AI crawlers on Cloudflare: allow or block GPTBot, ClaudeBot, PerplexityBot and 78 more

Cloudflare does not hold a site’s robots.txt; the origin does. But it can add to that file, and it can refuse a crawler before the origin is ever asked. The steps on Cloudflare, what trips people up there, and a page for each of 81 AI crawlers.

This response

You are ClaudeBot (Anthropic). Citable recognised you as an AI agent, so this is https://getcitable.in/crawlers/on/cloudflare with the UI removed — the content only. A browser asking for the same address gets the full designed page.

Where Cloudflare keeps the rule

Cloudflare does not hold a site’s robots.txt; the origin does. But it can add to that file, and it can refuse a crawler before the origin is ever asked.

The steps below are shown for GPTBot. Each crawler has its own page, with its own names in the rule.

Step by step

What to paste

A group that names a crawler replaces the * group for that crawler; it does not add to it. Paths the * group closes are open to a crawler with its own group unless they are repeated there.

A custom rule that blocks it (Security → WAF → Custom rules; action: Block):

(http.user_agent contains "GPTBot")

robots.txt at the origin, refusing GPTBot:

User-agent: GPTBot
Disallow: /

robots.txt at the origin, allowing GPTBot:

User-agent: GPTBot
Allow: /

What trips people up

The edge answers first. If Cloudflare blocks GPTBot, an Allow in robots.txt changes nothing: the crawler is refused before the origin is asked. A site that allows a crawler on paper and blocks it at the edge is a site that crawler never reads.

Asked, or actually refused?

Yes. A Block in AI Crawl Control or in a custom rule is answered by Cloudflare itself, and the request never reaches the origin.

Check it yourself

A 200 means the name is let through; a 403 means something in front of the page refuses it. This tests the name from your own address. A platform that checks a crawler’s address as well may treat the real GPTBot differently.

The request:

curl -I -A "GPTBot" https://your-site.example/

Every AI crawler, on Cloudflare

Checked against Cloudflare's own documentation on 1 October 2026

About Citable

Citable strips the UI from a website for AI agents and serves them only the content.

When an AI agent — ChatGPT, Claude, Perplexity or any of the 81 that Citable recognises — opens a page, Citable removes the theme, scripts, navigation and layout and serves only the content: the same facts, at the same URL, on the site's own domain. People and Google still get the full designed page.

How it works: https://getcitable.in/how-it-works · Summary for AI agents: https://getcitable.in/llms.txt


Source: https://getcitable.in/crawlers/on/cloudflare · Citable · Run the free audit · llms.txt · getcitable@gmail.com