ChatGPT User Agent: Strings, IPs, Allow, Block and Verify

The ChatGPT user agent is ChatGPT-User. Its full string is Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot, and it shows up when ChatGPT or a custom GPT opens a page because someone asked a question. It is not a crawler, so robots.txt may not apply to it: you allow or block it with firewall rules, and you confirm it is real by checking the source IP against OpenAI’s published list.
OpenAI runs three other agents with different jobs, and ChatGPT’s agent mode identifies itself a fourth way, with signed requests. This guide gives every string, the robots.txt and firewall rules for each, a tested script that separates real ChatGPT traffic from fakes, a troubleshooting table for “ChatGPT can’t open my site,” and how to find out whether those visits turn into customers.
The Full ChatGPT User Agent String
OpenAI publishes the strings on its crawler documentation page. ChatGPT-User, the one people usually mean:
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/botThe other three OpenAI agents, as documented (OpenAI notes the version numbers may change):
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbotMozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbotMozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-AdsBot/1.0; +https://openai.com/adsbotMatch on the product token, not the whole string: ChatGPT-User/, OAI-SearchBot/, GPTBot/, OAI-AdsBot/. OAI-SearchBot and GPTBot may also add a robots.txt; marker to the string when they fetch your robots.txt file, which helps if your logs omit paths. Lists of these strings on GitHub go stale, so copy from the official page when you write a rule.
ChatGPT-User vs GPTBot vs OAI-SearchBot
Each OpenAI agent has one job and its own control. Mixing them up is the most common mistake.
| Agent | What it does | Controlled by | IP list |
|---|---|---|---|
| ChatGPT-User | Visits a page when a ChatGPT or custom GPT user asks a question, or when a GPT Action calls an external app | Firewall or bot rules. OpenAI says robots.txt rules may not apply because a user started the request | openai.com/chatgpt-user.json |
| OAI-SearchBot | Crawls to show sites in ChatGPT search answers | robots.txt. Opted-out sites are not shown in search answers, though they can still appear as navigational links | openai.com/searchbot.json |
| GPTBot | Crawls content that may be used to train OpenAI’s foundation models | robots.txt | openai.com/gptbot.json |
| OAI-AdsBot | Checks landing pages submitted as ads on ChatGPT; not used for training | Only visits pages submitted as ads | openai.com/adsbot.json |
Three consequences that are easy to miss:
- Blocking ChatGPT-User does not remove you from ChatGPT search. OpenAI says ChatGPT-User is not used to decide whether content appears in search. OAI-SearchBot controls that.
- Blocking GPTBot does not stop ChatGPT from reading you. GPTBot is the training crawler. The ChatGPT user agent for training does not exist as a separate thing: if you searched for “ChatGPT user agent training,” the token you want is GPTBot.
- The settings are independent. You can allow OAI-SearchBot to appear in answers and disallow GPTBot to opt out of training. If both are allowed, OpenAI says it may reuse one crawl for both purposes.
What a ChatGPT-User Visit Actually Is
A ChatGPT-User request is ChatGPT reading your page on behalf of one person, usually while it writes an answer. OpenAI describes it as not used for crawling the web in an automatic fashion. In practice that means:
- It comes in short bursts tied to questions, not in a steady crawl of your sitemap.
- It often lands on a single deep page: a pricing page, a doc, a comparison.
- It is not a visitor. The person asking reads ChatGPT’s answer. They reach your site only if they click a link in that answer, and that click is a normal browser visit with a normal browser user agent.
- It is a fetch of your HTML. If your main text is only rendered by JavaScript after load, or hidden behind a cookie wall or login, ChatGPT may read an empty shell.
That last point matters for analytics too. A fetcher that does not run your tracking script never appears in GA4 or any other JavaScript analytics tool, so your server or CDN logs are the only record of ChatGPT-User. The human click that may follow shows up in analytics as a referral from chatgpt.com, often tagged with utm_source=chatgpt.com.
ChatGPT Agent Mode Is a Different Visitor
Most of the pages ranking for this query are about ChatGPT agent, the product. Agent mode gives ChatGPT its own browser so it can complete a task: open sites, click buttons, fill in forms, compare options. According to OpenAI’s ChatGPT agent help page, it asks the user before consequential actions, and the user can take over the browser, which is how logins usually happen: the person signs in themselves instead of handing ChatGPT a password. At the time of writing it is available on paid plans only.
