
L7 DDoS

Behavioral DDoS Engine

Baselines built from country, network fingerprint and HTTPS attributes catch application-layer floods, with sensitivity set to your risk appetite.

Mitigate
Rate controls

Limits per path and client

Granular rate policies throttle by URL, client and request pattern, and URL Protection keeps critical paths serving real users during a flood.

Mitigate
Bots

Bot visibility, not Bot Manager

A directory of known bots, browser impersonation detection, conditional actions and crypto challenges are included; Bot Manager is sold apart.

Operate
Self-tuning

Recommendations, not rewrites

The Adaptive Security Engine proposes exceptions and threshold changes from local and global data; Akamai says it cut false positives 5x at launch.

Operate
As code

Terraform, CLI and GitOps

Akamai’s APIs, through its CLI or Terraform provider, cover every action in the console, so WAF policy can ship in the same pipeline as the app.

Operate
SIEM

Connectors included

Prebuilt SIEM connectors for Splunk, QRadar, ArcSight and others come with the product, alongside a SIEM API for any other analytics stack.

See it, don’t just read it

Watch App & API Protector in action

A 2025 unified WAAP demo, a 2024 how-to on narrow WAF exceptions, and Akamai’s 2023 case for one product across WAF, DDoS, bots and APIs. All from Akamai’s official channel.

Akamai (official)·Demo, July 2025

Demo: Unified WAAP Security in Action | Akamai App & API Protector

A walk through one console handling WAF events, rate controls and discovered APIs together.

Akamai (official)·How-to, June 2024

App and API Protector: How can I create WAF exceptions?

The everyday tuning task: carving a narrow exception for a rule that blocks legitimate traffic.

Akamai (official)·Overview, February 2023

See why companies are turning to Akamai App & API Protector

Akamai’s own pitch for consolidating WAF, DDoS, bot and API controls in one product.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Akamai App & API Protector

Every public app and API is a target. App & API Protector screens them at the edge and tunes itself.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Tuning that arrives as a suggestion

Most WAFs go quiet in alert-only mode because nobody has time to tune them. App & API Protector’s Adaptive Security Engine studies your traffic and Akamai’s wider view, then proposes exceptions and threshold changes you accept in one click. Akamai says it doubled detections and cut false positives 5x at launch.

02

Five controls, one console

WAF rules, Behavioral DDoS Engine, rate controls, bot visibility and API discovery sit in one product and one set of dashboards. Network-layer floods drop at the edge before any rule runs. Akamai’s brief also includes Site Shield, mPulse Lite and EdgeWorkers, so a team replacing separate tools has fewer contracts to run.

03

Same policy off the edge, with Hybrid

Apps that never pass through Akamai, such as internal portals or a second CDN, can still get the rules. Hybrid Protector runs as a sidecar on NGINX, Istio or Envoy, or as an AMI or OVA proxy, managed from the same Control Center. Akamai’s docs say that traffic is inspected without leaving your infrastructure.

04

Where it stops

There is no published price and no published licensing unit, so budgets wait for a quote. Bot visibility is not the full Bot Manager, account-takeover defence is Account Protector, and deep API posture testing is API Security; each is sold apart. Akamai documents no India-only processing option for edge inspection.

The idea
WAF, L7 DDoS, bots and APIs in one
The reach
Akamai edge, or Hybrid on your servers
The price
Quote-only; up to 9 months free
Proof, not promises

The numbers behind the platform

300+ apps
protected by Godrej Industries Group within six months, per its Akamai customer story
— Customer
up to 9 months
free for new Akamai customers under the current offer, add-ons and expert support included
— Vendor
5x
fewer false positives when the Adaptive Security Engine launched, by Akamai’s account
— Vendor
400+
Akamai security staff and threat researchers whose findings feed the tuning engine
— Vendor
22 criteria
in Forrester’s Q1 2025 WAF Wave, where Akamai was named a Leader among ten vendors
— Analyst
100%
availability SLA that Akamai’s product brief attaches to its edge platform
— Vendor

What your App & API Protector rollout looks like

Week 1Model

List every public app and API

Inventory hostnames, API endpoints and current WAF rules, and mark which apps sit behind a CDN and which never will.

