Original Message:
Sent: 12-08-2025 09:42
From: Jaired Anderson
Subject: Flexing with IncapRules
Did you know we added an AI BOT classification over one year ago? 🤔
It's true! You can read all about it in the release notes from December 1st, 2024.
Why am I mentioning this over one year later, you ask? Great question! We've taken it one step further
Leveraging this same category with incap rules, you can now configure Monetization for AI Traffic via TollBit Integration.
Ref: https://docs-cybersec.thalesgroup.com/bundle/cloud-application-security/page/release-notes/2025-12-07.htm
Transform how you manage and monetize AI bot and crawler traffic with our new TollBit integration. The Imperva-TollBit integration enables you to identify AI bots and seamlessly route them through Tollbit monetization paywall, ensuring AI agents pay for accessing your content according to your terms. Using TollBit, you gain full control over pricing, licensing policies, and detailed analytics on which AI agents accessed your content and the generated revenue.
How it works
The integration leverages Imperva's AI bot detection to identify AI agents, such as scrapers, crawlers, and LLM collectors, at the edge.
Using Imperva's open platform, you can flexibly shape traffic routes based on your needs. In this use case, you create a Cloud WAF rule that redirects identified AI traffic to TollBit's subdomains. Once routed, TollBit acts as a paywall that:
- Evaluates the AI agent
- Applies your licensing and pricing rules
- Collects payment for the access request
- Returns the requested content to the AI bot only after these steps are complete.
Imperva does not manage pricing, licensing policies, or payment flows.
Key benefits:
Revenue: Convert unauthorized scraping attempts into licensed, paid transactions.
Control: Set rules and pricing for which AI agents can access your content.
Visibility: Gain clear, AI-specific analytics on who is accessing your content and the resulting business impact.
Why the change:
To address the rapid growth of uncompensated AI scraping, this integration enables you to enforce access rules and pricing, turning content consumption by AI models into a licensed revenue stream.
Ready to get started?
To enable the Cloud WAF integration with TollBit for AI traffic monetization:
- Log in or create your own Tollbit account on the TollBit platform and set your monetization controls.
- Create custom rules in the Imperva Cloud WAF platform as instructed in the TollBit Guide.
------------------------------
Jaired Anderson
Imperva
https://www.imperva.com/
Original Message:
Sent: 06-21-2022 10:50
From: Jaired Anderson
Subject: Flexing with IncapRules
Are you ready to flex 💪 your brain? This thread will contain a list of IncapRules and be updated periodically.
Use Case: Retrieve content from a 3rd party or location while masking the Origin. When a client accesses www.example.com/PathHere the content will be retrieved from destination.example.org/PathHere
Your Site: www.example.com
3rd Party: destination.example.org
You must have the load balancing module to define data centers.
This can be accomplished using forward and rewrite rules.
Define destination.example.org as a Data Center and check the box to Support only forward rules.
Create a new Forward rule with the following filter criteria:
URL == "/PathHere"
Adjust the match criteria as desired. For example, the statement above is a strict match ( == ) on "/PathHere" and will not match "/PathHere/".
For the Rule Action, select Forward to Data Center and select the destination.example.org Data Center.
Give the rule a name and click Save.
Imperva Cloud will now Forward all requests for www.example.com/PathHere (client facing) to destination.example.org/PathHere. (backend) and retrieve the content. The clients address bar will display www.example.com/PathHere.
Please note however that a Rewrite rule is also typically required in conjunction with a Forward rule. This is because the Origin Data Center usually won't respond because the original Host header is sent. Additionally, the SSL handshake can fail with the Origin server if the Host names do not match.
Create a Rewrite matching the same path as the Forward rule.
URL == "/PathHere"
For the Rule Action, select Rewrite Header.
For the Header Name, enter Host
Leave the From empty and in the To enter destination.example.org
Enter a name for the rule and click Save.
Reply to this thread to share your IncapRules with the community! 👍
Helpful Links
IncapRule Syntax Guide
https://docs.imperva.com/bundle/cloud-application-security/page/rules/rule-syntax.htm
IncapRule Parameter List
https://docs.imperva.com/bundle/cloud-application-security/page/rules/rule-parameters.htm
Simplified Redirect Rules
https://docs.imperva.com/bundle/cloud-application-security/page/rules/simplified-redirect.htm
Scheduler Syntax
https://docs.imperva.com/bundle/cloud-application-security/page/rules/scheduler.htm
Variable$ Galore!
https://docs.imperva.com/bundle/cloud-application-security/page/rules/create-rule.htm
Custom Rate Rules
https://docs.imperva.com/bundle/cloud-application-security/page/rules/rates.htm
#CloudWAF(formerlyIncapsula)
⚠ WARNING: Please follow your organization's change control procedures, and always test rules before adding to production