● early access
$ ban --by=fingerprint --not=ip

Ban the bot.
Not the IP.

Stop paying to serve scrapers, scanners and fake crawlers, without blocking the real users who share their IPs. BannedRobots fingerprints every request at the Cloudflare edge, learns which clients are abusing your site, and blocks those exact clients before they reach your origin. Ban a bot on one of your domains and it's blocked on all of them within about a minute.

0
IP bans
1
ban list for all your domains
≈1 min
to block everywhere
auto
learns from your traffic
~/edge $ tail -f requests.logsimulated
verdictsigclient
  1. PASS3a9f…71c2chrome/129 AS7922
  2. BAN4aa2…90b1python-requests/2.32 AS14061 [tooling_ua]
  3. PASS5aa5…afa0safari/17.6 AS3320
  4. PASS6aa8…ce8fgooglebot/2.1 AS15169 [verified_bot]
  5. BAN7aab…ed7echrome/124 AS16509 [headless_scraper]
  6. PASS8aae…0c6dfirefox/130 AS21928
  7. BAN9ab1…2b5cgooglebot/2.1 AS24940 [spoofed_crawler]
  8. PASSaab4…4a4bchrome/129 AS7018
  9. BANbab7…693azgrab/0.x AS63949 [exploit_probe]
  10. PASScaba…8829edge/129 AS2856
PASS → originBAN → 403 + request id
ERR_COLLATERAL
IP bans hit the wrong people

Behind CGNAT, a corporate proxy or a mobile carrier, thousands of real users share one address. Block the IP and you block all of them.

ERR_SPOOFABLE
User-agent rules are easy to beat

Any scraper can claim to be Chrome or Googlebot. The UA header is one line the client writes itself.

ERR_ORIGIN_COST
Your origin pays for every bot

Every scraper request you serve costs CPU, database queries and egress. Blocking at the edge avoids that cost.

01 / what you get

Less bot traffic. No collateral damage.

What changes once BannedRobots sits in front of your site.

A smaller origin bill

Scrapers never reach your servers, so you stop paying egress, CPU and database time to serve them. Your cache stops filling up with pages only crawlers ask for.

✓ ban → 403 at edge · origin: 0 requests

Your content stays yours

Prices, listings and articles stop being copied. Bans follow the scraper's fingerprint, so switching to a new proxy doesn't get it back in.

✓ fingerprint match → blocked on any IP

Fewer attacks reach your app

Scanners probing for /.env and /wp-login.php are identified by behavior and stopped at the edge. Once banned, their probes stop reaching your application.

✓ probe pattern → BAN

Real users never notice

Bans target one client fingerprint, not an IP or a network. Customers on the same mobile carrier, VPN or office proxy keep browsing normally.

✓ 1 client banned · 0 neighbors affected

Search rankings stay safe

Verified Googlebot, Bingbot and other good crawlers are exempt before any rule runs. Impostors using their user agent are blocked.

✓ verified_bot → ALLOW

Nothing to maintain

No IP lists to curate, no regexes to tune. It learns from your own traffic, and bans are removed once a bot stops showing up.

✓ new traffic → re-cluster → update bans
● one ban list for all your sites

Ban it once.
Blocked on every domain.

Bots don't stop at one site. When a scraper gets banned on your shop, it usually moves on to your API, your blog or your docs next. With BannedRobots, all your domains share one ban list, so a bot banned on any of them is blocked on all of them within about a minute.

  • ✓No per-site rules to copy around
  • ✓A bot caught on your busiest site is already blocked on your quietest
  • ✓New domains are covered by your existing bans from day one
ban_propagation.logexample
t+0s shop.example.com BAN headless scraper
└─ shared with every domain on your account
├─ api.example.com blocked ✓
├─ blog.example.com blocked ✓
├─ docs.example.com blocked ✓
└─ status.example.com blocked ✓
every domain covered≈ 1 min
02 / how it works

Observe. Cluster. Enforce.

It learns from your own traffic, not a generic rule set. Bans are applied in a Worker, next to your users.

  1. [01] observe
    request → fingerprint

    Fingerprint every request

    At the edge, each request is described by signals a client can't easily fake: how its TLS handshake is built, how it speaks HTTP and the network it comes from. It doesn't slow the request down.

