Finding one · the shape of the traffic
What arrived
91
requests inspected since 29 August 2026
Every request that reaches a trap, the parlour or a station door is classified once, by the same detector, and counted. Nothing is sampled and nothing is excluded. 35 of them were machines presenting as something they were not — more than the number that gave a name.
-
16
Declared
Said what it was — a named crawler on the register, or a request signed under Web Bot Auth. 18% -
28
Undercover
Presented as an ordinary browser and was not one. This is the band the site exists to measure. 31% -
18
Tooling
Made no pretence: curl, a Go or Python HTTP client, a script. Honest by omission. 20% -
7
Irregular
Contradicted itself in ways that no ordinary client does, without matching a known agent. 8% -
22
Consistent with a person
Nothing out of place. Counted, and then set aside — this page is not about them. 24%
1 other site has a station installed, contributing 3 further requests as counts only. Those are reported separately at /api/network and are not folded into the figures on this page.
Finding two · who admitted to it
By name
The full tally, longest first. A named operator here means the request said so itself, in its own User-Agent or signature — not that we identified it against its will. There is no way to put a name to the undercover rows, which is the entire difficulty.
- 28 unidentified undercover
- 22 consistent-with-human browser
- 16 curl tooling
- 7 unidentified irregular
- 6 GPTBot OpenAI
- 3 ClaudeBot Anthropic
- 3 Claude-User Anthropic
- 2 Go net/http tooling
- 2 Meta-ExternalAgent Meta
- 1 https://chatgpt.com signed
- 1 https://ahrefs.com signed
Method
How each onewas decided
A request is read once, on arrival, from its own headers: what it claims to be, whether that claim is internally consistent, whether it carries a signature, and whether it behaves the way the client it names actually behaves. The bands above are the outcome of that single reading. Every token and every rule is published in the field manual, generated from the detector’s own table, so the classification can be checked rather than trusted. The live numbers are at /api/census.
No address is recorded, ever. No IP, no cookie, no identifier for any person. The census holds what each request volunteered about itself and nothing else, which is also why it can be published at all.
Limits
What thiscannot show
It is one address. 91 requests is a small number and they all arrived at a site about catching AI agents, which is not a neutral place to stand. Anything that crawls here may be unrepresentative of what crawls a shop or a newspaper.
It cannot name the undercover rows. A request presenting as Chrome may be a person using Chrome, a scraper, or an AI agent told to blend in. The band says the claim did not hold up. It does not say who made it, and this page will not guess.
There is no raw archive. Captures are deleted after seven days, as promised on the front page. Only the aggregate counts survive, so these figures cannot be re-derived from source and no per-request history can be produced — by us or by anyone asking us for it.
The comparison is young. Daily snapshots began on 11 September 2026. Until enough of them accumulate, this page reports a state, not a trend.