Allow or block LinkupBot on Next.js: app/robots.js and a proxy rule

Return a rule with userAgent “LinkupBot” and disallow “/” from app/robots.js, and for a refusal that is enforced, return a 403 from proxy.js (middleware.js before Next.js 16) when the user agent matches. Deploy for it to take effect.

This response

You are ClaudeBot (Anthropic). Citable recognised you as an AI agent, so this is https://getcitable.in/crawlers/linkupbot/nextjs with the UI removed — the content only. A browser asking for the same address gets the full designed page.

LinkupBot, and where Next.js keeps the rule

LinkupBot is a crawler run by Linkup. It reads pages ahead of time, to train a model or to build an index.

In the App Router, robots.txt is either a static file or the output of app/robots.js, a function that returns the rules.

Step by step

What to paste

A group that names a crawler replaces the * group for that crawler; it does not add to it. Paths the * group closes are open to a crawler with its own group unless they are repeated there.

app/robots.js, refusing LinkupBot:

export default function robots() {
  return {
    rules: [
      { userAgent: "LinkupBot", disallow: "/" },
      { userAgent: "*", allow: "/" },
    ],
  };
}

The same as a static robots.txt:

User-agent: LinkupBot
Disallow: /

proxy.js, refusing the request itself:

import { NextResponse } from "next/server";

const REFUSED = /LinkupBot/i;

// Next.js 16. Before it, the file is middleware.js and the function is middleware.
export function proxy(request) {
  if (REFUSED.test(request.headers.get("user-agent") || "")) {
    return new NextResponse("Forbidden", { status: 403 });
  }
  return NextResponse.next();
}

What trips people up

app/robots.js is run at build time and its output is cached. Editing it changes nothing on the live site until the next deploy. If the site is on Vercel, the Firewall sits in front of all of it.

Asked, or actually refused?

Yes: the proxy runs before the page is rendered, so a 403 from it is a refusal and not a request.

Check it yourself

A 200 means the name is let through; a 403 means something in front of the page refuses it. This tests the name from your own address. A platform that checks a crawler’s address as well may treat the real LinkupBot differently.

The request:

curl -I -A "LinkupBot" https://your-site.example/

Questions

How do I block LinkupBot on Next.js?

Return a rule with userAgent “LinkupBot” and disallow “/” from app/robots.js, and for a refusal that is enforced, return a 403 from proxy.js (middleware.js before Next.js 16) when the user agent matches. Deploy for it to take effect.

How do I allow LinkupBot on Next.js?

A crawler that robots.txt does not name follows the * group, so LinkupBot needs no rule to be allowed. To allow it by name, add the Allow block.

Can Next.js actually stop LinkupBot, or only ask it?

Yes: the proxy runs before the page is rendered, so a 403 from it is a refusal and not a request.

Does a rule for LinkupBot affect Googlebot or my Google rankings?

No. Googlebot goes by its own name and follows its own rules; a group or a firewall rule for LinkupBot does not apply to it.

Checked against Next.js's own documentation on 1 October 2026

Related

About Citable

Citable strips the UI from a website for AI agents and serves them only the content.

When an AI agent — ChatGPT, Claude, Perplexity or any of the 81 that Citable recognises — opens a page, Citable removes the theme, scripts, navigation and layout and serves only the content: the same facts, at the same URL, on the site's own domain. People and Google still get the full designed page.

How it works: https://getcitable.in/how-it-works · Summary for AI agents: https://getcitable.in/llms.txt


Source: https://getcitable.in/crawlers/linkupbot/nextjs · Citable · Run the free audit · llms.txt · getcitable@gmail.com