{"slug": "is-that-visitor-a-person-or-an-agent-crawlproof-now-lets-them-say-so", "title": "Is that visitor a person or an agent? CrawlProof now lets them say so", "summary": "CrawlProof's tracker now accepts a self-declared actor token that lets a visitor state whether a visit is a human or an AI agent, with agents able to name the human operator behind them. Each registered actor receives one or more cpa_ tokens sent via a Crawlproof-Actor header or a per-site crp_actor URL parameter, and declared agents are counted as bots in unique visitors while declared humans change nothing; the tracker remains cookieless. CrawlProof reported that a headless scraper on one of its sites appeared as 31,000 \"humans\" a day from Singapore before being caught by volume, and its own agent, riotcoder, was the first registered agent, with its first beacon arriving through a stock Chrome user agent and landing in bot:declared.", "body_md": "# Is that visitor a person or an agent? CrawlProof now lets them say so\n\nAn AI agent driving a real Chrome looks exactly like a person. Same TLS handshake, same headers, it runs your JavaScript and scrolls. User-agent checks catch the crawlers that announce themselves and nothing else. On one of our sites a headless scraper was showing up as 31,000 \"humans\" a day from Si\n\nAn AI agent driving a real Chrome looks exactly like a person. Same TLS handshake, same headers, it runs your JavaScript and scrolls. User-agent checks catch the crawlers that announce themselves and nothing else. On one of our sites a headless scraper was showing up as 31,000 \"humans\" a day from Singapore before we caught it by volume. Some agents are perfectly happy to say what they are, though. Mine is. So CrawlProof's tracker now accepts a declaration: this visit is a person, or this visit is an agent, and here is who. You register actors on your CrawlProof account: an email and a kind, human or agent. An agent can name the human who runs it. Each actor gets one or more cpa_ tokens, and the visitor sends the token with its visits: crawlproof actors add anthony@example.com --kind=human crawlproof actors add mybot@example.com --kind=agent --operator=anthony@example.com # an agent sets one header on every request (Playwright extraHTTPHeaders, Puppeteer) Crawlproof-Actor: cpa_... # a person opens each site once; the token is kept for that site and stripped from the URL https://example.com/?crp_actor=cpa_... The token is the credential. Typing someone's email claims nothing, and an address only shows as verified after a link sent to it is clicked (your own login address is verified on the spot). One verified claim per address, across every account. It is the honor system, so the rule is one-way. If a visit says it is an agent, we believe it and count it as a bot, including in unique visitors. Nobody gains anything by pretending to be a bot. If a visit says it is a human, we write that down and change nothing. When the user agent or our scripted-browser cap says bot, it stays a bot, and the actor gets a contradiction on its record. A token with contradictions piling up is a token being used by something it should not be. Names are private to whoever registered them. Other site owners see counts per kind, not who. The tracker stays cookieless. I started with a cookie so one click would declare you on every site, then remembered our docs say \"No cookies\", so it is a link per site instead. crawlproof stats prints a \"Declared (self-reported)\" block when anyone declared, kept apart from the measured numbers. There is also a settings page with a link per tracked site for declaring a browser, MCP tools (list_actors, add_actor, mint_actor_token) and the API under /api/tracker/v1/actors. My agent, riotcoder, is the first registered agent. Its first beacon came in through a stock Chrome user agent and landed in bot:declared, which is the point. Docs: https://crawlproof.com/docs/statistics#declared-actors\n\n## Key Takeaways\n\n- •An AI agent driving a real Chrome looks exactly like a person\n- •This story was reported by **Dev.to** , covering developments in the**dev** space.\n- •AI advancements continue to reshape industries — read the full article on Dev.to for complete coverage.\n\n📖 Continue reading the full article:\n\n[Read Full Article on Dev.to →](https://dev.to/chovy/is-that-visitor-a-person-or-an-agent-crawlproof-now-lets-them-say-so-1co1)", "url": "https://wpnews.pro/news/is-that-visitor-a-person-or-an-agent-crawlproof-now-lets-them-say-so", "canonical_source": "https://ainexusdaily.vercel.app/article/2026-10-04-is-that-visitor-a-person-or-an-agent-crawlproof-now-lets-them-say-so", "published_at": "2026-10-04 13:49:37+00:00", "updated_at": "2026-10-04 14:43:48.273731+00:00", "lang": "en", "topics": ["ai-crawlers", "ai-agents", "ai-tools"], "entities": ["CrawlProof", "riotcoder", "Playwright", "Puppeteer", "Dev.to"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/is-that-visitor-a-person-or-an-agent-crawlproof-now-lets-them-say-so", "markdown": "https://wpnews.pro/news/is-that-visitor-a-person-or-an-agent-crawlproof-now-lets-them-say-so.md", "text": "https://wpnews.pro/news/is-that-visitor-a-person-or-an-agent-crawlproof-now-lets-them-say-so.txt", "jsonld": "https://wpnews.pro/news/is-that-visitor-a-person-or-an-agent-crawlproof-now-lets-them-say-so.jsonld"}}