Skip to main content
Comparison

Botscope vs. Cloudflare: What Each Sees, and Where to Put It

A WAF decides whether a request is dangerous. Botscope decides who the client is and what it does with your content. Where each is better, what Botscope loses behind Cloudflare's proxy, and how to run both without losing it.

Botscope Team · 8 min read

Two different questions

"We already have Cloudflare" is the first thing almost every technical evaluator says, and it is a fair objection. The short answer is that a WAF and Botscope answer different questions about the same request.

A WAF asks is this request dangerous? — an injection, a flood, a known-bad signature. Botscope asks who is this client, and what is it doing with my content? That second question matters more every month, because a growing share of automated traffic is not hostile at all: it is GPTBot, ClaudeBot and PerplexityBot reading your pages so an AI assistant can answer someone's question with them.

Side by side

Stops volumetric abuse and L7 floods
WAF / CDN ✓ Yes Botscope ~ Partly
This is what a WAF is for, and it is better at it. Botscope blocks at the origin or the edge, per agent — it is not a DDoS layer and does not try to be.
Tells you which AI agents are on your site
WAF / CDN — No Botscope ✓ Yes
GPTBot, ClaudeBot, PerplexityBot, Google-Extended and 556 more, identified by catalogue and, where the operator publishes its ranges, verified by reverse DNS rather than by the user agent they claim.
Shows which AI answers cite your pages
WAF / CDN — No Botscope ✓ Yes
Which pages get fetched for an answer, and how many readers come back from it. A WAF has no concept of this.
A separate decision per agent
WAF / CDN ~ Partly Botscope ✓ Yes
Allow the search crawler, observe the AI trainer, challenge the scraper — one policy each, and a matching robots.txt generated from it. A WAF rule set is written per pattern, not per identity.
Bot traffic as analytics, not just as a log
WAF / CDN — No Botscope ✓ Yes
What automated clients read, how often, and what it costs you — in a dashboard rather than in a request log you have to query.
Runs in observe mode before it blocks anything
WAF / CDN ~ Partly Botscope ✓ Yes
Every new site starts in observe: it classifies and reports, and enforces nothing until you turn it on. Your first week carries no risk of blocking a customer.

What the WAF does better

Volumetric abuse. A CDN-level WAF sits in front of everything, absorbs L7 floods across a global network and drops them before they cost you a CPU cycle. Botscope is not a DDoS layer and does not try to be one: it makes a decision per client, at your origin or at the edge, and it assumes something in front of it is soaking up the floods. If that is all you need, the WAF is the right answer and you should keep only it.

What a WAF does not see

A WAF rule set is written per pattern, not per identity. It can block a user agent string, but it cannot tell you that the client claiming to be GPTBot really comes from OpenAI's published ranges, which of your pages it read this week, or whether readers came back from the answer that cited them.

That is the part Botscope is built for: a catalogue of AI agents verified by reverse DNS rather than by the name they claim, a separate policy for each one — allow the search crawler, observe the AI trainer, challenge the scraper — and a dashboard of what automated clients read and what it costs you, instead of a request log you have to query.

What Botscope loses behind the proxy

There is a catch, and it is better said here than discovered in week two. Only whoever terminates the TLS connection sees the client's TLS handshake — and with it the JA4 fingerprint, one of the strongest signals for telling a real browser from a script that borrowed its user agent. Behind Cloudflare's proxy, that is Cloudflare, not Botscope.

Behind the proxy, Botscope also cannot take the DNS route: your A record already points at Cloudflare, so it connects as a Worker inside your zone instead. What it then sees depends on your Cloudflare plan:

Botscope on the edge (DNS)
Full JA4 from the handshake
Every layer runs: JA4 session continuity, shared JA4 reputation, proof-of-work, behavioural traps.
Cloudflare Worker + Enterprise Bot Management
JA4 as Cloudflare reports it
Close to the full stack — Cloudflare passes its own JA4 through to the Worker.
Cloudflare Worker on Free, Pro or Business
A reduced TLS fingerprint
Enough to notice a client changing mid-session, not a real JA4. Session continuity and JA4 reputation are noticeably weaker.

Everything that does not depend on the handshake — agent identification by reverse DNS, per-agent policy, citation analytics, observe mode — works the same in every row.

Running both

If what you need from Botscope is AI-agent visibility and per-agent policy, the Worker inside your Cloudflare zone is a fine setup and needs no DNS change — the connection guide walks through it.

If you are buying it to stop sophisticated bots — headless browsers, residential-proxy scrapers, clients that rotate user agents — our honest recommendation is to put Botscope on the edge. Keep Cloudflare as your DNS provider, switch the record to DNS-only (the grey cloud), and point it at Botscope. You keep Cloudflare's DNS; Botscope sees every handshake and runs every layer. What you give up is Cloudflare's proxy in front of the site, so weigh that against how much volumetric protection you actually rely on.

Either way, every new site starts in observe mode. For the first week it reports and enforces nothing, so you see exactly what it would have done before it does anything.

FAQ

Does Botscope replace Cloudflare Bot Management?

For identifying and governing AI agents and crawlers, it covers that ground in more detail. For volumetric protection, no. And behind Cloudflare's proxy it sees less of the TLS layer than it does on the edge — see what it loses there.

Will it conflict with my existing WAF rules?

As a Worker, no: it sees only the requests your WAF lets through, and in observe mode it changes nothing about how they are served. On the edge, Cloudflare's proxy rules no longer apply to that hostname, because the record is DNS-only — that is the trade, not a conflict.

How do I know whether it adds anything for me?

Run it in observe mode for a week and look at the agent report — or book 30 minutes and we will tell you honestly whether your WAF already covers what you need.

See what your WAF was not telling you

Every new site starts in observe mode: Botscope classifies and reports, and blocks nothing until you turn it on.

Start free — connect in minutes