For a site owner the key fact is how it identifies itself. Its browser traffic is not labeled by a ChatGPT-User token you can match. OpenAI’s allowlisting article says these requests are signed using HTTP Message Signatures (RFC 9421), also called Web Bot Auth. Each signed request carries three headers:
Signature-Agent, set to"https://chatgpt.com"Signature-Input, which lists the signed components and the key IDSignature, the signature itself
The public keys live at https://chatgpt.com/.well-known/http-message-signatures-directory. When we opened it on October 6, 2026, it held one Ed25519 key with signature_agent set to https://chatgpt.com.
How to verify or allow agent traffic
- Cloudflare: OpenAI says Cloudflare lists it as a signed agent in its bots directory with the tag
chatgpt-agent. Allow or block that agent in your bot settings. - Akamai and Vercel: OpenAI says both verify the signatures automatically, with no extra setup.
- Anything else: check that
Signature-Agentis exactly"https://chatgpt.com", fetch the key from the directory, and verifySignatureandSignature-Inputper RFC 9421. Do not trust the header alone. Anyone can send it; only the signature proves it.
Because the agent drives a full browser, it can load your scripts and submit your forms. Two practical effects. First, it may appear in analytics as an ordinary visit, and its form submissions are made for a real user, so a lead it submits is a real lead, but a sudden run of identical, oddly fast submissions deserves a look. Second, anything your page says gets read by a model acting with a user’s permissions, which is why OpenAI and security teams talk about prompt injection. Hidden instructions in your page are a bad idea for that reason alone.
Workspace agents, the shared team agents on business plans, run tasks across connected apps such as Google Drive, Slack and SharePoint. When they need the open web, treat them like any other ChatGPT traffic: check the tokens and signatures above rather than assuming a new string.
robots.txt Rules for OpenAI’s Agents
robots.txt governs the crawlers, OAI-SearchBot and GPTBot. A common setup that keeps you in ChatGPT search but out of training:
User-agent: *
Disallow: /admin/
Disallow: /cart/
# Appear in ChatGPT search answers
User-agent: OAI-SearchBot
Disallow: /admin/
Disallow: /cart/
Allow: /
# Do not use this site to train models
User-agent: GPTBot
Disallow: /Note that the OAI-SearchBot group repeats the /admin/ and /cart/ rules. A crawler obeys the group that names it and ignores the * group once one exists, so a named group with only Allow: / would open those paths. Our PerplexityBot guide walks through this trap in detail; it applies to every named bot.
A User-agent: ChatGPT-User group is legal and costs nothing, but OpenAI says robots.txt rules may not apply to user-initiated requests, so do not rely on it. OpenAI also says search changes take about 24 hours to register after you edit robots.txt.
How to Allow or Block ChatGPT-User
Enforcement happens at your firewall, CDN or server. The rule has two conditions, not one:
- The user agent contains
ChatGPT-User/. - The source IP is inside a prefix from
https://openai.com/chatgpt-user.json.
To allow, attach an allow or skip action to that pair so bot protection and rate limits do not challenge it. To block, use a block action on the user agent alone, since you want to stop anything that claims the name anyway. When we fetched the JSON files on October 6, 2026, chatgpt-user.json listed 230 IPv4 prefixes (dated September 25, 2026), searchbot.json 39 and gptbot.json 18. The lists change, so load them on a schedule instead of pasting them into a config once.
Some guides suggest middleware that skips consent, session or geo checks when it sees an AI user agent. If that check reads only the string, any scraper can send ChatGPT-User/1.0 and get the same bypass. Require the IP match, or your CDN’s verified-bot signal, before you relax anything.
