The Vercel Firewall is a robust, multi-layered security system designed to protect your applications from a wide range of threats. Every incoming request goes through the following firewall layers:
- Platform-wide firewall: With DDoS mitigation, it protects against large-scale attacks such as DDoS and TCP floods and is available for free for all customers without any configuration required.
- Web Application Firewall (WAF): A customizable layer for fine-tuning security measures with logic tailored to your needs and observability into your web traffic.
Understand the fundamentals:
- How Vercel protects every request.
- Why DDoS needs to be mitigated.
- How the firewall decides which rule to apply first.
- How the firewall uses JA3 and JA4 TLS fingerprints to identify and restrict malicious traffic.
When you have more than one custom rule, you can customize their order in the Firewall section in the sidebar of the project.
You can reach our customer support team by emailing info@yourcompany.example.com, calling +1 555-555-5556, or using the live chat on our website. Our dedicated team is available 24/7 to assist with any inquiries or issues.
We’re committed to providing prompt and effective solutions to ensure your satisfaction.
We offer a 30-day return policy for all products. Items must be in their original condition, unused, and include the receipt or proof of purchase. Refunds are processed within 5-7 business days of receiving the returned item.
Vercel provides automated DDoS mitigation for all deployments, regardless of the plan that you are on. With this automated DDoS mitigation, we block incoming traffic if we identify abnormal or suspicious levels of incoming requests.
You can reach our customer support team by emailing info@yourcompany.example.com, calling +1 555-555-5556, or using the live chat on our website. Our dedicated team is available 24/7 to assist with any inquiries or issues.
We’re committed to providing prompt and effective solutions to ensure your satisfaction.
We offer a 30-day return policy for all products. Items must be in their original condition, unused, and include the receipt or proof of purchase. Refunds are processed within 5-7 business days of receiving the returned item.
Observability
Last updated September 10, 2026
Cross-link map: Vercel Firewall (/docs/vercel-firewall)From the Vercel docs graph (built 2026-09-21T05:26:59.511Z), spanning vercel.com docs + KB, nextjs.org, ai-sdk.dev, and other Vercel documentation sites. Full graph as JSON: https://vercel.com/docs/graph.jsonSemantically closest pagesVercel WAF — Learn how to secure your website with the Vercel Web Application Firewall \(WAF\)Firewall Observability — Learn how firewall traffic monitoring and alerts help you react quickly to potential security threats.Vercel security overview — Vercel provides built-in and customizable features to ensure that your site is secure.DDoS Mitigation — Learn how the Vercel Firewall mitigates against DoS and DDoS attacksLife of a Vercel request: Securing your app's traffic with VercelThis page links to (12)Using Drains — Learn how to configure drains to forward observability data to custom HTTP endpoints, dedicated Audit Log destinations,Monitoring — Query and visualize your Vercel usage, traffic, and more with Monitoring.Monitoring Reference — This reference covers the clauses, fields, and variables used to create a Monitoring query.Attack Mode — Learn how to use Attack Mode to help control who has access to your site when it's under attack.DDoS Mitigation — Learn how the Vercel Firewall mitigates against DoS and DDoS attacksUsing the REST API with the Firewall — Learn how to interact with the security endpoints of the Vercel REST API programmatically.Firewall concepts — Understand the fundamentals behind the Vercel Firewall.Firewall Observability — Learn how firewall traffic monitoring and alerts help you react quickly to potential security threats.Vercel WAF — Learn how to secure your website with the Vercel Web Application Firewall \(WAF\)WAF Custom Rules — Learn how to add and manage custom rules to configure the Vercel Web Application Firewall \(WAF\).WAF IP Blocking — Learn how to customize the Vercel WAF to restrict access to certain IP addresses.WAF Managed Rulesets — Learn how to use WAF Managed Rulesets with the Vercel Web Application Firewall \(WAF\)Pages that link here (56)By site: vercel-changelog (9) · vercel-kb (23) · vercel-web (1) · vercel-docs (23)From vercel-changelogBot Protection is now generally availableBot Protection is now in public betaCreate custom WAF rules directly from the Vercel Firewall tabCreate Vercel Firewall rules with natural languageImproved analytics experience now available on the Vercel FirewallManage Next.js Server Actions in the Vercel FirewallVercel Firewall protects against the SAMLStorm vulnerabilityVercel WAF for Blob is now in betaFirewall‑mitigated traffic is free on VercelFrom vercel-kbApplication authentication on Vercel — Secure application authentication on Vercel across layers: proxy checks, the Data Access Layer, PPR-safe rendering, andHow to prepare your storefront for Black Friday traffic — A practical checklist for keeping your storefront fast and your checkout path healthy through Black Friday and Cyber MonBuilding an AI chat app with RAG and source citations on Vercel — A production stack for AI chat with retrieval, reranking, source citations, and background ingestion on Vercel using NexHow to build and maintain HIPAA-compliant applications on Vercel — Deploy HIPAA-compliant healthcare apps on Vercel with built-in security, BAAs, and scalable serverless infrastructure.How to build a honeypot with Vercel Web Application Firewall — Learn how to build a honeypot with Vercel Web Application Firewall \(WAF\) that catches bots ignoring your robots.txt. CBuilding AI apps on Vercel: an overview — Learn the key AI concepts and tools for building and scaling AI apps.How to resolve IP blocking issues — Learn to