Analytics for the agentic web

See all your traffic — humans, bots, and AI agents, told apart.

Your analytics can’t tell a human from a bot, so your numbers are noisy and half your traffic is invisible. Lume runs server-side to give you a clean human count, show every bot and AI agent your analytics misses, measure the humans AI is sending you, and prove which agents are genuinely who they claim to be.

lume · verify + classify + track incoming · mixed
sampled 12,482 humans, a count you can trust of 28,351 requests told apart

Every request identified server-side, measured and named, never blocked.

Built for a web going non-human  ·  every visitor: human, bot, or agent  ·  verified, not just self-declared  ·  no full IP stored
Product

Every visitor, told apart — humans, bots, and AI agents.

Traffic analytics, told apart

Every request sorted as human, bot, or AI agent, then the non-human half broken down by operator, type (17 categories), and page. Real-time, no sampling.

Cryptographic verification

Verified-vs-self-declared status per request via HTTP Message Signatures (Web Bot Auth / RFC 9421 Ed25519), forward-confirmed reverse DNS, and published IP ranges. Proof of who an agent is, not a green light that it’s harmless.

AI referral tracking

See which AI assistants (ChatGPT, Claude, Gemini, Perplexity and more) are sending real human visitors, often hidden in “Direct,” so you can double down on the surfaces that actually convert.

Segments

The segments in your traffic.

Standard analytics lumps them together or drops them entirely. Lume tells them apart, and shows you why each one matters.

Humans

Your clean, bot-free count: the denominator everything else is measured against.

AI-referred humans

A new channel of real visitors from AI answers, usually hidden inside “Direct.”

AI agents

Real intent acting for a person: worth understanding, not filtering out.

AI crawlers

Whether AI can actually reach and index your pages.

Search & utility bots

Expected traffic, but finally told apart from your humans.

Spoofers / unverified

The one segment to actually worry about: agents that can’t prove who they claim to be.

Verification

Verified, not just self-declared.

A user-agent string is just a claim, and anyone can copy it. Lume checks the agents that matter against signatures, DNS, and published IP ranges, so you stop trusting a spoofable label. A signature proves who an agent is, not that it’s well-behaved. The analytics show you how it actually acts.

Verified vs. self-declared. Know which is which.

Operator Agent type Verification method Status
Google Search crawler FCrDNS + published IP ranges Verified
Microsoft (Bing) Search crawler FCrDNS + published IP ranges Verified
OpenAI AI crawler / agent Web Bot Auth (RFC 9421 Ed25519) + IP ranges Verified
Anthropic AI crawler / agent Web Bot Auth (RFC 9421 Ed25519) + IP ranges Verified
Perplexity AI answer engine Published IP ranges Verified
Amazon Crawler FCrDNS + published IP ranges Verified
Apple Search crawler FCrDNS + published IP ranges Verified
Plus 36 operators and 56 agents cataloged across 10 of 17 agent types, verified where the operator supports it.
Use cases

What teams do with Lume

Audit AI crawlers on your content

See which AI crawlers (GPTBot, Google-Extended, ClaudeBot) are on your site, and decide what to allow with real data instead of guesswork.

Verify an agent before you trust it

Check whether a request is a genuine, signed agent (in your own code via the Identification API) before you honor, route, or log it.

Attribute AI referral traffic

Measure the humans ChatGPT, Perplexity, and other AI answers send you, even when the referrer is stripped and it lands in “Direct.”

How it works

From first event to full picture.

01

Install

One ingest token, one SDK call.

new Lume(token) .trackPageview(req, res)
02

Classify

Every request sorted as human, bot, or AI agent, across 17 agent types.

03

Verify

Signatures, FCrDNS, and IP ranges checked against 7 verified operators.

04

Dashboard

The human / bot / AI agent split of your traffic, live and unsampled.

Install paths: TypeScript SDKRESTCloudflare WorkerVercel middlewareWordPress pluginCDN logs

See all your traffic, cleanly told apart, in minutes.

Pricing

Start free. Scale when your traffic does.

Free

$0
  • 250k events/mo
  • 1 project
Start for free →

Starter

$29/mo or $290/yr, 2 months free
  • 5M events/mo
  • 3 projects
  • CSV export
  • Identification API
Start with Starter →

Scale

$599/mo or $5990/yr, 2 months free
  • 600M events/mo
  • 25 projects
Start with Scale →

Enterprise

Custom
  • Custom volume & terms
Talk to us →

Every paid plan includes overage billing past its allowance instead of a hard stop. See full rates on pricing.

Know your traffic. All of it.

Set up in minutes. One ingest token, one SDK call. Free plan, no card required.

Start for free →

Privacy-first by design: analytics that never stores a full IP, truncated to a network prefix before storage. US-hosted. Hashed tokens only.