Verify Real ChatGPT Traffic in Your Logs
A quick count of what ChatGPT-User requested and what your server answered, for the common combined log format:
grep "ChatGPT-User/" access.log | awk '{print $9, $7}' | sort | uniq -c | sort -rn | head -20That trusts the string. To separate OpenAI from impostors, check each IP against the published ranges. This Python 3 script uses only the standard library, downloads the three lists, counts hits by agent, verdict and status code, and lists the pages verified ChatGPT-User fetched successfully:
import ipaddress, json, re, sys, urllib.request
from collections import Counter
LISTS = {
"ChatGPT-User": "https://openai.com/chatgpt-user.json",
"OAI-SearchBot": "https://openai.com/searchbot.json",
"GPTBot": "https://openai.com/gptbot.json",
}
def load(url):
with urllib.request.urlopen(url) as r:
data = json.load(r)
return [ipaddress.ip_network(p.get("ipv4Prefix") or p.get("ipv6Prefix"))
for p in data["prefixes"]]
nets = {agent: load(url) for agent, url in LISTS.items()}
# combined log format: IP - - [time] "GET /path HTTP/1.1" status bytes "referer" "user-agent"
line_re = re.compile(r'^(\S+) .*?"\S+ (\S+) [^"]*" (\d{3}) .*"([^"]*)"$')
hits, pages = Counter(), Counter()
for line in open(sys.argv[1], errors="replace"):
m = line_re.match(line.strip())
if not m:
continue
ip, path, status, ua = m.groups()
for agent, ranges in nets.items():
if agent + "/" in ua:
real = any(ipaddress.ip_address(ip) in n for n in ranges)
hits[(agent, "verified" if real else "SPOOFED", status)] += 1
if real and agent == "ChatGPT-User" and status == "200":
pages[path] += 1
for (agent, verdict, status), n in sorted(hits.items()):
print(f"{agent:14} {verdict:9} {status} {n}")
print("\nTop pages fetched by verified ChatGPT-User:")
for path, n in pages.most_common(10):
print(f"{n:6} {path}")Run it with python3 check_openai.py /var/log/nginx/access.log. On a five-line test log (two good fetches of /pricing, one blocked fetch, one fake from an outside IP, one GPTBot hit) it printed:
ChatGPT-User SPOOFED 200 1
ChatGPT-User verified 200 2
ChatGPT-User verified 403 1
GPTBot verified 200 1
Top pages fetched by verified ChatGPT-User:
2 /pricing- Verified 200: ChatGPT can read those pages. The page list tells you which content people are asking ChatGPT about.
- Verified 403, 429 or 503: your own security is turning ChatGPT away, whatever robots.txt says.
- Spoofed: something borrows the name. Treat it like any unknown scraper.
- Nothing at all: check the CDN logs before concluding ChatGPT never visits. A CDN block happens before your origin server logs anything.
Signed agent-mode requests will not show up here, because they carry no ChatGPT token. Look for them in your CDN’s bot analytics.
Why ChatGPT Cannot Open Your Site
A frequent complaint: you paste your URL into ChatGPT and it says it cannot access the page, while the site loads fine for you. Test it the way ChatGPT sees it:
curl -s -o /dev/null -w "%{http_code} %{time_total}s\n" \
-A "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" \
https://example.com/pricingThis only tests user agent rules, since your request still comes from your IP. If it returns 200 quickly but ChatGPT still fails, the block is probably IP-based or a challenge page. Then work through this table:
| Symptom | Likely cause | Fix |
|---|---|---|
| curl with the ChatGPT-User string gets 403 | A rule or plugin blocks AI user agents by name | Find the rule in your WAF, server config or security plugin and add the verified allow rule above it |
| Verified ChatGPT-User hits get 403 or a challenge page in logs | Bot management, a managed "block AI" setting, or a CAPTCHA | Allow ChatGPT-User plus its IP list; headless fetchers cannot solve interactive challenges |
| Verified hits get 429 | Rate limiting groups many ChatGPT users behind a few OpenAI IPs | Raise the limit for the verified prefixes instead of blocking them |
| No ChatGPT-User requests in origin logs at all | Blocked upstream at the CDN, security group or geo rule | Check CDN security events and cloud firewall rules; OpenAI IPs may sit in regions you filter |
| Plain http:// URL times out, https:// works | Port 80 closed or not redirecting | Open port 80 with a 301 to https, or give ChatGPT the https URL |
| 200 in logs but ChatGPT summarizes the page wrongly | Main content loads with JavaScript, or a consent or session wall returns a stub | Serve the text in the initial HTML; let the first anonymous request see the content |
| Agent mode is blocked but ChatGPT-User works | Signed agent traffic is handled by a separate bot category | Allow the chatgpt-agent signed agent in your CDN, or verify the signature yourself |
Should You Allow ChatGPT-User?
