asn:14061
- Automated
- 0.97
- Harm
- 0.64
- Intent
- Scraper
Challenged, not blocked: a whole network can include real people, so broad keys only ever get a challenge.
In development. Open source under Apache-2.0.
An open-source Cloudflare Worker that watches your zone once a minute, asks Jev which groups of traffic are automated, and writes short-lived WAF challenges and blocks. Real visitors never wait on it.
A spike can be millions of requests. Scoring each one with a model would add latency for every visitor and cost a fortune. Spikeward runs beside Cloudflare instead of in front of it: the edge keeps doing its per-request work, and once a minute Spikeward reads your analytics, groups the spike, and asks Jev about the handful of groups that look wrong.
Jev calls scale with the number of suspicious clusters, usually tens per spike, not with your traffic.
Added latency for real visitors: none.
A cron tick runs this loop for each zone you manage. Everything is configurable in the app and takes effect on the next tick.
Read the last two minutes from Cloudflare's GraphQL Analytics API, grouped by IP, ASN, user agent, path, and status. Works on the Free plan with no Logpush.
Compare against a rolling baseline for this hour of the week. A spike starts at 3x baseline and at least 500 requests per minute.
Group the spike by IP, /24, ASN, user agent, and JA4 on Enterprise. Measure each group: rate, share of the spike, paths, error mix, asset ratio.
Drop your never-block list, verified bots, tiny clusters, and anything already handled.
Replace attack strings in paths with flags, so probes never reach the model and nothing identifying leaves your account.
One Jev call per cluster: is it automated, what does it want, how harmful is it. Verdicts are cached for the life of the action.
Your policy thresholds pick the action. Spikeward writes it to rules it owns, with an expiry, and logs why.
The Decisions screen records what Spikeward sent, what Jev answered, and what your policy did with it. The model's suggested action is advisory; your thresholds on probability and harm make the call, so you can tune behavior without rewriting prompts.
Add your own questions too. Ask "is this a partner integration?" and map the answer to allow.
asn:14061
Challenged, not blocked: a whole network can include real people, so broad keys only ever get a challenge.
Spikeward only touches rules and lists it created, tagged spikeward:. It never edits your own rules. Hard blocks are reserved for single IPs above the block threshold.
| What it targets | Default action | Default expiry |
|---|---|---|
| A single IP | Block when confident, otherwise challenge | 6 hours |
| A /24 or small IP range | Managed challenge | 1 hour |
| A whole network (ASN) | Managed challenge, never block | 1 hour |
| A user agent | Managed challenge | 1 hour |
| A TLS fingerprint (Enterprise) | Rate limit | 1 hour |
The Deploy to Cloudflare button forks the repo, creates the database and cache, and asks you for one secret. The rest happens in Spikeward's own setup screen.
The core loop runs on every Cloudflare plan. Higher plans add sharper signals. The app hides what your zone can't use.
| Capability | Free | Pro | Business | Enterprise |
|---|---|---|---|---|
| Spike detection and clustering | Yes | Yes | Yes | Yes |
| IP blocks and managed challenges | Yes | Yes | Yes | Yes |
| Custom IP lists per account | 1 | 10 | 10 | 1,000 |
| Bot score and JA4 as signals | No | No | No | Yes, with Bot Management |
| Rate limits keyed on JA4 | No | No | No | Yes, with Bot Management |
Spikeward layers on top of Cloudflare Bot Management and Super Bot Fight Mode. It doesn't replace them.
Nothing runs per real request, so your bill follows spikes, not traffic. Workers Paid is recommended for CPU headroom; the database and cache stay inside free limits.
Daily call and spend caps bound the worst case. When a cap is hit, Spikeward falls back to rules-only decisions and tells you.
Jev sees cluster features only: network, country, user-agent strings, path patterns, and rates. No raw IPs, cookies, or query values. Clusters are named with a salted hash.
Spikeward runs in your Cloudflare account, not ours. Your API token and Jev key are encrypted in your own database and never appear in your fork, build logs, or environment. Put Cloudflare Access in front for single sign-on.
No. It never sits in the request path. It reads analytics on a one-minute schedule and writes WAF rules, which Cloudflare's edge already evaluates.
Usually within one to two minutes of a spike starting. For very sharp bursts, pair it with a static rate limiting rule for the first minute.
Start in shadow mode and review a day of decisions first. Broad targets like whole networks only ever get a challenge, which real people pass. Every action expires, and you can undo any decision or mark it "always allow" in one click.
Jev is a TypeSafe System One model that turns structured state into typed answers with probabilities, such as "is this automated: 0.97". Spikeward asks it a fixed set of questions about each cluster, and you can add your own.
Spikeward falls back to rules-only decisions based on rate and ratio thresholds, and alerts you. Cached verdicts keep working.
Not by design. Spikeward targets spikes. Steady low-volume bots are better handled by Cloudflare's own bot tools.
The code is Apache-2.0. You pay Cloudflare and your Jev provider directly, usually about $5 a month plus cents.
Spikeward is being built in the open. Star the repo to follow along; the Deploy to Cloudflare button appears here with the first release.