Introducing Kong Bot Detector for Dedicated Cloud Gateways
Blog post from Kong
Kong has introduced Bot Detector in beta for Dedicated Cloud Gateways version 3.10 and later, a Kong Konnect-managed capability intended to identify, monitor, allow, or block automated API traffic before it reaches upstream services. The tool combines Kong-maintained rules for signals such as suspicious user agents, abnormal request shapes, vulnerability probes, and injection attempts with customizable rules that take precedence and can match IPs, CIDRs, JA4 fingerprints, user agents, paths, or advanced Kong Expression Language conditions. It begins in monitoring mode to record potential detections without affecting traffic, allowing users to review results, create passthrough rules for false positives, and later enable blocking, which returns a 403 response and excludes blocked requests from gateway usage billing. Kong positions the feature as complementary to WAFs, IP restrictions, CDNs, and edge bot-management products because it evaluates requests as they arrive at the API gateway, while trusted crawlers and monitoring services are protected through an allowlist. Future plans include network-level allow and block lists and a behavioral detection model trained on Cloud Gateway traffic.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.