| Your situation | Setup |
|---|---|
| Public pages you want cited and recommended | Allow ChatGPT-User and OAI-SearchBot (verified by IP); decide on GPTBot separately |
| You want ChatGPT answers but no training use | Allow ChatGPT-User and OAI-SearchBot; disallow GPTBot in robots.txt |
| Paid or member content | Keep it behind login; block ChatGPT-User on those paths at the firewall |
| Licensing forbids AI summaries | Block all three tokens at the firewall, plus the signed agent in your CDN |
| Server load is the only issue | Rate limit with 429 and a Retry-After header instead of blocking |
Blocking ChatGPT-User means ChatGPT cannot read your page live when a user asks about you, so its answer will rely on whatever else it knows. If you want to be the source it quotes, our guide on how to rank in ChatGPT covers what earns the mention once access is sorted.
From ChatGPT-User Hits to Revenue
A ChatGPT-User fetch tells you a page was read for an answer. It does not tell you whether anyone came, or bought. To judge whether ChatGPT matters for your business, put three numbers side by side for each landing page:
- Verified ChatGPT-User fetches of the page, from the script above.
- Sessions that landed on the page from chatgpt.com, from your analytics. Our AI traffic analytics guide shows how to isolate them in GA4. Visits from apps that pass no referrer fall into Direct, so this is a floor.
- Conversions on those sessions and what each is worth.
A software company checks September. Its pricing page had 900 verified ChatGPT-User fetches, 210 sessions from chatgpt.com and 7 trial signups. A trial is worth $150 to them (20% of trials convert to a $750 first-year plan, and 0.20 x $750 = $150). So ChatGPT sent 7 x $150 = $1,050 of value through that page, about $5 per ChatGPT session ($1,050 / 210).
Its API docs had 3,400 fetches, 60 sessions and no signups. ChatGPT reads the docs constantly and answers from them, so few people click through. The team keeps both pages open, adds a short signup prompt to the docs, and compares the docs’ ChatGPT sessions and signups next month.
The fetch count comes from logs; the sessions and value need conversion tracking by landing page and AI source, which our AI conversion tracking guide sets up. SEOConversion does this part with one cookieless script: it identifies ChatGPT visits from the referrer, records conversions on each landing page and turns them into value, and leaves visits without a referrer in Direct instead of guessing.
FAQ
What is the ChatGPT user agent string?
OpenAI documents it as Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot. The token to match is ChatGPT-User. It appears when ChatGPT or a custom GPT visits a page because a user asked something, and its source IPs are published at openai.com/chatgpt-user.json.
Can free users use ChatGPT agent?
Not at the time of writing. OpenAI’s help center lists agent mode for paid plans: Plus, Pro, Business, Enterprise and Edu. Free users can still trigger ChatGPT-User page visits when ChatGPT looks something up for them, which is a different thing from agent mode.
What is an agent in ChatGPT?
ChatGPT agent, or agent mode, lets ChatGPT carry out a multi-step task with its own browser and tools: it opens sites, clicks, fills in forms and asks for confirmation before consequential steps. Workspace agents are a separate team feature: shared, saved agents that run repeatable workflows across connected business apps.
Who are the big 4 AI agents?
There is no official list, so treat the phrase as informal. It usually refers to the assistants from OpenAI (ChatGPT), Google (Gemini), Anthropic (Claude) and Microsoft (Copilot). For a site owner the useful question is which of their fetchers appear in your logs, and each vendor documents its own tokens.
How much does ChatGPT agent cost?
Agent mode comes with paid ChatGPT plans rather than a separate price, with a usage allowance that depends on the plan. Workspace agents on business plans are billed through credits, with heavier runs using more. Prices and allowances change, so check OpenAI’s pricing page for current numbers.
How do I get access to ChatGPT agent?
On a paid plan, choose agent mode from the tools menu in the ChatGPT composer, or type /agent, then describe the task. Workspace agents, on business plans, are reached from Agents in the ChatGPT sidebar once a workspace admin has enabled them.
See what ChatGPT visits are worth, not just how often it reads you.
SEOConversion identifies ChatGPT and other AI assistant visits from the referrer and reports the conversions and value each landing page earns, with one cookieless script.
Start free