catalogue / tools / Feeds & site structure / Robots Check API

Robots Check API

Fetches robots.txt and answers whether a user agent may crawl a URL, showing the group, the winning rule and every rule that competed with it.

Endpoint
POST /v1/robots-check
Price
$0.002 per call
Family
Feeds & site structure

01When to use it

  • It needs the network, and the part an agent gets wrong on its own is precedence: RFC 9309 resolves conflicts by longest match, not first match. One fetch answers up to 50 paths.

When not to use it

  • The destination needs more than 8 s to answer: the call ends with upstream_timeout (424).
  • The destination is on a private or local network: the network guard refuses it with blocked_target (403).

02Parameters

FieldTypeRequiredDescription
urlstringyesAbsolute http(s) URL to check, up to 2048 characters; robots.txt is fetched from the root of its origin and the verdict is for its path and query.
user_agentstringnoCrawler product token or full User-Agent string, printable ASCII up to 200 characters; the text before the first slash or space picks the group, and the default is *. Default: "*".
include_sitemapsbooleannoWhether to return the Sitemap URLs listed in robots.txt; false returns null for sitemaps and its counters. Default: true.
additional_pathsarraynoUp to 50 more root-relative paths or absolute URLs on the same origin as url, each answered from the same robots.txt fetch in additional_results.

03Limits

LimitValue
Size cap500 KB (512,000 bytes)
Timeout8 s

04Example

The published example of robots-check, verbatim: the request body and the response it returns.

Request
POST /v1/robots-check
content-type: application/json
payment-signature: <base64 x402 payload>

{
  "url": "https://grist.tools/v1/whois",
  "user_agent": "GPTBot",
  "include_sitemaps": true,
  "additional_paths": [
    "/docs/whois",
    "/v1/whois/schema"
  ]
}
Response
200 OK
payment-response: <base64 settlement receipt>

{
  "url": "https://grist.tools/v1/whois",
  "source_url": "https://grist.tools/robots.txt",
  "robots_url": "https://grist.tools/robots.txt",
  "robots_status": "found",
  "robots_http_status": 200,
  "user_agent": "GPTBot",
  "user_agent_token": "GPTBot",
  "allowed": false,
  "decision_reason": "rule",
  "matched_rule": {
    "type": "disallow",
    "path": "/v1/",
    "line": 3,
    "octet_length": 4
  },
  "matched_group": {
    "user_agents": [
      "*"
    ],
    "is_wildcard": true,
    "line": 1
  },
  "competing_rules": [
    {
      "type": "disallow",
      "path": "/v1/",
      "line": 3,
      "octet_length": 4
    },
    {
      "type": "allow",
      "path": "/",
      "line": 2,
      "octet_length": 1
    }
  ],
  "competing_rules_total": 2,
  "competing_rules_truncated": false,
  "crawl_delay": null,
  "sitemaps": [
    "https://grist.tools/sitemap.xml"
  ],
  "sitemaps_total": 1,
  "sitemaps_truncated": false,
  "groups_found": 1,
  "rules_parsed": 3,
  "unparsed_lines": 0,
  "robots_size_bytes": 141,
  "robots_truncated": false,
  "additional_results": [
    {
      "path": "/docs/whois",
      "allowed": true,
      "decision_reason": "rule",
      "matched_rule": {
        "type": "allow",
        "path": "/",
        "line": 2,
        "octet_length": 1
      }
    },
    {
      "path": "/v1/whois/schema",
      "allowed": true,
      "decision_reason": "rule",
      "matched_rule": {
        "type": "allow",
        "path": "/v1/*/schema",
        "line": 4,
        "octet_length": 12
      }
    }
  ],
  "fetched_at": "2026-09-01T12:00:00.000Z",
  "checked_at": "2026-09-01T12:00:00.000Z"
}
Response fieldTypeIn the example
urlstring"https://grist.tools/v1/whois"
source_urlstring"https://grist.tools/robots.txt"
robots_urlstring"https://grist.tools/robots.txt"
robots_statusstring"found"
robots_http_statusnumber200
user_agentstring"GPTBot"
user_agent_tokenstring"GPTBot"
allowedbooleanfalse
decision_reasonstring"rule"
matched_ruleobjectan object with type, path, line and octet_length
matched_groupobjectan object with user_agents, is_wildcard and line
competing_rulesarray2 items, each with type, path, line and octet_length
competing_rules_totalnumber2
competing_rules_truncatedbooleanfalse
crawl_delaynullnull
sitemapsarray1 item
sitemaps_totalnumber1
sitemaps_truncatedbooleanfalse
groups_foundnumber1
rules_parsednumber3
unparsed_linesnumber0
robots_size_bytesnumber141
robots_truncatedbooleanfalse
additional_resultsarray2 items, each with path, allowed, decision_reason and matched_rule
fetched_atstring"2026-09-01T12:00:00.000Z"
checked_atstring"2026-09-01T12:00:00.000Z"

