Greyline is a reverse proxy that detects autonomous AI agents probing your API and deploys a counter-agent to interrogate, delay, or mislead them — before a single request reaches your real infrastructure.
Free tier available. No credit card required. 5-minute CNAME setup.
Agent sessions intercepted today
Signal detectors across 3 FP tiers
Added latency for legitimate traffic
Live interrogation transcript
Greyline detected a LangChain agent, scored it 94/100, and routed it to the Bouncer. What follows is the actual conversation — while your real API never received a single request.
Setup
Point your API subdomain at Greyline's edge. That's the entire setup. We provision TLS, handle routing, and start detecting immediately.
Add a single CNAME record: api.yourdomain.com → proxy.greyline.themeridianlab.com. Cloudflare auto-provisions your TLS cert within minutes.
11 signal detectors run on every inbound request — zero FP signals for known framework UAs, low FP signals for timing and header anomalies, and global threat intel from our shared fingerprint network.
High-scoring requests are routed to a Claude-powered counter-agent that interrogates, delays, or feeds fake data. Your real origin server is never touched. Legitimate traffic passes through with zero added latency.
Defense modes
Greyline adapts to your threat model. Start with Interrogate to waste agent time. Graduate to Poison when you want agents to walk away with confidently wrong data.
The Bouncer engages the agent in a bureaucratic conversation — requesting compliance documentation, company details, use case verification. Every turn wastes the agent's context window and API budget.
Same as Interrogate, but responses are artificially delayed by 8–30 seconds. For agents on tight timeouts, this causes upstream failures. For persistent agents, it burns real clock time.
Return convincing empty-200 responses. The agent believes it succeeded. No interrogation, no friction — just silent logging. Useful for mapping what agents are after without engaging them.
Provide your OpenAPI schema and Greyline generates structurally-valid but entirely fabricated API responses. Agents walk away with confidently wrong data. Only activates at score ≥ 95 to eliminate false-positive liability.
Who uses Greyline
SaaS APIs
Competitors are running agents against your API to map your product capabilities, pricing logic, and user data. Greyline stops them before they get anything useful.
Data APIs
Agents scraping your content to train proprietary models — without your permission and without paying. Greyline detects the pattern and serves them garbage.
Financial APIs
Rate limits don't stop creative agents. Greyline adds a layer of behavioral detection — even agents that stay within rate limits get caught by timing and header anomalies.
E-commerce APIs
Automated agents checking inventory and price points every few seconds. Greyline detects the heartbeat cadence and feeds them stale data while real customers get real answers.
Internal APIs
Employees building unauthorized agents against your internal APIs. Greyline surfaces the sessions so you can see exactly what's being accessed and with what framework.
Any HTTP service
On Business tier, confirmed agent fingerprints are shared (anonymized) across all Greyline customers. When one customer confirms an agent, everyone else gets the protection automatically.
Pricing
Every plan includes the full detection engine. Upgrade when you need the counter-agent features that make interception useful.
Free
Forever free. No credit card.
Pro
Everything in Free, plus:
Business
Everything in Pro, plus:
Trust signal
Add a Greyline badge to your docs or status page. It's a live SVG that updates with your real blocked-agent count. Some operators find it deters low-effort agents entirely.
Your badge preview