Omni Impact uses separate identities for site audits, the free AEO Readiness Check, WordPress publishing, and Agent Journeys. Identify the traffic you intend to allow before changing your site's rules.
Identify the request
Each workflow has a recognizable user-agent token. The main site crawler uses the same identity for HTTP fetches and its browser-rendering fallback.
| Workflow | Identity to recognize |
|---|---|
| Site crawl and browser fallback | OmniImpactBot/1.0 |
| Free AEO Readiness Check | OmniImpactAEOCheckBot/1.0 |
| Self-hosted WordPress connection and publishing | OmniImpactBot-Publisher/1.0 |
| Agent Journeys | OmniImpactJourneyBot/1.0; also sends an X-OmniImpact-Journey header. |
The full site-crawler user-agent is:
Mozilla/5.0 (compatible; OmniImpactBot/1.0; +https://omniimpact.net/bot)The free-check user-agent is:
Mozilla/5.0 (compatible; OmniImpactAEOCheckBot/1.0; +https://omniimpact.net/aeo-readiness-check)The publisher user-agent is:
OmniImpactBot-Publisher/1.0 (+https://omniimpact.net/bot)Journey requests append OmniImpactJourneyBot/1.0 (+https://omniimpact.net/bot) to their browser user-agent.
How robots.txt is applied
The site crawler reads /robots.txt and evaluates rules for the bare token OmniImpactBot. It checks the starting URL and URLs discovered from the sitemap. It does not apply a separate robots check to every link discovered in page content.
A disallowed starting URL stops that crawl. A disallowed sitemap URL is excluded from the queue. If robots.txt returns a non-200 response, cannot be fetched, or cannot be checked, the main site crawler allows crawling.
The free AEO Readiness Check evaluates OmniImpactAEOCheckBot before every page URL and redirect hop. Its identity is separate from the main crawler.
Set a crawl delay
The main site crawler honors a positive whole-number Crawl-delay, capped at 30 seconds, between page requests to the same origin. This applies to HTTP requests and browser fallback requests.
User-agent: OmniImpactBot
Allow: /
Crawl-delay: 5A matching OmniImpactBot group replaces the wildcard group. If that named group has no Crawl-delay, the crawler does not inherit a delay from User-agent: *. Zero, negative, fractional, and nonnumeric values are not used.
Verify crawler signatures
OmniImpactBot supports Web Bot Auth for page requests and browser navigations using Ed25519 HTTP Message Signatures. Requests for robots.txt, sitemaps, and llms.txt are unsigned.
The signature headers include Signature-Agent, Signature-Input, and Signature. A verifier obtains the public key directory from the origin in Signature-Agent, at /.well-known/http-message-signatures-directory. Signatures expire after 300 seconds.
Some page requests may be unsigned. A user-agent string alone does not authenticate a request; verify the signature when present and when your firewall supports it.
Resolve a firewall block
To resolve a block, match the failing workflow's identity and allow the required request path through your host or security plugin. The WordPress connection check reports REST blocks and bot challenges with an allowlisting action.
- Check your host's request or firewall logs for the bot identity and blocked URL.
- Add a rule for the relevant token, or ask your host to allow it. For WordPress publishing, include access to the WordPress REST API.
- Check that requests receive the real page or JSON response, rather than a CAPTCHA or challenge page.
- Retry the connection check or crawl from Omni Impact.
Cloudflare Verified Bot approval is pending. Your firewall may still need an allowlisting rule even when a request has a Web Bot Auth signature.
Opt out of a site crawl
To stop the main crawler at your starting URL, serve this group in a reachable robots.txt that returns HTTP 200. Add the separate free-check group if you also want to disallow the AEO Readiness Check.
User-agent: OmniImpactBot
Disallow: /
User-agent: OmniImpactAEOCheckBot
Disallow: /For unexpected requests or an allowlisting problem, contact support with the bot token, affected URL, time, and response status. Keep credentials and private page content out of the message.