Fingerprint's Bot Directory: Name the AI Traffic Hitting Your Site
Fingerprint launched Bot Directory on September 18, 2026: a free, public, continuously updated list of the AI tools, bots, and crawlers its detection network can identify, each entry listed with its identity, provider, purpose, and a trust status. It is the first practical reference built for a question every marketing team should be asking this year: which of the bots in your traffic are buyers using AI, which are crawlers you want around, and which are junk automation polluting your reports?
Here is what shipped, why it matters more to marketers than it looks, and what to do with it this week.
What did Fingerprint launch?
Bot Directory is a searchable, filterable public repository powered by Fingerprint’s Bot Detection Smart Signal. Each entry names the bot, its provider, and its purpose, and assigns one of three trust statuses:
| Status | What it means | Examples |
|---|---|---|
| Signed | The agent cryptographically proves its identity via Web Bot Auth | ChatGPT Agent, Browserbase Agent, Manus Agent |
| Verified | Fingerprint has confirmed the operator behind the traffic | Googlebot, GPTBot, ClaudeBot, PerplexityBot |
| Unknown | No verifiable identity, including most scraping frameworks | Puppeteer Stealth, Undetected ChromeDriver, NoDriver |
Bot operators can test their own agents for Web Bot Auth compliance and submit them for inclusion. Fingerprint co-founder and CTO Valentin Vasilyev framed the launch plainly: “We are building for an internet that is increasingly composed of automated traffic.”
The company’s pitch is that bots now account for the majority of web traffic, and that legacy bot lists built before generative AI cannot tell a verified AI agent from malicious browser automation. That matches exactly what we see in the wild.
Why should demand gen teams care about a bot list?
Because your reporting is already full of automated traffic, and most teams still read it as human demand.
We have documented this twice on our own Search Console data. In August, a swarm of “reply io discount” query permutations racked up roughly 5,500 impressions at positions 4.6 to 8.4 with zero clicks, including misspellings carrying the same volume as the correct spelling. In the first week of September, a single machine-generated query, “tl;dv pricing plans 2026 per seat monthly,” logged 1,145 impressions and zero clicks against one page. No human types that. We broke the pattern down in what agent swarms are doing to marketing analytics.
Until now, the tooling to actually name that traffic lived inside enterprise bot-management products. A public directory moves the reference layer into the open, where a marketing ops person can use it without a security budget.
Get the next analysis first We publish first-day breakdowns of stories like this one. The free AI Readiness Scorecard also shows you where AI traffic, AI search, and AI agents touch your funnel today. Get the free scorecard |
Which AI bots should you allow on your site?
Do not block by reflex. The directory makes distinctions visible that most robots.txt files ignore:
| Bot type | Examples | Our call |
|---|---|---|
| AI search crawlers | OAI-SearchBot, Claude-SearchBot, PerplexityBot, Meta-WebIndexer | Allow. They feed the AI answers that cite and link you |
| User-triggered fetchers | ChatGPT-User, Claude-User, Perplexity-User | Allow. A real person asked their assistant to read your page |
| Training crawlers | GPTBot, ClaudeBot, CCBot, Bytespider | Your call, weighed against future model familiarity with your brand |
| Unverified automation | Puppeteer Stealth, Undetected ChromeDriver, NoDriver | Watch or block. This is where the junk lives |
One detail worth knowing: the directory entry for Meta-ExternalFetcher, which fetches links when a user asks Meta AI to complete a task, notes that it may bypass robots.txt rules. Robots.txt is a request, not a wall. Verified identity, not user-agent strings, is where bot governance is heading.
Blocking AI search crawlers is the expensive mistake. AI answers are a real discovery channel now, and those crawlers are how you show up in them. We covered the measurement side in our look at the new AI visibility data, and making your site legible to AI search is the exact job of our SEO and AEO page service.
What is Web Bot Auth?
Web Bot Auth is an emerging standard that lets a bot sign its requests with a cryptographic key, so your site can verify which operator an agent belongs to instead of trusting a user-agent string anyone can fake. The directory’s Signed tier shows who has adopted it already: OpenAI’s ChatGPT Agent, AWS Bedrock AgentCore, Cloudflare Browser Rendering, and agentic commerce players like HenryAgent and Nekuda Payment Executor. If your company ships its own agents, Fingerprint offers a compliance test and a submission path to get listed.
What should you do this week?
1. Stop reading impressions as demand. If a query cluster has big impressions, stable positions, and zero clicks, treat it as machine traffic until proven otherwise. Do not spend content or ad budget chasing it.
2. Audit robots.txt against the directory before blocking anything. Check what you currently block against the directory’s categories. Plenty of sites blocked AI search crawlers in 2024 and are invisible in AI answers now.
3. Separate automated traffic in reporting. Use the directory to build a named-bot segment in your analytics, so pipeline conversations start from human numbers. If you want a second set of eyes on how AI-era traffic hits your stack, our AI readiness audit covers exactly this, or just talk to an expert.
Frequently asked questions
What is Fingerprint’s Bot Directory?
A free public directory, launched September 18, 2026, of the AI tools, bots, and crawlers Fingerprint can detect. Each entry lists the bot’s identity, provider, purpose, and whether its identity is Signed, Verified, or Unknown.
Should I block AI crawlers from my website?
Not as a blanket rule. AI search crawlers and user-triggered fetchers drive citations and real readers. Training crawlers are a business decision. Unverified browser automation is the category to watch or block.
What is Web Bot Auth?
An emerging standard where a bot cryptographically signs its requests so websites can verify its operator. Bots in the directory that implement it carry the Signed status.
Do AI bots show up in Google Search Console?
Machine-generated queries can inflate impression counts in Search Console while contributing zero clicks. We have observed swarms of thousands of impressions on queries no human types, which is why clicks, not impressions, are the number to steer on.
Sources: Fingerprint Bot Directory and the September 18, 2026 launch announcement via Business Wire, both checked today.
Founder of Hacking Demand. 12+ years building B2B demand generation, including 330+ B2B and B2C webinars produced.
Keep building demand
Want us to build your demand engine?
Done-for-you webinars, AI agents, and pipeline plays, live in days.
Talk to an expertBrowse the hacks