Vercel WAF for Blob is now in beta
Vercel WAF now protects Vercel Blob stores with the same rules (deny, challenge, rate limit) that guard deployments, evaluated at the edge with no code changes required. Protection is available on all plans and configured via a single dashboard switch during the beta period.
The can now protect a Vercel Blob store. The same rules that guard your deployments (deny, challenge, rate limit) now apply to blob traffic with no changes to your code, blob URLs, or . Vercel WAF@vercel/blob
Every blob is already served through , so protection is a switch on the store, not a new proxy. Stop scrapers, geo-restrict downloads, rate limit expensive assets, or block abusive IPs before a byte is served.Vercel's CDN
Rules evaluate at the edge, matching on IP, country, path, and :more
The OWASP Core Ruleset is not supported, since it targets dynamic application traffic, not object delivery.
Setup is a single switch in the dashboard:
During the beta, setup is dashboard-only, and challenges need a browser to solve, so server-side requests matching a challenge rule are blocked. Use challenge rules for browser traffic.@vercel/blob
Vercel WAF for Blob is available in beta on all plans. See the for the full setup.documentation
Deny returns a and stops the request early, so no data transfer is incurred.
403Challenge serves the standard browser challenge, and a request that fails it is blocked.
Rate limit returns a when a client exceeds your limit.
429Redirect and log behave as they do for deployment traffic.
Open , select , then .your Blob storeSettingsProtect your store
Vercel connects it to a shared on your team. You author its rules with the standard rule builder, and they take effect immediately.
vercel-blob-default-projectOne rule set covers every protected store, so rules can't be scoped per store.
Protecting a store
Source: original entry ↗
More from Vercel
Follow Vercel to get its new changes in your feed and email digest.
OpenAI Decisions API now available on AI Gateway
OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.
Timestamp attributes now supported in Vercel Flags
Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.
Glyph Cluster now available in stealth on AI Gateway
Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.