← 回到 Reading
ByteByteGo 2026-08-11

How Cloudflare Is Making AI Pay for Content

Historically, websites monetized traffic after requests were served through advertisements, subscriptions, or repeat human visits. The rapid rise of AI and software agents disrupts this economic model because agents retrieve data in a single pass without viewing ads or subscribing. Consequently, software now represents over half of all web requests, increasing site operational load while revenue remains stagnant. Cloudflare is positioned to address the historical impracticality of charging anonymous callers micropayments per request by moving settlement directly onto the request level. A reverse proxy sits between clients and destination servers, receiving incoming traffic on behalf of the origin machine that hosts the target page or API. Cloudflare operates as a reverse proxy across a substantial portion of the internet. While caching is a common proxy function, being positioned in the middle also allows requests to be inspected, classified, and acted upon before reaching the origin. Implementing early request handling at scale fundamentally requires resolving a classification problem. Cloudflare categorizes automated web traffic according to specific behaviors rather than applying a blanket 'AI' label. Its taxonomy distinguishes between search indexing, real-time agent requests, and model training, which appear identical in raw request logs despite having different business consequences. Because individual web crawlers can perform multiple roles at once, this behavioral separation enables site owners to track and evaluate crawler activities independently. Cloudflare's system also monitors additional behaviors like checkout actions and data collection while allowing sites to specify data storage and resharing permissions.

閱讀原文 ↗
目錄 8 段
  1. 01The Attention Model
  2. 02The Proxy Layer
  3. 03Traffic Classification
  4. 04Blocking and Charging
  5. 05The Request Layer
  6. 06The x402 Exchange
  7. 07Costs and Limits
  8. 08Conclusion

The Attention Model

Historically, websites monetized traffic after requests were served through advertisements, subscriptions, or repeat human visits. The rapid rise of AI and software agents disrupts this economic model because agents retrieve data in a single pass without viewing ads or subscribing. Consequently, software now represents over half of all web requests, increasing site operational load while revenue remains stagnant. Cloudflare is positioned to address the historical impracticality of charging anonymous callers micropayments per request by moving settlement directly onto the request level.

  • Historically, websites made money downstream of requests via ads, subscriptions, and returning visitors while serving requests for free.
  • Software agents bypass traditional monetization mechanisms by completing data retrieval in a single pass without viewing ads or engaging with subscription flows.
  • More than half of the requests reaching websites currently originate from software rather than human visitors.
  • Request volumes are increasing while website revenue remains flat due to the prevalence of agent-driven traffic.
  • Charging anonymous callers micropayments per request was historically impractical due to transaction costs exceeding the payment value.
  • Cloudflare is positioned to shift monetization settlement back onto individual web requests.

The Proxy Layer

A reverse proxy sits between clients and destination servers, receiving incoming traffic on behalf of the origin machine that hosts the target page or API. Cloudflare operates as a reverse proxy across a substantial portion of the internet. While caching is a common proxy function, being positioned in the middle also allows requests to be inspected, classified, and acted upon before reaching the origin. Implementing early request handling at scale fundamentally requires resolving a classification problem.

  • A reverse proxy intercepts incoming requests before passing them to the destination origin server.
  • The origin is the machine hosting the actual page or API being requested.
  • Cloudflare functions as a reverse proxy for a substantial portion of the web.
  • Proxy capabilities extend beyond caching to reading, classifying, checking, and acting on requests.
  • Acting on traffic prior to reaching the origin relies on request classification.

Traffic Classification

Cloudflare categorizes automated web traffic according to specific behaviors rather than applying a blanket 'AI' label. Its taxonomy distinguishes between search indexing, real-time agent requests, and model training, which appear identical in raw request logs despite having different business consequences. Because individual web crawlers can perform multiple roles at once, this behavioral separation enables site owners to track and evaluate crawler activities independently. Cloudflare's system also monitors additional behaviors like checkout actions and data collection while allowing sites to specify data storage and resharing permissions.

  • Cloudflare groups automated web traffic by behavior instead of using a single 'AI' label.
  • Three primary traffic behaviors affecting site policies are search, agent, and training.
  • Search, agent, and training behaviors appear identical in raw server logs but carry different business implications.
  • A single crawler can perform multiple activities simultaneously, such as indexing for search and harvesting training data.
  • Cloudflare also classifies other behaviors, including checkout actions and data collection.

Blocking and Charging

Cloudflare initially offered a simple control to block automated AI crawlers outright to protect website content, but this failed to restore lost revenue. To address this, Cloudflare introduced 'Pay Per Crawl', allowing site owners to block, allow, or charge crawlers a flat per-request fee as the merchant of record. Over time, Cloudflare recognized that crawls correlate poorly with actual value, observing that over half of crawl traffic from well-behaved bots merely refetches unchanged pages. Consequently, Cloudflare began experimenting with a 'Pay Per Use' model that shifts the payment unit from the fetch to the downstream use or citation.

