How to recognise it
Every request sends this user agent:
AltpassBot/1.0 (+https://altpass.pages.dev/bot)
Requests come from Cloudflare’s network (our API runs on Cloudflare Workers), so the IP addresses are Cloudflare’s.
When it visits
- Single-page checks: one request for the page someone entered (plus
/robots.txt). - Site audits:
/robots.txt, the sitemaps listed there or at/sitemap.xml, then the audited pages — a few at a time, at most around five pages per request cycle, capped by the user’s plan (100 to 10,000 pages). - Alt-text generation: one request for the specific image a user asked us to describe.
It doesn’t run JavaScript, submit forms, log in, or follow rel="nofollow" links while crawling. Pages are limited to 3 MB and images to 5 MB, with a 10-second timeout.
robots.txt
AltpassBot checks robots.txt before fetching any page, for checks and audits alike. It obeys a group for AltpassBot if you have one, otherwise the * group, including Allow, Disallow, * wildcards and $ anchors. robots.txt is cached for up to 10 minutes.
To block AltpassBot everywhere:
User-agent: AltpassBot
Disallow: /
To block it from part of your site:
User-agent: AltpassBot
Disallow: /private/
If your * rules are strict but you want to audit your own site with Altpass, allow it explicitly:
User-agent: AltpassBot
Allow: /
Image requests made when a user asks for alt text on one specific image are user-initiated, like a browser loading the image, and aren’t crawled.
Questions or problems
If AltpassBot is causing you trouble, block it with robots.txt (above) — that takes effect within 10 minutes — and tell us through the contact on our terms page.