close

Choose Your Shared Hosting Plan

Choose Your Reseller Hosting Plan

Choose Your VPS Hosting Plan

Choose Your Dedicated Hosting Plan

Cloudflare expands BotBase with an operator-facing workflow to reduce bot

Cloudflare expands BotBase with an operator-facing workflow to reduce bot

Cloudflare expands BotBase with an operator-facing workflow to reduce bot

Cloudflare enhances BotBase with a new workflow for bot operators, streamlining submissions and improving bot classification for better website security.

Cloudflare is tightening the feedback loop between bot operators and the websites that decide whether to trust automated traffic. With a new operator-focused experience inside BotBase, bot providers can submit for inclusion, track review status, correct rejected entries, and keep their bot identity and behavior descriptions current—without relying on manual support tickets.

For operators, that means less uncertainty after submission. For website owners and security teams, the aim is more accurate bot classification, faster verification, and fewer mismatches that can lead to unnecessary blocks or overly permissive access. The move reflects a broader infrastructure reality: bot ecosystems are now large enough that transparency and automation are as important as detection.

Key developments: from one-way submission to an auditable operator workflow

  • Operator portal for BotBase: The bot submission entry point has been relocated into Protect & Connect → Application Security → BotBase, aligning BotBase with other bot and trust tools in the Cloudflare dashboard.
  • Submission history with explicit statuses: Operators can now see whether a submission is Waiting for review, Accepted, or Rejected. Rejections include reasons and actionable steps rather than leaving operators guessing.
  • Editing and cancellation: Bot identity details can be updated after initial submission—useful for changes like IP list endpoints, verification methods, or how content access is declared. Operators can also cancel submissions that are still pending review.
  • New intake taxonomy reflecting real bot behavior: Submissions are structured around what the bot does, how it uses content, and who operates the infrastructure. This is designed to replace overly coarse, single-label categorization with a more accurate behavioral model.
  • Faster, more consistent review via automated checks: Instead of relying solely on manual verification, the system performs validations such as duplicate detection, user-agent specificity to avoid overlap, and verification-method checks (e.g., IP list and reverse DNS, or Web Bot Auth signature verification).

Technical analysis: how automated identity and behavior checks improve trust decisions

BotBase sits at the intersection of application security controls, edge traffic classification, and—critically—bot identity verification. The operator-facing workflow is not just a UI improvement; it changes how reliable bot metadata becomes over time and how quickly that metadata can influence enforcement.

1) Verification moves from manual review to deterministic validation

The article describes a reconstructed review path where submissions are validated automatically against specific criteria. In practice, that usually means fewer

Frequently Asked Questions

What exactly is the new operator-facing workflow inside BotBase, and how does it reduce back-and-forth?

Cloudflare added an operator portal in BotBase where bot providers can submit their bot identity and behavior details, track the review status, and see whether an entry is waiting, accepted, or rejected. If rejected, they get reasons and actionable steps to correct it. This avoids relying on manual support tickets and gives operators clearer expectations.

Where do operators submit bots in the Cloudflare dashboard now?

The submission entry point moved into the Cloudflare dashboard under Protect & Connect → Application Security → BotBase. The goal is alignment with other bot and trust tools in the same area, so operators don’t need to hunt for a separate workflow. This also makes BotBase easier to manage alongside related security controls.

What do the new submission statuses mean, especially when a bot is rejected?

Operators can now view explicit statuses: Waiting for review, Accepted, or Rejected. Rejections include reasons and specific steps to address the problem, rather than leaving providers to guess. This is designed to speed up the path from submission to accurate bot classification, reducing delays caused by unclear feedback.

Can operators update bot identity details after submission, and what types of changes are supported?

Yes. Operators can edit bot identity details after the initial submission, which is useful when endpoints change (for example, IP list endpoints), when verification methods are updated, or when bot content access is declared differently. The key benefit is keeping bot metadata current so website enforcement doesn’t rely on outdated behavior descriptions.

How do automated checks (like duplicate detection and verification-method checks) improve trust decisions?

Instead of relying only on manual verification, BotBase runs validations to confirm the submitted identity and behavior match expected patterns. Typical checks include duplicate detection, bot user-agent specificity to reduce overlap with other bots, and verification-method checks such as IP list and reverse DNS validation or Web Bot Auth signature verification. This makes bot classification more consistent and faster.

Post Your Comment

INS-CO
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.