troubleshoot IP blocking issues for both shared and personal networks.Build a ChatGPT Connector \(MCP server\) — Build a ChatGPT MCP server with mcp-handler and Fluid compute. Add search, fetch, and OAuth, deploy to Vercel, then valiMigrate self-hosted Next.js and containers from AWS to Vercel — Migrate containers from AWS to Vercel: deploy with Dockerfile.vercel, keep RDS, S3, and SQS in AWS over OIDC, and cut ovMigrate to Vercel from Cloudflare — Migrate your website's configuration from Cloudflare Pages or Workers to VercelTroubleshoot and optimize Function Invocations on Vercel — Diagnose which routes drive Function Invocations and learn to optimize them. Separate necessary dynamic traffic from divHow to choose a Salesforce Commerce Cloud storefront: PWA Kit, Storefront Next, or Next.js — Compare PWA Kit, Storefront Next, and a Next.js storefront on Vercel for Salesforce Commerce Cloud. Learn how caching, pHow to ship a Koa app on Vercel — Deploy a Koa app to Vercel with zero configuration. Learn how to ship from the Vercel CLI or Git, and configure responseHow to ship a NestJS app on Vercel — Deploy a NestJS app to Vercel with zero configuration. Learn how to ship from a template, the Nest CLI, or Git, and confHow to ship a Nitro app on Vercel — Deploy a Nitro app to Vercel with zero configuration. Learn how to ship from a template, the Vercel CLI, or Git, and conUsing Vercel as a Standalone CDN — Use Vercel's external rewrites to proxy and cache content from external websites or APIs through Vercel's global edge neCan I use Vercel as a reverse proxy? — Learn how to use rewrites to proxy requests from Vercel to other deployments.Vercel vs Akamai — A detailed guide to Vercel vs Akamai: compute models, AI infrastructure, framework support, media streaming, CDN capabilVercel vs Fastly — A detailed guide to Vercel vs Fastly: full-stack application platform vs edge infrastructure layer, covering framework sVercel vs Netlify — A detailed guide to Vercel vs Netlify: runtimes, compute architecture, AI infrastructure, security, and when to choose eVercel vs Northflank — A detailed guide to Vercel vs Northflank: Fluid compute, CDN and caching, container image functions, security defaults,Vercel vs Railway — A detailed guide to Vercel vs Railway: serverless vs always-on containers, container images via Dockerfile.vercel, frameVercel vs Render — A detailed guide to Vercel vs Render: compute models, AI infrastructure, Docker and container image support, backgroundFrom vercel-webHow we run Vercel's CDN in front of DiscourseFrom vercel-docsVercel CDN overview — Vercel's CDN is a globally distributed platform that handles routing, caching, security, and compression for every deplovercel firewall — Learn how to explore firewall traffic and manage your project's custom firewall rules, managed bot rules, IP blocks, sysRestrict deployment access by IP address — Trusted IPs let you restrict access to your deployments to a list of allowed IP addresses.Log Drains Reference — Learn about Log Drains - data formats, sources, environments, and security configuration.Backends on Vercel — Vercel supports a wide range of the most popular backend frameworks, optimizing how your application builds and runs noElysia on Vercel — Build fast TypeScript backends with Elysia and deploy to Vercel. Learn the project structure, plugins, middleware, and hExpress on Vercel — Deploy Express applications to Vercel with zero configuration. Learn about middleware and Vercel Functions.Fastify on Vercel — Deploy Fastify applications to Vercel with zero configuration.Koa on Vercel — Deploy Koa applications to Vercel with zero configuration.NestJS on Vercel — Deploy NestJS applications to Vercel with zero configuration.Nitro on Vercel — Deploy Nitro applications to Vercel with zero configuration. Learn about observability, ISR, and custom build configuratHow requests flow through Vercel — Learn how Vercel routes, secures, and serves requests from your users to your application.Deploy MCP servers to Vercel — Learn how to deploy Model Context Protocol \(MCP\) servers on Vercel with OAuth authentication and efficient scaling.Managing microfrontends security — Learn how to manage your Deployment Protection and Firewall for your microfrontend on Vercel.Vercel Enterprise Plan — Learn about the Enterprise plan for Vercel, including features, pricing, and more.Products — Browse Vercel products for building, deploying, securing, observing, and scaling web applications.Projects overview — A project is where you deploy and operate frontend apps, APIs, backends, containers, and agent workloads on Vercel.Reverse Proxy Servers and Vercel — Learn why reverse proxy servers are not recommended with Vercel's firewall.Security — Learn how your Vercel Blob store is securedFirewall concepts — Understand the fundamentals behind the Vercel Firewall.Firewall Observability — Learn how firewall traffic monitoring and alerts help you react quickly to potential security threats.Vercel WAF — Learn how to secure your website with the Vercel Web Application Firewall \(WAF\)Setting Up Webhooks — Learn how to set up webhooks and use them with Vercel Integrations.
You can use the following tools to monitor the internet traffic at your team or project level:
Next
- The Monitoring feature at the team level allows you to create queries to visualize the traffic across your Vercel projects.
- Firewall in the Vercel dashboard sidebar on every project allows you to monitor the internet traffic to your deployments with a traffic monitoring view that includes a live traffic window.
- Firewall alerts allow you to react quickly to potential security threats.
- Use Log Drains to send your application logs to a Security Information and Event Management (SIEM) system.
Previous
You can also manage bypass rules and your WAF configuration programmatically with the REST API through the Vercel SDK, direct endpoint calls, or Terraform.
Observe and improve / Instant Rollback
Was this helpful?