Sentra
Sentra Edge for Cloudflare Workers is now generally available

Bot mitigation for high-volume web apps

Stop scraping, credential attacks, transaction abuse, and fraud before they reach your app — without CAPTCHAs, slowdowns, or extra steps for real users.

or $ npm i @sentra/edge
Trusted in production by
Northwind lumen/co Atlas&Co VELA Halcyon RIVERLINE Mercato stride.io PARALLAX Foundry cinder.dev QUARTZ Mercer&Sons Holberton orbital/io Pinecone
Bot Defender

The only bot protection you need.

Every verdict at the edge — allowed, blocked, challenged, monitored — in one console. Drill into a session, see why it scored, and tune the rule that fired without leaving the page.

All systems operational View status
API Latency12 ms
Events /s3,142
us-east-1 · last 24 hr

Bot Defender Overview

Monitor protected requests, enforcement outcomes, and risk concentration across your active sites.

Allowed 71.4% 43,240 sessions · low risk
Blocked 24.1% 3,847 sessions · 6 threat types
Challenged 2.5% 1,204 sessions · 87% resolved
Monitored 2.0% 962 sessions · shadow mode

Traffic Overview

Requests evaluated by Sentra over time, split by verdict.

Allowed Challenged Blocked
8K6K4K2K0
00:0003:0006:0009:0012:0015:0018:0021:00Now

Decision Breakdown

How the rule engine resolved traffic — allowed, challenged, or blocked.

  • Allowed
    43,240
    71.4%
  • Blocked
    3,847
    24.1%
  • Challenged
    1,204
    2.5%
  • Monitored
    962
    2.0%

Live Verdicts Live

Session IDIP addressLocationRiskActionThreat
sess_f9a2b34191.108.4.1Moscow, RU94● BlockCredential stuffing
sess_a1c93e02203.0.113.45New York, US12● Allow—
sess_7d8f129045.33.32.156Fremont, US61● ChallengeSuspicious timing
sess_e3190aff198.51.100.22Chicago, US88● BlockCard testing
sess_b8d12904185.220.101.4Amsterdam, NL91● BlockAPI scraping
Showing 1–5 of 482
…
Fraud Intelligence

See the pattern.
Stop the abuse.

A login, a payment, a refund. See how they connect. Bring account activity, device signals, and risk decisions into one investigation.

All systems operational View status
API Latency12 ms
ProfileDefault

Activity explorer

Monitor account activity, risk signals, and policy decisions.

Production
Events in view—Across the selected filters
Accounts—Distinct account identities
Blocked—Actions stopped by a policy
Needs review—Flagged for investigation

Event volume / Hourly

Recent activity

Latest 4 events · UTC
TimeEventAccountRisk scoreDecisionLocationPrimary signal
Code Virtualizer

Your code. Harder to reverse.

Client-side code is exposed by design. We’re building a protection layer that makes sensitive JavaScript harder to inspect, modify, and reuse in automated attacks.

All systems operational View status
API Latency12 ms
ProfileDefault
JAVASCRIPT PROTECTION · DEFAULT PROFILE

Code Virtualizer Overview

Upload JavaScript for obfuscation and configure your protection profile.

Obfuscate JavaScript

Select a file to prepare it for protection.

JavaScript
Drop your JavaScript file here or browse from your computer .js, .mjs, .cjs · Up to 10 MB · One file at a time

Upload your source file, then apply your protection profile.

No file selected
Protection starts with the routines you choose. Keep secrets, authorization, and pricing validation on the server.
The protection roadmap

Built in layers. Designed for your build.

Virtualized logic

Move selected JavaScript routines into a dedicated instruction set, adding distance between shipped code and its original intent.

Polymorphic builds

Vary transformed output between builds to make repeatable signatures and reusable analysis less straightforward.

Execution boundaries

Define intended domains and deployment windows for protected bundles, alongside server-enforced access controls.

Tamper detection

Check protected routines for unexpected changes and surface integrity signals to your application.

Runtime awareness

Look for debugging, instrumentation, and altered browser APIs that could change how sensitive logic runs.

Build fingerprints

Associate protected bundles with a release so teams can trace unexpected copies back to a build.

Response policies

Decide how your application should respond to integrity signals—from recording an event to requesting server verification.

Protection telemetry

Bring runtime signals into your monitoring workflow to investigate unusual behavior across releases.

Client-side protection adds friction; keep secrets, pricing validation, and authorization on the server.