What it does
ChatGPT-User is OpenAI's user action crawler. A live fetch made because a human asked the assistant about your page right now. Closest thing to a real visitor; several of these (Perplexity-User, meta-externalfetcher) ignore robots.txt by design because the request is user-initiated.
Fires when a ChatGPT user or Custom GPT visits a page on demand. Full UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot
How to verify a hit is really ChatGPT-User
Verification method (July 2026): Published IP list: https://openai.com/chatgpt-user.json (fetched live 2026-08-22)
Strongest available check: the vendor publishes the crawler's egress IPs. Fetch the list, then confirm the hit's source IP falls inside it — a UA match from any other IP is a spoofer.
User-agent strings are freely spoofed, so a UA match alone proves nothing. Full step-by-step method: verify by IP.
Allow or block in robots.txt
Match the exact token ChatGPT-User in robots.txt:
# Block ChatGPT-User site-wide
User-agent: ChatGPT-User
Disallow: /
# Explicitly allow ChatGPT-User
User-agent: ChatGPT-User
Allow: /
For the allow-search-block-training combined pattern (and the Allow-directive gotcha that silently kills carve-outs), see the robots.txt guide. robots.txt governs whether ChatGPT-User may fetch; llms.txt is the separate, curated map AI assistants read once allowed in.
Vendor documentation: https://developers.openai.com/api/docs/bots
The OpenAI family
OpenAI operates 4 distinct tokens in this roster, and they do not block each other: a robots.txt line for ChatGPT-User does nothing to its siblings — each needs its own User-agent: entry (the robots.txt guide has combined patterns).
| Token | Role | robots.txt |
|---|---|---|
| GPTBot | Training | honors robots.txt |
| OAI-SearchBot | AI search | honors robots.txt |
| OAI-AdsBot | User action | claims robots compliance |
Frequently asked questions
What is ChatGPT-User?
ChatGPT-User is OpenAI's user action crawler. A live fetch made because a human asked the assistant about your page right now. Closest thing to a real visitor; several of these (Perplexity-User, meta-externalfetcher) ignore robots.txt by design because the request is user-initiated.
Does ChatGPT-User respect robots.txt?
OpenAI claims ChatGPT-User respects robots.txt, but compliance is not independently confirmed.
How do I block ChatGPT-User?
Add 'User-agent: ChatGPT-User' followed by 'Disallow: /' to your robots.txt. Use the exact token — substring variants of other tokens will not match.
How do I verify ChatGPT-User traffic by IP?
Fetch OpenAI's published IP list for ChatGPT-User and confirm the hit's source IP falls inside it — a ChatGPT-User user-agent from any other IP is a spoofer.
Related bots
Same vendor, then other user-action fetchers — the full directory profiles all 34.