Allow or block Cloudflare-AutoRAG on Nginx: robots.txt and a map on the user agent

Add a “User-agent: Cloudflare-AutoRAG” group with “Disallow: /” to robots.txt, and to enforce it, map $http_user_agent to a flag for Cloudflare-AutoRAG and return 403 when it is set.

This response

You are ClaudeBot (Anthropic). Citable recognised you as an AI agent, so this is https://getcitable.in/crawlers/cloudflare-autorag/nginx with the UI removed — the content only. A browser asking for the same address gets the full designed page.

Cloudflare-AutoRAG, and where Nginx keeps the rule

Cloudflare-AutoRAG is a crawler run by Cloudflare. It reads pages ahead of time, to train a model or to build an index.

Nginx serves robots.txt as a file from the site’s root, like any other file. The server itself can also refuse a request by its user agent.

Step by step

What to paste

A group that names a crawler replaces the * group for that crawler; it does not add to it. Paths the * group closes are open to a crawler with its own group unless they are repeated there.

robots.txt, refusing Cloudflare-AutoRAG:

User-agent: Cloudflare-AutoRAG
Disallow: /

nginx.conf, refusing the request itself:

# http {}
map $http_user_agent $refuse_crawler {
    default 0;
    "~*Cloudflare-AutoRAG" 1;
}

# server {}
if ($refuse_crawler) {
    return 403;
}

robots.txt, allowing Cloudflare-AutoRAG:

User-agent: Cloudflare-AutoRAG
Allow: /

What trips people up

The map belongs in the http block, not inside server; in the wrong place nginx -t fails and a reload would too. The 403 also covers /robots.txt itself, so the refused crawler cannot read the file either.

Asked, or actually refused?

Yes. The 403 is the server’s own answer.

Check it yourself

A 200 means the name is let through; a 403 means something in front of the page refuses it. This tests the name from your own address. A platform that checks a crawler’s address as well may treat the real Cloudflare-AutoRAG differently.

The request:

curl -I -A "Cloudflare-AutoRAG" https://your-site.example/

Questions

How do I block Cloudflare-AutoRAG on Nginx?

Add a “User-agent: Cloudflare-AutoRAG” group with “Disallow: /” to robots.txt, and to enforce it, map $http_user_agent to a flag for Cloudflare-AutoRAG and return 403 when it is set.

How do I allow Cloudflare-AutoRAG on Nginx?

A crawler that robots.txt does not name follows the * group, so Cloudflare-AutoRAG needs no rule to be allowed. To allow it by name, add the Allow block.

Can Nginx actually stop Cloudflare-AutoRAG, or only ask it?

Yes. The 403 is the server’s own answer.

Does a rule for Cloudflare-AutoRAG affect Googlebot or my Google rankings?

No. Googlebot goes by its own name and follows its own rules; a group or a firewall rule for Cloudflare-AutoRAG does not apply to it.

Checked against Nginx's own documentation on 1 October 2026

Related

About Citable

Citable strips the UI from a website for AI agents and serves them only the content.

When an AI agent — ChatGPT, Claude, Perplexity or any of the 81 that Citable recognises — opens a page, Citable removes the theme, scripts, navigation and layout and serves only the content: the same facts, at the same URL, on the site's own domain. People and Google still get the full designed page.

How it works: https://getcitable.in/how-it-works · Summary for AI agents: https://getcitable.in/llms.txt


Source: https://getcitable.in/crawlers/cloudflare-autorag/nginx · Citable · Run the free audit · llms.txt · getcitable@gmail.com