Spikeward

In development. Open source under Apache-2.0.

When bots spike your site, Spikeward judges the clusters and shuts them out in minutes.

An open-source Cloudflare Worker that watches your zone once a minute, asks Jev which groups of traffic are automated, and writes short-lived WAF challenges and blocks. Real visitors never wait on it.

A replayed scraper spike. Traffic crosses the trigger line, Spikeward sends twelve clusters to Jev, and a managed challenge on one hosting network brings it back to baseline.

AI judges the clusters, not the requests.

A spike can be millions of requests. Scoring each one with a model would add latency for every visitor and cost a fortune. Spikeward runs beside Cloudflare instead of in front of it: the edge keeps doing its per-request work, and once a minute Spikeward reads your analytics, groups the spike, and asks Jev about the handful of groups that look wrong.

Jev calls scale with the number of suspicious clusters, usually tens per spike, not with your traffic.

What happens every minute

A cron tick runs this loop for each zone you manage. Everything is configurable in the app and takes effect on the next tick.

  1. Poll

    Read the last two minutes from Cloudflare's GraphQL Analytics API, grouped by IP, ASN, user agent, path, and status. Works on the Free plan with no Logpush.

  2. Baseline

    Compare against a rolling baseline for this hour of the week. A spike starts at 3x baseline and at least 500 requests per minute.

  3. Cluster

    Group the spike by IP, /24, ASN, user agent, and JA4 on Enterprise. Measure each group: rate, share of the spike, paths, error mix, asset ratio.

  4. Filter

    Drop your never-block list, verified bots, tiny clusters, and anything already handled.

  5. Sanitize

    Replace attack strings in paths with flags, so probes never reach the model and nothing identifying leaves your account.

  6. Judge

    One Jev call per cluster: is it automated, what does it want, how harmful is it. Verdicts are cached for the life of the action.

  7. Enforce

    Your policy thresholds pick the action. Spikeward writes it to rules it owns, with an expiry, and logs why.

Every decision shows its work.

The Decisions screen records what Spikeward sent, what Jev answered, and what your policy did with it. The model's suggested action is advisory; your thresholds on probability and harm make the call, so you can tune behavior without rewriting prompts.

Add your own questions too. Ask "is this a partner integration?" and map the answer to allow.

asn:14061

Hosting network, 180 IPs, 62% of the spike

Managed challenge
Automated
0.97
Harm
0.64
Intent
Scraper

Challenged, not blocked: a whole network can include real people, so broad keys only ever get a challenge.

Expires in 58 min

Narrow when it's sure. Gentle when it isn't.

Spikeward only touches rules and lists it created, tagged spikeward:. It never edits your own rules. Hard blocks are reserved for single IPs above the block threshold.

What it targetsDefault actionDefault expiry
A single IPBlock when confident, otherwise challenge6 hours
A /24 or small IP rangeManaged challenge1 hour
A whole network (ASN)Managed challenge, never block1 hour
A user agentManaged challenge1 hour
A TLS fingerprint (Enterprise)Rate limit1 hour

Safety rails, on by default

  • Shadow mode first. New zones log what Spikeward would do for 24 hours. You review, then switch to enforce.
  • Everything expires. Every block and challenge has a timer. Repeat offenders get double the time, up to 7 days.
  • Grey-zone alerts. Verdicts between 0.70 and 0.95 only challenge, and send you approve and reject links in Slack or email.
  • Rate cap. More than 50 new actions in an hour pauses enforcement and alerts you.
  • Never-block list. IPs, networks, user agents, and paths you trust. Verified bots are always excluded.
  • Kill switch. One button turns off every Spikeward rule on every zone.
  • Self-cleaning. Each tick removes expired items and reconciles its records with Cloudflare, so a failed call never leaves an orphan block.

From button to protected in one sitting

The Deploy to Cloudflare button forks the repo, creates the database and cache, and asks you for one secret. The rest happens in Spikeward's own setup screen.

  1. Deploy. Click the button and paste a long random secret.
  2. Claim. Open your new app, enter the secret, and create an admin passkey.
  3. Connect Cloudflare. Paste a least-privilege API token. Spikeward refuses tokens with more access than it needs.
  4. Connect Jev. Paste a TypeSafe key, or route through OpenRouter or Vercel AI Gateway.
  5. Pick zones. Spikeward detects each zone's plan and shows what's available.
  6. Watch, then enforce. Review a day of shadow-mode decisions and flip the switch.

Works on the Free plan

The core loop runs on every Cloudflare plan. Higher plans add sharper signals. The app hides what your zone can't use.

CapabilityFreeProBusinessEnterprise
Spike detection and clusteringYesYesYesYes
IP blocks and managed challengesYesYesYesYes
Custom IP lists per account110101,000
Bot score and JA4 as signalsNoNoNoYes, with Bot Management
Rate limits keyed on JA4NoNoNoYes, with Bot Management

Spikeward layers on top of Cloudflare Bot Management and Super Bot Fight Mode. It doesn't replace them.

About $5 a month, plus cents

Nothing runs per real request, so your bill follows spikes, not traffic. Workers Paid is recommended for CPU headroom; the database and cache stay inside free limits.

Daily call and spend caps bound the worst case. When a cap is hit, Spikeward falls back to rules-only decisions and tells you.

Workers Paid
$5 / month
D1 and KV
Free tier
Jev, a typical spike
~$0.03
Jev, a very bad day
~$2.50

Your visitors stay anonymous

Jev sees cluster features only: network, country, user-agent strings, path patterns, and rates. No raw IPs, cookies, or query values. Clusters are named with a salted hash.

Your keys stay yours

Spikeward runs in your Cloudflare account, not ours. Your API token and Jev key are encrypted in your own database and never appear in your fork, build logs, or environment. Put Cloudflare Access in front for single sign-on.

Questions

Does Spikeward slow down my site?

No. It never sits in the request path. It reads analytics on a one-minute schedule and writes WAF rules, which Cloudflare's edge already evaluates.

How fast does it react?

Usually within one to two minutes of a spike starting. For very sharp bursts, pair it with a static rate limiting rule for the first minute.

What if it challenges real people?

Start in shadow mode and review a day of decisions first. Broad targets like whole networks only ever get a challenge, which real people pass. Every action expires, and you can undo any decision or mark it "always allow" in one click.

What is Jev?

Jev is a TypeSafe System One model that turns structured state into typed answers with probabilities, such as "is this automated: 0.97". Spikeward asks it a fixed set of questions about each cluster, and you can add your own.

What if Jev is down or I hit my cap?

Spikeward falls back to rules-only decisions based on rate and ratio thresholds, and alerts you. Cached verdicts keep working.

Will it catch a slow, low-volume bot?

Not by design. Spikeward targets spikes. Steady low-volume bots are better handled by Cloudflare's own bot tools.

Is it really free?

The code is Apache-2.0. You pay Cloudflare and your Jev provider directly, usually about $5 a month plus cents.

Put a ward on your next spike.

Spikeward is being built in the open. Star the repo to follow along; the Deploy to Cloudflare button appears here with the first release.