05Call it from code

JavaScript
// robots-check: $0.002 per call, paid in USD Coin on eip155:8453 via x402
// Install: npm install @x402/fetch@2 @x402/evm@2 viem@2
// Save as client.mjs (ES module, Node 18+), export EVM_PRIVATE_KEY with the paying wallet's key in your shell, then run: node client.mjs
// The wrapper reads the 402 (payment-required), signs and retries with payment-signature.
import { wrapFetchWithPayment, x402Client, decodePaymentResponseHeader } from '@x402/fetch'
import { ExactEvmScheme } from '@x402/evm/exact/client'
import { privateKeyToAccount } from 'viem/accounts'

const account = privateKeyToAccount(process.env.EVM_PRIVATE_KEY)
const client = new x402Client().register('eip155:8453', new ExactEvmScheme(account))
const fetchWithPayment = wrapFetchWithPayment(fetch, client)

const body = {
  "url": "https://grist.tools/v1/whois",
  "user_agent": "GPTBot",
  "include_sitemaps": true,
  "additional_paths": [
    "/docs/whois",
    "/v1/whois/schema"
  ]
}

const res = await fetchWithPayment('https://grist.tools/v1/robots-check', {
  method: 'POST',
  headers: { 'content-type': 'application/json' },
  body: JSON.stringify(body),
})
console.log(res.status, await res.json())
const settle = res.headers.get('payment-response')
if (settle) console.log(decodePaymentResponseHeader(settle).transaction)
Python
# robots-check: $0.002 per call, paid in USD Coin on eip155:8453 via x402
# Install: pip install "x402[requests,evm]>=2.24,<3"
# The session reads the 402 (payment-required), signs and retries with payment-signature.
import os
from eth_account import Account
from x402 import x402ClientSync
from x402.http import decode_payment_response_header
from x402.http.clients.requests import x402_requests
from x402.mechanisms.evm.exact import register_exact_evm_client
from x402.mechanisms.evm.signers import EthAccountSigner

account = Account.from_key(os.environ["EVM_PRIVATE_KEY"])
client = x402ClientSync()
register_exact_evm_client(client, EthAccountSigner(account), networks="eip155:8453")
session = x402_requests(client)

payload = {
    "url": "https://grist.tools/v1/whois",
    "user_agent": "GPTBot",
    "include_sitemaps": True,
    "additional_paths": [
        "/docs/whois",
        "/v1/whois/schema"
    ]
}

res = session.post("https://grist.tools/v1/robots-check", json=payload)
print(res.status_code, res.json())
settle = res.headers.get("payment-response")
if settle:
    print(decode_payment_response_header(settle).transaction)
curl
# robots-check: $0.002 per call, paid in USD Coin on eip155:8453 via x402
# 1. Unpaid call: HTTP 402, the requirements in the payment-required header (base64 JSON) and in the body.
curl -i -X POST 'https://grist.tools/v1/robots-check' -H 'content-type: application/json' -d '{"url":"https://grist.tools/v1/whois","user_agent":"GPTBot","include_sitemaps":true,"additional_paths":["/docs/whois","/v1/whois/schema"]}'

# 2. Same call with the signed payment (an EIP-3009 authorization, EIP-712 signed: it cannot be
#    typed by hand). x-payment is accepted as the v1 alternative. HTTP 200 carries payment-response.
curl -i -X POST 'https://grist.tools/v1/robots-check' -H 'content-type: application/json' -H 'payment-signature: <base64 x402 payload>' -d '{"url":"https://grist.tools/v1/whois","user_agent":"GPTBot","include_sitemaps":true,"additional_paths":["/docs/whois","/v1/whois/schema"]}'

06Errors

CodeHTTPFor this service
invalid_input400The body does not match the schema; its fields are url, user_agent, include_sitemaps and additional_paths.
blocked_target403
upstream_timeout424
internal500

Input that is rejected before the tool runs (malformed JSON, schema mismatch, body over the size limit) is never charged.

When each code is raised, and what it means for payment: /docs/robots-check.

07Questions

How much does a robots-check call cost?
$0.002 per call, paid in USDC on Base via x402, with no account and no API key.
What does robots-check return?
A JSON object with 26 top-level fields: url, source_url, robots_url, robots_status, robots_http_status, user_agent, user_agent_token, allowed, decision_reason, matched_rule, matched_group, competing_rules, competing_rules_total, competing_rules_truncated, crawl_delay, sitemaps, sitemaps_total, sitemaps_truncated, groups_found, rules_parsed, unparsed_lines, robots_size_bytes, robots_truncated, additional_results, fetched_at and checked_at. The example on this page is a real call.
What happens when a robots-check call fails?
The tool answers with a typed JSON error from the errors table. Payment is settled only after the tool has produced its result; a call that fails inside the tool is never settled. A 503 upstream_unavailable can follow a settled call; the x402 payments guide covers it, 429, 402 and an uncertain 500.