Skip to content
Klacos
Verified bots

Verified bots: useful bots get through once their identity is confirmed

Search engines, uptime monitors, link previews, payment providers: your site needs these bots. Klacos checks with their operator that they are who they claim to be, lets them through, and treats anyone borrowing their name as an impostor.

Illustration: a large checkpoint gantry between two buildings, over an access road.
The problem

A bot’s name proves nothing

Every bot states its name in its requests, and anyone can type “Googlebot” there. A scraper that introduces itself that way hopes to get in wherever the real one does. Blocking by name shuts out the real search engine along with the fake; allowing by name opens the door to anyone who borrows it.

Getting it wrong costs you either way. Block the real search engine and your pages drop out of search results. Refuse a payment webhook and an order never gets confirmed. Stop an uptime probe and someone gets paged for an outage that isn’t happening. Let a fake Googlebot through and a scraper walks in with a free pass. robots.txt doesn’t change any of that: it is a request to well-behaved bots, not a barrier.

What you should expect: that a bot is verified with its operator before it is believed, that an impostor is treated as one, and that useful bots get through without you maintaining a single list.

Illustration: a checkpoint gate whose doors open onto a bright corridor.
Our approach

Useful bots recognised, with no list to maintain

Verified at the source

A bot calling itself Googlebot has to come from Google: its name alone is never enough.

Impostors spotted

A client borrowing the name of a known bot is treated as an impostor.

Sorted by category

Search engines, monitoring, link previews, feeds, accessibility, payments, archiving.

A policy per category

Let through, observe, slow down or block, for each category and each site.

Out of your audience

A verified bot doesn’t inflate your visitor numbers.

Visible in the console

What each category requests, in requests and in visitors.

Nothing to copy

The lists operators publish are tracked for you.

A safety net

Blocking a search engine raises a warning before it applies.
How it works

From a claimed name to a verified bot

  1. It states its name

    The bot introduces itself as a search engine, an uptime monitor or the crawler of a well-known service.

  2. Klacos checks

    The check is made with the operator, using what the operator itself publishes about its bots. A client that does not come from them is treated as an impostor and gets none of the access granted to the real one.

  3. It joins its category

    Search engine, monitoring, link preview, payment provider: the policy for its category applies.

  4. You see what it did

    The console shows, category by category, what these bots requested.

A bot whose operator publishes nothing is neither believed nor condemned: it stays unknown, judged on its visit like any other visitor. Verified bots are part of protecting your site, alongside bot management, which judges everyone else.

Your decision

A policy for each category of bot

For each category, you choose to let through, observe, slow down or block, site by site. The suggested settings let through search engines, uptime monitors, link previews, feed readers, accessibility and translation tools, and corporate proxies, which have people behind them. Payment providers get through on the paths you declare.

AI crawlers are observed by default: it is an editorial choice, and AI crawler control leaves it to you. Blocking a search engine is still possible, with a warning, because it is nearly always a mistake.

Illustration: a glass office building surrounded by trees.
The result

Out of your audience, still in plain view

A verified bot doesn’t count towards your cookieless analytics: your visitors stay human. It stays visible in the Traffic view, which shows the share of humans, bots, verified bots and visitors not yet classified, and what each category requested.

So you can see what your uptime monitoring asks for, and how many pages search engines crawl each day.

Traffic screen in the console: requests, page views, active visitors and the share of bots for the day, then a chart of requests per hour.
Klacos console (French interface), demo data.
Questions

Questions about verified bots

Could Googlebot end up blocked?

No. It is verified, then it gets through. Blocking it would take an explicit choice on your part, flagged with a warning.

Do I need to keep a list of addresses up to date?

No. The lists operators publish change often, and they are tracked for you.

Is a fake Googlebot blocked?

It is treated as an impostor: it gets none of the access you gave the real search engine, and what happens next depends on its visit and your settings.

What about a bot nobody knows?

It is neither believed nor condemned. It stays unknown, judged on its visit like any other visitor.

Will my uptime monitor and my payment provider get through?

Yes, their categories get through by default. For a tool of your own, an entry in your access rules is enough.

Opening early 2027

See which bots crawl your site, and which ones lie about their name

Request early access: your site starts in observation, and the console separates verified bots from the ones borrowing a well-known name. Or tell us about the bots you see on your site.