FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Akamai Bot Manager
A

Akamai Bot Manager

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential

Altcha

Altcha is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Altcha supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Altcha ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Akamai Bot Manager do?

Akamai Bot Manager is an enterprise bot management product running at the edge of the Akamai CDN. It classifies and mitigates bots through device fingerprinting, behaviour analysis and JavaScript challenges.

Akamai Bot Manager is a bot detection and mitigation product that runs on the Akamai Intelligent Platform, the world''s largest content delivery network. It analyses every request reaching your site, scores it against bot signatures and machine learning models, and applies the action you configured (allow, monitor, slow down, serve alternate content, challenge with a JavaScript test or a captcha, block).

What Akamai Bot Manager does

Bot Manager Premier injects a JavaScript sensor that fingerprints the device, captures behavioural signals (mouse movements, scrolling, typing cadence), and posts the proof of work back to the Akamai edge. The edge stores a bot score in a signed cookie so subsequent requests do not require revalidation. Akamai threat intelligence updates the rules continuously from the global Akamai network.

Cookies and data collected

The platform sets first party cookies on the protected domain (typically _abck for the score, bm_sz for the session, ak_bmsc for behaviour) and reads the IP, user agent, TLS fingerprint, the device sensor payload, and request headers. None of the cookies is used for marketing.

GDPR and ePrivacy implications

The bot scoring cookies can be considered strictly necessary for security under Article 5(3) ePrivacy, since they directly support the integrity of the service. The behavioural signals are personal data and rely on legitimate interest (Article 6(1)(f) GDPR) with a documented balancing test. Akamai is a processor under your DPA. Inform users in your privacy notice that bot management is used.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data hosting and transfers

Edge evaluation happens close to the visitor (including EU points of presence). Akamai Technologies is a US company and the central threat intelligence platform runs in the US. Transfers are covered by the EU-US Data Privacy Framework (Akamai is certified) and by Standard Contractual Clauses for non DPF flows.

How to deploy it compliantly

Treat Bot Manager as a strictly necessary security tool, enabled by default. Restrict the sensor to pages where bot risk justifies it (login, checkout, search), keep the cookies on the first party domain, and document the deployment in your record of processing activities. Provide an accessible alternative for users blocked by false positives.

GDPR consent category

Essential

Websites using Akamai Bot Manager must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Art. 6(1)(f) GDPR) for security, fraud and bot prevention, with documented balancing test; the bot scoring cookie can be considered strictly necessary
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, NIS2, EU-US Data Privacy Framework, EDPB Guidelines 5/2020 on consent

DPIA considerations

A DPIA is recommended when Bot Manager runs on consumer journeys (login, account creation, checkout) where false positives could exclude legitimate users. Document the signals captured by the sensor (device, behaviour), the retention by Akamai, the EU edge architecture, and the appeal path for users blocked by mistake.

Sample consent text

We use Akamai Bot Manager to protect this site against automated abuse, fraud and credential stuffing. It sets small bot scoring cookies and reads device signals on every request. These are strictly necessary for security and are active without prior consent.

Technical details

Tracking methodEdge protection on the Akamai CDN, JavaScript sensor that collects device and behaviour signals, first party cookies for bot scoring
Server locationAkamai Intelligent Platform edge with EU points of presence; centralised analytics in the United States
Data transferred outside the EUAkamai Technologies is a US company operating a global CDN. Bot Manager evaluates requests at the edge close to the visitor (including EU edge), but central analytics and the Threat Intelligence platform run in the United States. Transfers rely on the EU-US Data Privacy Framework (Akamai is certified) and on Standard Contractual Clauses.

Third-party domains contacted

akamaihd.netakamaized.netakamaiedge.netedge.akamai.com

Cookies placed

NameTypeDurationPurpose
_abckhttp_cookie1 yearStores the signed Akamai Bot Manager score and a sensor verification token used to identify legitimate browsers across requests.
bm_szhttp_cookie4 hoursAkamai session cookie issued at the edge to associate a visitor session with the bot scoring decisions.
ak_bmschttp_cookie2 hoursStores intermediate behavioural state and sensor results during a visit.
bm_svhttp_cookie1 hourSensor verification cookie used to confirm that the JavaScript sensor has been executed by a legitimate browser.

Akamai Bot Manager is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Akamai Bot Manager set?

Bot Manager typically sets _abck (bot score), bm_sz (session), ak_bmsc (behavioural state) and bm_sv (sensor verification) as first party cookies on the protected domain. Lifetimes range from session to one year. They are not used for marketing.

Does Akamai Bot Manager require GDPR consent?

Generally no. The cookies and the sensor are used to protect the integrity of the service and qualify as strictly necessary under Article 5(3) ePrivacy. Disclose Bot Manager in your privacy notice instead of asking for consent.

What is the legal basis for processing?

Legitimate interest under Article 6(1)(f) GDPR for fraud and bot prevention, with a documented balancing test. The strictly necessary cookies benefit from the exemption of Article 5(3) ePrivacy.

Are data transferred outside the EU?

Edge evaluation happens close to the visitor (including EU). Akamai Technologies is a US company and central analytics run in the United States. Transfers rely on the EU-US Data Privacy Framework and on SCCs for any non DPF flow.

Do I need a DPIA?

A DPIA is recommended for deployments on consumer flows where false positives could impact rights (login, account creation, payment). Document the signals, the impact on accessibility, the appeal mechanism, and the retention of bot scores.

How do I implement Akamai Bot Manager compliantly?

Enable Bot Manager on critical surfaces (login, password reset, search) rather than every page. Keep the cookies first party. Document the legitimate interest balancing test. Provide an alternative path for users blocked by mistake.

Are there alternatives to Akamai Bot Manager?

Alternatives include Cloudflare Bot Management, AWS WAF Bot Control, Datadome, PerimeterX (HUMAN), F5 Distributed Cloud Bot Defense, Imperva Advanced Bot Protection and Reblaze. Datadome and HUMAN can offer EU hosting.

How do I update my cookie policy for Akamai Bot Manager?

List _abck, bm_sz, ak_bmsc and bm_sv as strictly necessary security cookies, with their lifetime and the fact that Akamai operates the bot management. Mention the US transfer mechanism and link to Akamai's privacy notice.