Your WAF has sat in alert mode since launch. Nobody has time to tune it — Akamai App & API Protector inspects every request on Akamai’s edge — WAF, Layer 7 DDoS, bot visibility and API discovery — and Hybrid carries the same policy into clusters and VMs you run yourself.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Akamai App & API Protector — the WAAP, including its Hybrid edition. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Web application and API protection puts a WAF, Layer 7 DDoS defence, bot controls and API discovery in front of every public app.
What consolidation actually replaces, dimension by dimension.
| Dimension | A hand-tuned WAF per app | Akamai App & API Protector |
|---|---|---|
| Who tunes the rules | An engineer reading logs after each complaint | Engine suggestions, accepted in one click |
| Layer 7 floods | Static rate limits guessed in advance | Behavioural baselines from your own traffic |
| Unknown APIs | Found by an auditor, or an attacker | Discovered from traffic and registered |
| Apps off the CDN | A second WAF with its own rules | Hybrid Protector under the same policy |
| Policy changes | Console clicks with no review trail | Terraform or CLI through your pipeline |
| What it is NOT | — | Full Bot Manager, Account Protector or a price list |
The cheapest test is the free trial: onboard one hostname in alert mode, read a week of events, and see which rules would have fired.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Your DNS points at Akamai, so every request to a site or API is inspected on edge servers before it reaches the origin; network-layer floods are dropped there outright.
Machine learning, real-time threat intelligence and input from 400+ Akamai researchers score each request and suggest customer-specific tuning that you accept in one click.
A Protector engine runs as a sidecar on NGINX, Istio or Envoy, or as an AMI or OVA reverse proxy, so inspection happens inside infrastructure you control.
Security configurations, rate policies and exceptions sit in Control Center; Web Security Analytics shows events, and APIs, CLI and Terraform match every UI action.
Inspection on Akamai’s edge — with a Hybrid Protector for apps the edge never sees, under one Control Center policy.
App & API Protector puts WAF, L7 DDoS, bot and API defence in front of every public app, and tunes itself with your approval.
Rules cover SQL injection, cross-site scripting, local file inclusion and server-side request forgery, mapped to both OWASP Top 10 lists.
Known, unknown and changing APIs are discovered from web traffic with endpoints and profiles, then registered for protection in a few clicks.
Client Reputation scores IPs on their past behaviour across Akamai customers; it comes with the Advanced Security Management module.
Baselines built from country, network fingerprint and HTTPS attributes catch application-layer floods, with sensitivity set to your risk appetite.
Granular rate policies throttle by URL, client and request pattern, and URL Protection keeps critical paths serving real users during a flood.
A directory of known bots, browser impersonation detection, conditional actions and crypto challenges are included; Bot Manager is sold apart.
The Adaptive Security Engine proposes exceptions and threshold changes from local and global data; Akamai says it cut false positives 5x at launch.
Akamai’s APIs, through its CLI or Terraform provider, cover every action in the console, so WAF policy can ship in the same pipeline as the app.
Prebuilt SIEM connectors for Splunk, QRadar, ArcSight and others come with the product, alongside a SIEM API for any other analytics stack.
A 2025 unified WAAP demo, a 2024 how-to on narrow WAF exceptions, and Akamai’s 2023 case for one product across WAF, DDoS, bots and APIs. All from Akamai’s official channel.
A walk through one console handling WAF events, rate controls and discovered APIs together.
The everyday tuning task: carving a narrow exception for a rule that blocks legitimate traffic.
Akamai’s own pitch for consolidating WAF, DDoS, bot and API controls in one product.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most WAFs go quiet in alert-only mode because nobody has time to tune them. App & API Protector’s Adaptive Security Engine studies your traffic and Akamai’s wider view, then proposes exceptions and threshold changes you accept in one click. Akamai says it doubled detections and cut false positives 5x at launch.
WAF rules, Behavioral DDoS Engine, rate controls, bot visibility and API discovery sit in one product and one set of dashboards. Network-layer floods drop at the edge before any rule runs. Akamai’s brief also includes Site Shield, mPulse Lite and EdgeWorkers, so a team replacing separate tools has fewer contracts to run.
Apps that never pass through Akamai, such as internal portals or a second CDN, can still get the rules. Hybrid Protector runs as a sidecar on NGINX, Istio or Envoy, or as an AMI or OVA proxy, managed from the same Control Center. Akamai’s docs say that traffic is inspected without leaving your infrastructure.
There is no published price and no published licensing unit, so budgets wait for a quote. Bot visibility is not the full Bot Manager, account-takeover defence is Account Protector, and deep API posture testing is API Security; each is sold apart. Akamai documents no India-only processing option for edge inspection.
Inventory hostnames, API endpoints and current WAF rules, and mark which apps sit behind a CDN and which never will.
Ask whether the free-months offer applies and whether you need Advanced Security Management or Malware Protection.
Point one busy hostname at the edge with a starter policy in alert mode, and add a Hybrid sidecar for one internal app.
Work through Adaptive Security Engine suggestions, register discovered APIs and set rate policies for login and search.