  2. [02] cluster
    cluster → score

    Group clients by behavior

    Clients that behave alike are grouped together, so a botnet is judged as one. Each group is scored on what it requests, how it browses and whether it is who it claims to be.

  3. [03] enforce
    match → 403

    Block those clients at the edge

    Only fingerprints actually seen in banned groups are blocked. A matching request gets a 403 at the Cloudflare edge and never reaches your origin.

03 / fingerprints

Precise enough to ban one client.

Every request carries a fingerprint: how its TLS handshake is built, how it speaks HTTP and where it connects from. A scraper can copy Chrome's user agent, but not everything else. Two clients on the same IP look different, so the scraper is blocked and the person next to it gets through.

same_ip.logexample
ip 100.64.12.7 // shared: mobile carrier nat
├─ client A says "chrome" · handshake matches claim → PASS
├─ client B says "chrome" · handshake ≠ claim → BAN
└─ client C says "safari" · handshake matches claim → PASS
an IP ban here blocks 3 clients · a fingerprint ban blocks 1
block bystops botspares users
ip address~ until it rotates✕ shared IPs
asn / country✓✕ whole networks
user-agent rule✕ spoofed✓ mostly
fingerprint✓✓
04 / detection

What gets banned, and why.

Every ban records the reason it happened, so you can audit any block and reverse it if needed.

  • vulnerability scannersBANClients probing for admin panels, config files and known exploits.
  • headless scrapersBANAutomated page fetching with no real browser behind it.
  • spoofed crawlersBANClients claiming to be Googlebot or another search engine, and failing verification.
  • scripted toolingBANHTTP libraries and scripts that make no attempt to look like a browser.
  • high-risk behaviorBANGroups whose combined signals add up to clear automation, even without one smoking gun.
  • verified botsALLOWSearch engines, social previews and monitoring services verified by Cloudflare. Always let through.
05 / safety

Safe to put in front of your site.

A bot filter that takes your site down is worse than having no filter.

availability = your site first

Never the reason you are down

BannedRobots is built so that a problem on our side never turns into an outage on yours. Your site keeps serving visitors, whatever happens to us.

latency = edge-local

No slowdown for real users

Checks run in the Cloudflare location nearest each visitor, and reporting happens after the response is sent.

headers_out = allowlist

Sensitive headers stay put

Only the request metadata needed for detection is analyzed. Cookies and Authorization headers never leave your edge.

on_ban = 403 + request_id

Every block is traceable

Every ban is logged with its reason. Look up the request ID, see why it was blocked, and reverse it if needed.

06 / faq

Questions.

The short answers. Ask us anything else when you request access.

Q.Do I need to be on Cloudflare?+

Yes. BannedRobots runs as a Cloudflare Worker and uses the TLS and network metadata Cloudflare attaches to each request. Your origin can be hosted anywhere.

Q.Will it block Google or other good bots?+

No. Crawlers verified by Cloudflare are exempt before any rule runs. Bots that only claim to be Googlebot are a different case: failing verification is one of the ban signals.

Q.I run several sites. Do I ban a bot on each one?+

No. All your domains share one ban list. When a bot is banned on one of them, it's blocked on every other domain within about a minute, before it can move on to your next site.

Q.What if a real user gets blocked?+

They see a 403 with a request ID. Look up that ID to find the signature and ban reason, then remove the signature from the ban list. Because bans are per fingerprint, removing one affects nobody else.

Q.Does it add latency?+

Not noticeably. The check runs in the Cloudflare location nearest the visitor, and logging happens after the response is sent. Blocked requests never reach your origin, so your origin has less work to do.

Q.What data leaves my edge?+

Request metadata used for detection: method, host, path, IP, Cloudflare network and TLS fields, and an allowlist of non-sensitive headers. Cookies and Authorization headers are never sent.

07 / blog

Read the engineering notes.

How fingerprinting, bot detection and edge enforcement work, in depth. All articles →

early_access● waitlist open

Stop serving scrapers.

We're onboarding a small number of Cloudflare sites during early access. Join the waitlist and we'll email you when there's a spot.

// no spam. one email when we launch.