Two different questions
"We already have Cloudflare" is the first thing almost every technical evaluator says, and it is a fair objection. The short answer is that a WAF and Botscope answer different questions about the same request.
A WAF asks is this request dangerous? — an injection, a flood, a known-bad signature. Botscope asks who is this client, and what is it doing with my content? That second question matters more every month, because a growing share of automated traffic is not hostile at all: it is GPTBot, ClaudeBot and PerplexityBot reading your pages so an AI assistant can answer someone's question with them.
Side by side
What the WAF does better
Volumetric abuse. A CDN-level WAF sits in front of everything, absorbs L7 floods across a global network and drops them before they cost you a CPU cycle. Botscope is not a DDoS layer and does not try to be one: it makes a decision per client, at your origin or at the edge, and it assumes something in front of it is soaking up the floods. If that is all you need, the WAF is the right answer and you should keep only it.
What a WAF does not see
A WAF rule set is written per pattern, not per identity. It can block a user agent string, but it cannot tell you that the client claiming to be GPTBot really comes from OpenAI's published ranges, which of your pages it read this week, or whether readers came back from the answer that cited them.
That is the part Botscope is built for: a catalogue of AI agents verified by reverse DNS rather than by the name they claim, a separate policy for each one — allow the search crawler, observe the AI trainer, challenge the scraper — and a dashboard of what automated clients read and what it costs you, instead of a request log you have to query.
What Botscope loses behind the proxy
There is a catch, and it is better said here than discovered in week two. Only whoever terminates the TLS connection sees the client's TLS handshake — and with it the JA4 fingerprint, one of the strongest signals for telling a real browser from a script that borrowed its user agent. Behind Cloudflare's proxy, that is Cloudflare, not Botscope.
Behind the proxy, Botscope also cannot take the DNS route: your A record already points at Cloudflare, so it connects as a Worker inside your zone instead. What it then sees depends on your Cloudflare plan:
Everything that does not depend on the handshake — agent identification by reverse DNS, per-agent policy, citation analytics, observe mode — works the same in every row.
Running both
If what you need from Botscope is AI-agent visibility and per-agent policy, the Worker inside your Cloudflare zone is a fine setup and needs no DNS change — the connection guide walks through it.
If you are buying it to stop sophisticated bots — headless browsers, residential-proxy scrapers, clients that rotate user agents — our honest recommendation is to put Botscope on the edge. Keep Cloudflare as your DNS provider, switch the record to DNS-only (the grey cloud), and point it at Botscope. You keep Cloudflare's DNS; Botscope sees every handshake and runs every layer. What you give up is Cloudflare's proxy in front of the site, so weigh that against how much volumetric protection you actually rely on.
Either way, every new site starts in observe mode. For the first week it reports and enforces nothing, so you see exactly what it would have done before it does anything.
FAQ
Does Botscope replace Cloudflare Bot Management?
For identifying and governing AI agents and crawlers, it covers that ground in more detail. For volumetric protection, no. And behind Cloudflare's proxy it sees less of the TLS layer than it does on the edge — see what it loses there.
Will it conflict with my existing WAF rules?
As a Worker, no: it sees only the requests your WAF lets through, and in observe mode it changes nothing about how they are served. On the edge, Cloudflare's proxy rules no longer apply to that hostname, because the record is DNS-only — that is the trade, not a conflict.
How do I know whether it adds anything for me?
Run it in observe mode for a week and look at the agent report — or book 30 minutes and we will tell you honestly whether your WAF already covers what you need.