ChatGPT-User: robots token, verification and how to allow or disallow it
ChatGPT-User is an AI crawler operated by OpenAI. Its robots.txt token is ChatGPT-User, and the vendor documentation we fetched on 2026-09-06 is the source for every statement on this page.
| Robots token | ChatGPT-User |
|---|---|
| Vendor | OpenAI |
| Purpose | user-initiated fetch |
| Documented verification | published IP ranges |
| Vendor documentation last verified | 2026-09-06 |
| Share of read domains disallowing it for / | 7.8% of 128 |
| Last verified |
Identity
| Robots token | ChatGPT-User |
|---|---|
| Matched as | chatgpt-user |
| Vendor | OpenAI |
| Purpose | user-initiated fetch |
| Documentation | https://platform.openai.com/docs/bots |
| Documented verification | published IP ranges: https://openai.com/chatgpt-user.json |
Fetches a page because a user or an agent asked for it. Vendor documents the full UA 'ChatGPT-User/1.0; +https://openai.com/bot' and states the content is not used to train foundation models.
Allow or disallow it
User-agent: ChatGPT-User Allow: /
User-agent: ChatGPT-User Disallow: /
A robots.txt rule is a request that a well behaved crawler honours. It is not an access control, and this page does not tell anyone what to choose.
Questions
Does ChatGPT-User obey robots.txt?
The vendor documentation at https://platform.openai.com/docs/bots states that ChatGPT-User respects robots.txt. We fetched that page and it answered our checker on 2026-09-06. This records what the vendor documents, not what any individual request did.
How do I allow ChatGPT-User in robots.txt?
Add this group to the robots.txt at the root of the host: User-agent: ChatGPT-User Allow: /. The token is matched case insensitively as a substring of the user agent by RFC 9309, and the longest matching rule wins.
How do I disallow ChatGPT-User in robots.txt?
Add this group to the robots.txt at the root of the host: User-agent: ChatGPT-User Disallow: /. A robots.txt rule is a request that a well behaved crawler honours; it is not an access control.
How do I verify a request really came from ChatGPT-User?
The vendor publishes the IP ranges this crawler fetches from at https://openai.com/chatgpt-user.json. Check the address of the request against that file. A user agent string on its own proves nothing, because anyone can send one.
What we measure
Of the 128 seeded domains whose robots.txt we have read, 10 disallow ChatGPT-User for / and 118 allow it, which is 7.8% disallowed, week 2026-W37. Counts only: no domain is named.
The weekly AI crawler access index
Sources
| Source | Type | HTTP | Verified | Note |
|---|---|---|---|---|
| https://platform.openai.com/docs/bots | vendor | 200 | 2026-09-06 | 7 occurrences of ChatGPT-User in the fetched body |
| https://openai.com/chatgpt-user.json | vendor | 200 | 2026-09-06 | published IP ranges |
Free data
Check a domain against every token
AEO Watch is an independent, factual monitor. It is not affiliated with, endorsed by or speaking for any crawler vendor. Every statement is an observation with the date it was made and the raw evidence behind it: a robots.txt line, an HTTP status code, a header. There are no scores, no grades and no verdicts here, and nothing on this page is advice. A site opts out at any time and the opt out is honoured automatically and permanently.