Security · Bot Management
Your bot score, live from the edge
Bot Management already scores every request to this zone with a machine-learning model. See the score attached to your own browser session, probe an endpoint that blocks low scores, and compare with what curl or Python gets from a terminal.
How Cloudflare scores and stops bots
Two slides, then your own live bot score — and a gated path that blocks automation.
Bot Management
Every request gets a score from 1 to 99
Bot Management analyzes TLS and HTTP fingerprints, behavioral signals, and IP intelligence with a machine-learning model trained across Cloudflare's network. The result is attached to the request: low scores mean automation, high scores mean human.
Signals
TLS · HTTP/2 · headers · behavior
ML model
Trained on global traffic
Score
1 = bot, 99 = human
Live scoring
Score, gate, and contrast
Nothing here is simulated: the score comes from cf.botManagement on the request you just made, and the gated endpoint is protected by a real custom rule on this zone.
Your live bot score
Computed by Bot Management on this very request — nothing is simulated.
Probe the gated endpoint
A scoped custom rule blocks low bot scores on /api/bot-score-gated. Your browser should pass — an automated client usually won't.
http.request.uri.path eq "/api/bot-score-gated" and cf.bot_management.score lt 30 and not cf.bot_management.verified_bot → blockContrast: score yourself from a terminal
The same endpoints, called by curl or Python — no browser fingerprint, no cookies, a machine TLS stack. Compare the score (and the gated endpoint's answer) with what your browser just got.
Score yourself from a terminal (curl)
curl -s https://app.orangemoussa.net/api/bot-scoreHit the gated endpoint (blocked when score < 30)
curl -s -o /dev/null -w "%{http_code}\n" https://app.orangemoussa.net/api/bot-score-gatedPython (requests)
python3 -c "import requests,json;print(json.dumps(requests.get('https://app.orangemoussa.net/api/bot-score').json(),indent=2))"