All Products
Search
Document Center

Web Application Firewall:WAF API Security module upgrade

Last Updated:Aug 03, 2026

Dear Alibaba Cloud users,

Thank you for your long-standing trust and support for the Alibaba Cloud Web Application Firewall (WAF) product.

To enhance API security protection capabilities, Alibaba Cloud Web Application Firewall (WAF) 3.0 will officially launch Agentic API Security (AI-powered edition) on July 31, 2026, along with feature and billing upgrades to the existing API Security module. Please evaluate the business impact in advance and complete the necessary preparations.

Effective date

July 31, 2026, 00:00:00 (Beijing Time). The actual effective time is subject to system notification.

Change overview

WAF 3.0 will introduce the new Agentic API Security module, which builds upon the existing API Security capabilities by incorporating an AI-powered intelligent detection engine (Agentic AI). Advanced security operations and management capabilities will be added in the future, comprehensively enhancing the depth and breadth of API security protection.

After the new version is launched, the existing "API Security" module will enter a maintenance period with no further feature updates.

Feature changes

Agentic API Security (new version)

Agentic API Security is the AI-powered intelligent edition of API Security. Compared to the original API Security (rule-based detection), it primarily adds the following capabilities:

  • An Agentic API security detection engine powered by large language models, enhancing the ability to identify unknown threats.

  • More comprehensive API security operations and management features.

Original API Security (legacy version)

After the new version is launched, the existing "API Security" module will enter a maintenance period:

  • Users who have already enabled the legacy API Security can continue to use it normally without any impact on functionality.

  • The legacy API Security will no longer release new features and will only receive necessary stability maintenance.

  • We recommend that users upgrade to Agentic API Security as soon as possible for more comprehensive protection.

Billing changes

Note

Actual prices are subject to the purchase page.

Subscription WAF

New users

Starting from July 31, 2026, when purchasing a new WAF 3.0 instance, the API Security module will provide Agentic API Security by default, and the legacy "API Security" option will no longer be displayed.

Existing users

  • If you have not enabled the legacy API Security: You can directly purchase Agentic API Security when upgrading your instance.

  • If you have already enabled the legacy API Security: Please contact your account manager for assistance with upgrading to Agentic API Security.

Once you choose to enable Agentic API Security, you cannot switch back to the legacy API Security. Please confirm before proceeding.

Agentic API Security pricing

  • Base version fee

    • Pro: 1,080 USD/month

    • Enterprise: 1,800 USD/month

    • Ultimate: 3,600 USD/month

  • QPS expansion add-on fee: After enabling Agentic API Security, the API Security QPS expansion fee within the original QPS expansion fee will become the AI module QPS expansion fee, priced at 0.36 USD/QPS/month (originally 0.30 USD/QPS/month), displayed separately in the billing details.

  • Elastic QPS expansion add-on fee: After enabling Agentic API Security, the API Security elastic QPS expansion fee within the original elastic QPS expansion fee will become the AI module elastic QPS expansion fee, priced at 0.018 USD/QPS/day (originally 0.015 USD/QPS/day), displayed separately in the billing details.

Pay-as-you-go WAF

New Credit billing unit

Agentic API Security pay-as-you-go adopts the new Credit billing unit (100 Credits = 0.2 USD), with the following unit prices:

  • Instance fee (protected object): 125 Credits / protected object / hour

  • Request processing fee: 1 Credit / 1,200 requests / hour

Switching for existing users

  • Existing pay-as-you-go API Security users will continue to use SeCU billing, with no impact on functionality or billing.

  • A "Switch to Agentic API Security" button will be added to the API Security console page. Clicking it will switch to the new Credit billing mode and unlock all new features of Agentic API Security.

Important

The switch is a one-way operation. Once you switch to Credit billing, API Security-related billing items cannot be reverted to SeCU billing. Please make sure you fully understand the implications before proceeding. A pop-up window will explain the price changes during the switch.

Pay-as-you-go bill composition

After switching, the WAF pay-as-you-go bill will consist of two parts: SeCU and Credit:

  • SeCU portion: Covers WAF instance and traffic fees, resource access feature fees, web core protection feature fees, and legacy advanced protection feature fees (including Bot Management, legacy API Security, etc.).

  • Credit portion: Covers the new Agentic API Security protected object fees and traffic fees.

Recommended actions

  • Evaluate the impact: Based on your business needs, evaluate whether to upgrade and the impact on your API security protection policies and costs after the upgrade.

  • Learn about the new features: We recommend logging in to the WAF console to learn about the new capabilities and billing details of Agentic API Security.

  • Plan your switch timeline: If you are currently using the legacy API Security, we recommend switching to Agentic API Security as soon as possible after July 31, 2026 for more comprehensive security protection. If you have any questions, please contact your account manager.

FAQ

What is the difference between Agentic API Security and the legacy API Security?

Agentic API Security is a comprehensive upgrade of the legacy API Security. Building upon the original rule-based API data leakage and anomalous request detection capabilities, it introduces an AI-powered intelligent detection engine that performs contextual semantic recognition of sensitive data and business purposes. It also adds advanced security operations and management capabilities (such as API Swagger 3.0 validation), significantly enhancing both the depth and breadth of protection.

Will the cost increase after upgrading?

Yes. The overall cost of Agentic API Security will be slightly higher than the legacy API Security. Please refer to the details above. The billing structure of Agentic API Security is more transparent.

I have purchased the legacy API Security. Do I have to switch?

No, switching is not mandatory. The legacy API Security can continue to be used, but it will no longer receive feature updates and will gradually become outdated. We recommend proactively upgrading to Agentic API Security at an appropriate time.

Can pay-as-you-go users revert to SeCU after switching to Credit billing?

No. The switch to Credit billing is a one-way operation, and API Security-related billing items cannot be reverted to SeCU after the switch. Please carefully read the pricing and feature information in the pop-up window before switching.