Protect your applications with Coraza WAF
A high-performance reverse proxy with built-in Web Application Firewall powered by Coraza and OWASP Core Rule Set. Defend against SQL injection, XSS, RCE, and more.
Get started in minutes
Deploy enterprise-grade web application security in three simple steps
Pull the Docker image
Configure your backends
View full configuration options
View full configuration options
BACKENDS: JSON map of hostnames to backend server addressesPROXY_APIS_HOSTS: Comma-separated list of API hosts (uses PL2 protection profile)PROXY_WEB_HOSTS: Comma-separated list of web hosts (uses PL1 protection profile)PROXY_RATE_LIMIT: Requests per second per IPPROXY_RATE_BURST: Maximum burst size for rate limitingGEO_BLOCK_ENABLED: Enable GeoIP filtering (true/false)PROXY_BLOCK_BOTS: Block known bots (true/false)
Key features
Everything you need to secure your web applications and APIs
WAF protection
Rate limiting
GeoIP filtering
Bot detection
Multi-backend routing
Attack detection
Explore the documentation
Learn how to deploy, configure, and operate Coraza Proxy
Deployment guide
Deploy with Docker, Docker Compose, or Kubernetes. Production-ready configurations included.
View deployment optionsConfiguration reference
Complete guide to backends, WAF rules, rate limiting, GeoIP blocking, and bot detection.
Browse configurationSecurity testing
Test WAF protection with real attack payloads. Verify SQLi, XSS, RCE, and LFI detection.
View test casesAPI reference
Complete reference for all environment variables, core functions, and internal APIs.
Explore API docsReady to secure your applications?
Deploy Coraza Proxy in minutes and protect your web applications and APIs from OWASP Top 10 vulnerabilities.