Move proven policies to deny, export the configuration to Terraform, and wire events into your SIEM and on-call.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“A login flood hit during a sale weekend. The behavioural DDoS profile throttled it and checkout never slowed down.”
“We accepted about a dozen tuning recommendations in month one and finally moved our main policy from alert to deny.”
“API discovery turned up partner endpoints nobody had documented. Registering them took minutes, not a project.”
“Terraform for the security configuration means WAF changes now go through the same review as application code.”
“Hybrid let us apply the same rules to an internal portal that never touches the CDN. The sidecar setup was fiddly.”
“Strong protection, but the quote took several rounds and the contract terms were hard to compare with rivals.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the WAAP market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only; up to 9 months free for new customers.
The grid nobody publishes — how many places the WAF can run, India options included, vs how many attack types one product covers.
Edge plus Hybrid sidecars or VMs; WAF, L7 DDoS, bots, API discovery.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cloudflare Application Security, Imperva Cloud WAF, F5 Distributed Cloud WAAP, AWS WAF and Fortinet FortiWeb — on deployment, price, tuning, APIs, bots and India.
| Dimension | Akamai App & API Protector | Cloudflare Application Security | Imperva Cloud WAF (Thales) | F5 Distributed Cloud WAAP | AWS WAF | Fortinet FortiWeb |
|---|---|---|---|---|---|---|
| What it is | Edge WAAP, one product | Edge WAAP on its network | Cloud WAF, Thales-owned | SaaS WAAP from F5 | AWS-native rule engine | ML WAF, many forms |
| Deployment | Edge, plus Hybrid | Proxy on its network | Cloud, or WAF Gateway | SaaS, edges and sites | Inside AWS only | Box, VM, cloud or SaaS |
| Pricing model | Quote; unit unpublished | Plans, then Enterprise | Quote from Thales | Annual packages | Pay as you go | Appliance or metered |
| Published entry price | Not published | About $20 a site | Not published | Not published | $5 per web ACL | $0.03 per app-hour |
| Included vs add-on | Core in; modules extra | Add-ons on Enterprise | Bot, API sold apart | API depth in Enterprise | Each piece metered | Depends on licence |
| Network and scale | 100% SLA on the edge | 330+ cities, ~500 Tbps | About 60 PoPs listed | Regional edges | Scales with AWS | Your box sets the limit |
| Tuning and noise | Engine-led self-tuning | Managed and ML rules | Signatures + analytics | Behaviour on Enterprise | You write the rules | ML anomaly models |
| API protection | Discovery included | API Shield | Separate API product | OpenAPI and API Top 10 | Rules only, no inventory | REST and GraphQL |
| Bot defence | Visibility, not scoring | ML Bot Management | Advanced Bot Protection | Bot Defense is separate | Bot Control, metered | Bot mitigation built in |
| DevOps and SIEM | Terraform, SIEM kits | API and Terraform | API and log export | Console and API | AWS-native tooling | Security Fabric |
| India data path | Hybrid keeps it local | Indian DCs, DLS | Mumbai and New Delhi | Mumbai and Chennai PoPs | Mumbai and Hyderabad | Your Indian DC |
| Support | 24/7, managed options | Depends on the plan | Terms not published | Per package | Paid plan for the SRT | FortiCare via partners |
| Lock-in and exit | Tied to Akamai edge | Tied to its proxy | Cloud or own boxes | Within F5’s estate | AWS resources only | Run it where you like |
| Best fit | High-traffic, edge-first | Self-serve to enterprise | Cloud plus own DC | BIG-IP shops going SaaS | All-in on AWS | Fortinet estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no web application & API protection guide yet, so Akamai App & API Protector sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (web apps and APIs protected; security-engineer hour cost). Estimates model engineer time spent writing WAF exceptions, triaging false positives and re-tuning rate limits at an assumed 1.5 hours per application a year, with 70% of it removed by engine-proposed tuning. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote-only: Akamai publishes no price and no licensing unit for App & API Protector. New Akamai customers can currently get up to 9 months free, with add-ons and expert support included, and a free-trial form is offered. Advanced Security Management and Malware Protection are optional modules; Bot Manager and API Security are separate products. TechBag maps your apps first, then quotes in INR with GST.
Best for public sites and APIs on the edge
Best for a broader rollout
Best for mixed estates and stricter needs
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many hostnames and APIs need cover, and which of them sit outside any CDN and would need Hybrid?
Do you qualify as a new Akamai customer for the free-months offer, and what happens to price when it ends?
Is Advanced Security Management, Malware Protection or a managed WAAP service in the quote, or extra?
Is bot visibility enough, or do login abuse and scraping justify Bot Manager or Account Protector as well?
Will API discovery here do, or do you need posture tests and code scanning from the separate API Security product?
Must inspection stay in India? Ask Akamai in writing; for in-house apps, Hybrid keeps traffic on your servers.
Who reviews the tuning suggestions each week, and will policy changes go through Terraform and code review?
Ask for the licensing unit, overage terms and renewal cap in writing, quoted in INR with GST.
Size your apps and APIs first, or let a TechBag advisor scope a pilot that puts one busy hostname behind the edge in alert mode.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.