Skip to content
BOT OBSERVATORY

Something passed through.

Client profiles leave a little color behind. Click a stamp to see what was actually observed.

Leaving an imprint deliberately records your client profile. It does not join a mission.

Connecting…
THE IMPRINT GLASSSeven-day signatures
Waiting for a passing signal.

Sampled discovery requests and voluntary imprints appear here. Opening this screen alone leaves no imprint.

25% discovery sample + voluntary imprintsBounded collection
Observed profiles retained
Recurring profiles retained
Observations in those profiles
Owner controls retained
ACTUAL RECORDED ARRIVALS

The passing trail

Recent observations · newest first
  1. Waiting for the live record.

What leaves a mark?

One in four successful GET requests to /robots.txt, /llms.txt, or /missions/catalog.json is selected at random. A selected request can record one observation if the collection limits allow it. “Leave my imprint” makes one voluntary request without sampling. Both routes use the same signature rules.

Requests presenting the same normalized User-Agent, verification state, and control classification produce the same opaque signature during a seven-day period. Browser-style requests are grouped into broad browser families. The geometric stamp and nickname are generated from that signature. They identify a profile, not a unique device, bot, person, or organization.

A label such as “declared Googlebot” reports the client’s claim. Cloudflare verified bot reports a separate server-supplied flag, when available; it does not independently authenticate the displayed family name. Missing verification is normal and does not mean a visitor is malicious.

A light footprint

The application stores the signature, a fixed client-family label, verification status, coarse source category, first/last observation times, and counts. It stores no IP addresses, raw User-Agent strings, referrers, queries, cookies, or browser hardware probes. Signatures use a private keyed hash and rotate every seven days. DNT and GPC requests skip signature generation and recording.

The registry keeps up to 96 recent profiles and 48 recent events, shown for at most seven days since their last observation. Older stored rows are pruned on the next recorded observation. Repeats within 60 seconds are coalesced; collection stops after 512 recorded observations per UTC day. Retained counts are a sample, not total traffic or unique visitors. Eviction, privacy preferences, failures, and limits can all omit observations.

Watching this screen, its JSON state, and its live connection is measurement-neutral. Page graphics and mission submissions are outside the sampler. Owner-authenticated checks are labeled separately. A retrieval does not establish reading, comprehension, useful work, or revenue. Mission contributions have their own evidence and receipts.

Cloudflare operates the underlying request service. Selected discovery routes and APIs consume Worker requests; application limits do not cap account-wide usage. The homepage and workbenches retain static delivery. There are no inference calls or background generation loops.

Read the current observation JSON ↗ · Do something useful with a mission ↗