For security

Know which bots are authentic — and which are pretending

The user-agent is self-asserted text, and a significant share of traffic claiming to be ChatGPT’s crawler is spoofed. Lume verifies which bots, crawlers, and agents are genuinely who they claim and surfaces everything it can’t. It doesn’t block. It makes your blocking correct: the verified identity your WAF rules should rest on, so you stop challenging real customers and the good crawlers you meant to let in.

Sound familiar?

What Lume does for you

Verified vs. spoofed, per request

Web Bot Auth signatures, forward-confirmed reverse DNS, and published IP ranges give a verdict on every request against 7 major operators, so a spoofed “Googlebot” from the wrong network is flagged. A pass proves who an agent is, not that it’s harmless; that’s what the behavior view is for.

Surface the unverifiable

Everything that can’t be proven authentic is labeled exactly that, so nothing hides as “probably fine.” You see what’s real, what’s spoofed, and what’s simply unverifiable.

The evidence layer under your stack

Lume tells you the truth about each request; your WAF, CDN, or app acts on it: allow, challenge, rate-limit, or charge. Base those rules on verified identity and you stop wrongly challenging the real users and good bots generic rules catch by mistake. It’s the identity layer, not another gate.

Ready for the agentic web

As AI agents act on behalf of users, know which requests are a person, a bot, or a user-delegated agent: the foundation for any allow / charge / block decision.

Fits your stack

Verify at the edge, from your logs, or in your own code with the Identification API.

Cloudflare WorkerCDN logsREST ingestIdentification APITypeScript SDK

Security FAQ

Do you block bad bots?

No, and that’s the point. Lume verifies and surfaces; your WAF or CDN acts on the verdict. It’s the accurate identity layer beneath your mitigation, so your rules stop wrongly challenging real users and good bots. It doesn’t compete to be the wall.

A verified agent can still misbehave, so what does a pass actually buy me?

Right. Verification proves identity: that a request genuinely is the operator it claims. It says nothing about behavior. That’s why the verdict comes with analytics on how each agent actually behaves: verification tells you who, the behavior view tells you what they did. You need both, and a green check is never a synonym for “safe.”

Can you catch stealth scrapers on residential IPs?

Lume proves which agents are authentic and flags everything unverifiable, but it isn’t a full anti-scraping or fingerprinting tool. Use it to know what’s real; use your WAF to mitigate the rest.

How do you verify without storing IPs?

The IP is used at ingest to run the check, then truncated to a network prefix (/24 or /48) before anything is persisted. No full client IP is ever stored.

Which operators can you verify?

The 7 with published keys or IP ranges: Google, Microsoft (Bing), OpenAI, Anthropic, Perplexity, Amazon, and Apple. Everything else is honestly labeled unverified, never marked authentic.

Know what’s real before you act.

Free plan, one ingest token. Verify the agents you trust; surface the ones you can’t.

Start for free →