  • Cloudflare's initial response to AI scrapers was a binary control enabling websites to block automated AI traffic completely.
  • The 'Pay Per Crawl' feature expanded options to allow, block, or charge crawlers a flat per-request price with Cloudflare as the merchant of record.
  • Cloudflare found that crawl frequency is a weak proxy for value, noting that over 50% of well-behaved bot crawl traffic is spent refetching unchanged pages.
  • Cloudflare has introduced an experimental 'Pay Per Use' model to price AI outputs or usage rather than initial crawls, despite measurement difficulties.

The Request Layer

Recent architectural developments aim to consolidate identity verification, permission checking, and payment processing within a single HTTP request at the edge before it reaches origin servers. Cloudflare addresses identity through Web Bot Auth, which relies on cryptographic signatures rather than easily spoofed User-Agent headers. Permissions are evaluated through behavior classification and site content preferences, while payment is handled via the x402 protocol. This edge gateway consolidation model shifts metering and settlement away from origin servers, mirroring architecture patterns found in service meshes and middleware.

  • Traditional User-Agent strings offer weak identity guarantees because they can be modified arbitrarily by callers.
  • Web Bot Auth relies on private-key request signing and public-key edge validation to cryptographically verify automated callers.
  • Resolving identity, permission, and payment at the edge ensures origin servers only process pre-cleared requests.
  • Payment execution is handled through the x402 exchange protocol.
  • Web Bot Auth is currently available at the edge, whereas the Monetization Gateway remains in a waitlist phase.
  • Consolidating authentication, authorization, and billing at the edge reflects common gateway patterns from service meshes.

The x402 Exchange

The x402 protocol enables payments directly over HTTP by utilizing the existing HTTP 402 Payment Required status code. When a client requests a priced resource, the server responds with a 402 status specifying the price and destination, allowing the client to re-request the resource with attached proof of payment. Because the payment itself acts as the access credential and introduces minimal overhead, the mechanism supports sub-cent micropayments and autonomous machine agents without requiring account creation, per-seat licensing, or dedicated checkout pages.

  • The x402 protocol utilizes the standard HTTP 402 status code to conduct in-band payments without redirects or separate payment APIs.
  • Sites behind Cloudflare transmit over one billion HTTP 402 responses daily.
  • The exchange functions as a four-step state machine involving the client, server, and a payment-verifying facilitator.
  • Proof of payment serves as the access credential, removing the requirement for API keys or user registration.
  • Near-zero protocol overhead enables viable settlements for fractions of a cent, making it suitable for anonymous machine agents.

Costs and Limits

Resolving identity, permissions, and monetization at the network edge centralizes critical web infrastructure within a single proxy provider like Cloudflare, creating systemic risks alongside efficiency benefits. Cloudflare identifies several practical constraints, including privacy challenges that necessitate alternative measures like private rate limiting and limited value for small websites struggling primarily with discoverability. Furthermore, edge monetization models depend on ecosystem-wide support for HTTP 402 status codes and present verification difficulties for outcome-based pricing. Unbundling multi-purpose crawlers improves site transparency while simultaneously advancing Cloudflare's commercial interests.

  • Centralizing identity, permission, and payment at edge proxies concentrates significant web control within a single provider like Cloudflare.
  • Privacy-conscious and small traffic sources require alternative techniques such as private rate limiting rather than request-level identity.
  • Usage-based payments fail to solve discoverability issues for small sites, forcing them to balance content visibility against monetization.
  • Collecting edge payments requires client callers that can interpret and honor HTTP 402 response codes.
  • Outcome-based pricing aligns cost with value but remains difficult to measure and verify, leading Cloudflare to treat Pay-Per-Use as an experiment.
  • Multi-purpose crawlers diminish transparency for webmasters by obscuring the exact reason a site is being accessed.

Conclusion

The web is shifting from settling value after requests through human attention to settling value directly inside the request. Because agent traffic now makes up the majority of requests, the traditional post-request monetization model no longer functions. In response, Cloudflare is using its reverse proxy position to classify requests, verify sender identity via Web Bot Auth, enforce site rules, and settle payments through the x402 exchange before origins respond. Identity verification operates at the edge while the payment gateway is currently waitlisted, leaving key questions about market concentration, adoption, and pricing models.

  • Agent traffic now comprises the majority of web requests, undermining the historical model of settling value later through human attention.
  • Web value settlement is shifting from after the request to directly inside the request.
  • Cloudflare handles request classification, sender verification via Web Bot Auth, rule enforcement, and payment settlement via x402 at the reverse proxy layer before the origin responds.
  • Identity verification is implemented at the edge, while the payment gateway functionality has opened as a waitlist.
  • Cloudflare collaborated with Coinbase to launch the x402 Foundation and support x402 transactions.