VOOZH about

URL: https://thenewstack.io/arcjet-reaches-v10-promises-stable-security-for-javascript-apps/

⇱ Arcjet reaches v1.0, promises stable security for JavaScript apps - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2026-02-14 07:00:18
Arcjet reaches v1.0, promises stable security for JavaScript apps
AI / JavaScript / Security

Arcjet reaches v1.0, promises stable security for JavaScript apps

After two years of public testing with minimal breaking changes, Arcjet formalizes API stability in a JavaScript ecosystem plagued by dependency churn.
Feb 14th, 2026 7:00am by Darryl K. Taft
👁 Featued image for: Arcjet reaches v1.0, promises stable security for JavaScript apps
Photo by Growtika on Unsplash.

Arcjet this week released v1.0 of its JavaScript SDK, moving it from beta to a stable, production-ready API.

Arcjet’s security platform ships with an organization’s code and provides AI security embedded in every request. The Arcjet AI model performs attack detection, including bot detection, rate limiting, email validation, form spam prevention, and data redaction directly within a developer’s code. It is built to integrate directly into modern codebases to embed security into a codebase without sacrificing flexibility – easing the process of shifting left.

Two years in the making

Arcjet took more than two years to build and test the SDK in public to maintain stability and reduce the maintenance burden for developers.

“After 2.5 years of alpha/beta versions, we’ve declared the SDK stable and production ready,” David Mytton, founder and CEO of Arcjet tells The New Stack. “We’ve treated it as ‘production’ since the beginning — reliability, redundancy, security, etc. — but this is the official label.”

Stability is first class

Arcjet treats stability as a first-class product requirement rather than an afterthought, Mytton says, adding that adoption of security products depends on reliability, particularly in the JavaScript ecosystem.

“Security tooling only helps if it stays installed and the constant version churn that the JS ecosystem suffers from is a big reason libraries get ripped out,” Mytton tells The New Stack. “We have lots of plans for new features, but we’re aiming to avoid breaking changes.”

Throughout the alpha and beta period, Arcjet introduced only three breaking changes over two years, most of them minimal, while maintaining backward compatibility wherever possible, the company says.

“Shipping v1.0 is a clear signal to developers that Arcjet’s API is stable and fully tested with real production workloads,” Mytton notes in a statement. “Security should not introduce more work. It should quietly remove an entire class of problems so teams can focus on building features instead of maintaining tooling.”

Security cannot be an afterthought

Arcjet first released its JavaScript SDK in alpha in 2023, and the SDK graduated to beta in January 2025 once the core API design was proven in real-world usage. The company says thousands of developers have deployed its SDK to production environments.

“We have spent a lot of time talking about shift left security in the last 10 years, but it’s mostly been bullshit,” James Governor, co-founder and analyst at RedMonk, tells The New Stack. “Unless you make the right thing the absurdly easy thing nobody is going to do it. Without great developer experience security will always be an afterthought. JavaScript security is a dumpster fire and AI is only making it worse. It’s good to see Arcjet innovating in this area, really focusing on DX as the means to improve application security.”

New feature plans

Regarding the plans for new features that he mentioned, Mytton listed:

  • Public release of Arcjet’s local model: Announced last year, it will be publicly available in the next couple of months. It runs inside the application environment and helps reduce false positives on sensitive routes by making decisions with more local context.
  • Richer threat intel in decisions: We already use real-time reputation signals internally, but we’re planning to expose the underlying intel (the “why” behind a decision) so teams can feed it into their own fraud/risk analysis pipelines, not just treat Arcjet as a black box.
  • Support for more languages: We already released our Python beta based on the lessons from JS. Other languages like Java and Go are coming.

The company released a beta version of its Python SDK last month.

“We started with the JavaScript ecosystem, because that’s where most new applications are being built with full stack development,” Mytton told The New Stack last month. The company started with support for both JavaScript and TypeScript applications.

Novel approach

Arcjet’s novel approach involves embedding a WebAssembly (Wasm) module in its SDK, allowing for local analysis of incoming requests at near-native speed.

“Arcjet has helped us easily invest in the security and efficiency of our platform,” Chris Ellis, co-founder and CEO of Thatch, a beta user of Arcjet, told The New Stack in a previous interview.

“Unlike a separate security service that gives us little visibility into its impact on our system, Arcjet gives us rich application-level insights at runtime that help us build security automations in critical parts of our application, from sales to customer onboarding,” he added.

TRENDING STORIES
Darryl K. Taft covers DevOps, software development tools and developer-related issues from his office in the Baltimore area. He has more than 25 years of experience in the business and is always looking for the next scoop. He has worked...
Read more from Darryl K. Taft
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.