Week 2Decide

Scope the offer and modules

Ask whether the free-months offer applies and whether you need Advanced Security Management or Malware Protection.

Week 3Pilot

Onboard in alert mode

Point one busy hostname at the edge with a starter policy in alert mode, and add a Hybrid sidecar for one internal app.

Month 2Prove

Review the tuning queue

Work through Adaptive Security Engine suggestions, register discovered APIs and set rate policies for login and search.

Month 3Commit

Switch to deny and codify

Move proven policies to deny, export the configuration to Terraform, and wire events into your SIEM and on-call.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.4
64+ reviews*
87% would recommend
Attack detection4.6
L7 DDoS defence4.5
Tuning effort4.1
Console and reporting4.0
Value for money3.7
5★
56%
4★
31%
3★
9%
2★
3%
1★
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
E-commerce
“A login flood hit during a sale weekend. The behavioural DDoS profile throttled it and checkout never slowed down.”
Head of Platform Engineering
E-commerce
BFSI
“We accepted about a dozen tuning recommendations in month one and finally moved our main policy from alert to deny.”
Application Security Lead
BFSI
Insurance
“API discovery turned up partner endpoints nobody had documented. Registering them took minutes, not a project.”
Security Architect
Insurance
SaaS
“Terraform for the security configuration means WAF changes now go through the same review as application code.”
DevSecOps Engineer
SaaS
Manufacturing
“Hybrid let us apply the same rules to an internal portal that never touches the CDN. The sidecar setup was fiddly.”
Cloud Infrastructure Manager
Manufacturing
Media
“Strong protection, but the quote took several rounds and the contract terms were hard to compare with rivals.”
IT Procurement Manager
Media
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the WAAP market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag WAAP Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Akamai App & API ProtectorThis page

Quote-only; up to 9 months free for new customers.

Grid 02 · The architecture

Deployment Reach × Protection Breadth

The grid nobody publishes — how many places the WAF can run, India options included, vs how many attack types one product covers.

Edge-only suitesRun-anywhere WAAPCloud-native rule enginesAppliance-first WAFs
Akamai App & API ProtectorThis page

Edge plus Hybrid sidecars or VMs; WAF, L7 DDoS, bots, API discovery.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Akamai App & API Protector vs the WAAP field

Against Cloudflare Application Security, Imperva Cloud WAF, F5 Distributed Cloud WAAP, AWS WAF and Fortinet FortiWeb — on deployment, price, tuning, APIs, bots and India.

DimensionAkamai App & API ProtectorCloudflare Application SecurityImperva Cloud WAF (Thales)F5 Distributed Cloud WAAPAWS WAFFortinet FortiWeb
What it isEdge WAAP, one productEdge WAAP on its networkCloud WAF, Thales-ownedSaaS WAAP from F5AWS-native rule engineML WAF, many forms
DeploymentEdge, plus HybridProxy on its networkCloud, or WAF GatewaySaaS, edges and sitesInside AWS onlyBox, VM, cloud or SaaS
Pricing modelQuote; unit unpublishedPlans, then EnterpriseQuote from ThalesAnnual packagesPay as you goAppliance or metered
Published entry priceNot publishedAbout $20 a siteNot publishedNot published$5 per web ACL$0.03 per app-hour
Included vs add-onCore in; modules extraAdd-ons on EnterpriseBot, API sold apartAPI depth in EnterpriseEach piece meteredDepends on licence
Network and scale100% SLA on the edge330+ cities, ~500 TbpsAbout 60 PoPs listedRegional edgesScales with AWSYour box sets the limit
Tuning and noiseEngine-led self-tuningManaged and ML rulesSignatures + analyticsBehaviour on EnterpriseYou write the rulesML anomaly models
API protectionDiscovery includedAPI ShieldSeparate API productOpenAPI and API Top 10Rules only, no inventoryREST and GraphQL
Bot defenceVisibility, not scoringML Bot ManagementAdvanced Bot ProtectionBot Defense is separateBot Control, meteredBot mitigation built in
DevOps and SIEMTerraform, SIEM kitsAPI and TerraformAPI and log exportConsole and APIAWS-native toolingSecurity Fabric
India data pathHybrid keeps it localIndian DCs, DLSMumbai and New DelhiMumbai and Chennai PoPsMumbai and HyderabadYour Indian DC
Support24/7, managed optionsDepends on the planTerms not publishedPer packagePaid plan for the SRTFortiCare via partners
Lock-in and exitTied to Akamai edgeTied to its proxyCloud or own boxesWithin F5’s estateAWS resources onlyRun it where you like
Best fitHigh-traffic, edge-firstSelf-serve to enterpriseCloud plus own DCBIG-IP shops going SaaSAll-in on AWSFortinet estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose App & API Protector if…

  • ✓Your sites and APIs face Layer 7 floods and you want behavioural baselines rather than hand-set rate limits
  • ✓Your team cannot keep tuning a WAF by hand and would accept engine-proposed exceptions after review
  • ✓Some apps never touch a CDN and you want one policy across the edge and your own clusters through Hybrid

Compare alternatives if…

  • ✓You need a price before the first meeting — Cloudflare’s plans and AWS WAF’s metering are published
  • ✓Everything runs on AWS and a rules engine billed per request is enough — AWS WAF fits that
  • ✓You want the WAF on your own hardware with Fortinet or Imperva WAF Gateway appliances

Do not expect…

  • ✓A licensing unit or list price on akamai.com, beyond the free-months offer
  • ✓Bot Manager’s full scoring or Account Protector’s account-takeover defence inside this product
  • ✓A Gartner Magic Quadrant placement — the analyst win here is Forrester’s Q1 2025 WAF Wave

TechBag has no web application & API protection guide yet, so Akamai App & API Protector sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does hand-tuning your WAF cost you?

Drag the sliders (web apps and APIs protected; security-engineer hour cost). Estimates model engineer time spent writing WAF exceptions, triaging false positives and re-tuning rate limits at an assumed 1.5 hours per application a year, with 70% of it removed by engine-proposed tuning. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual WAF-tuning cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote-only: Akamai publishes no price and no licensing unit for App & API Protector. New Akamai customers can currently get up to 9 months free, with add-ons and expert support included, and a free-trial form is offered. Advanced Security Management and Malware Protection are optional modules; Bot Manager and API Security are separate products. TechBag maps your apps first, then quotes in INR with GST.

App & API Protector

Best for public sites and APIs on the edge

  • Quote-only; licensing unit not published
  • Up to 9 months free for new Akamai customers
  • WAF, L7 DDoS, bot visibility, API discovery

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Hybrid and modules

Best for mixed estates and stricter needs

  • Hybrid Protector for apps off the edge
  • Advanced Security Management, Malware Protection
  • Managed WAAP service quoted separately

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
App inventory

How many hostnames and APIs need cover, and which of them sit outside any CDN and would need Hybrid?

2
Offer terms

Do you qualify as a new Akamai customer for the free-months offer, and what happens to price when it ends?

3
Modules

Is Advanced Security Management, Malware Protection or a managed WAAP service in the quote, or extra?

4
Bots and accounts

Is bot visibility enough, or do login abuse and scraping justify Bot Manager or Account Protector as well?

5
APIs

Will API discovery here do, or do you need posture tests and code scanning from the separate API Security product?

6
India data

Must inspection stay in India? Ask Akamai in writing; for in-house apps, Hybrid keeps traffic on your servers.

7
Operations

Who reviews the tuning suggestions each week, and will policy changes go through Terraform and code review?

8
Contract

Ask for the licensing unit, overage terms and renewal cap in writing, quoted in INR with GST.

FAQ

Questions buyers ask

It is Akamai’s web application and API protection product. Requests to your sites and APIs pass through Akamai’s edge, where a WAF, a Behavioral DDoS Engine, rate controls, bot visibility and API discovery inspect them before they reach your origin. An Adaptive Security Engine suggests tuning changes.

Ready to evaluate Akamai App & API Protector?

Size your apps and APIs first, or let a TechBag advisor scope a pilot that puts one busy hostname behind the edge in alert mode.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.