A Fastly Compute service that detects AI bot access to your site and reports content_retrieved telemetry events to OpenAttribution. The Fastly counterpart of openattribution-org/cloudflare-worker.
It sits in front of your origin, passes every request straight through (telemetry runs in the background and never delays the response), and when a request looks like an AI crawler, fetcher, or search indexer it sends a content_retrieved event with source_role: edge.
Edge reporting sees retrieval only — what AI bots fetched from your site.
content_grounded,content_cited, andcontent_engagedhappen inside the agent and can't be observed from the CDN. Retrieval is still the most reliable signal because it needs no cooperation from the agent.
Two tiers, in order:
-
Bot Management signal (optional) — if you run Fastly Bot Management, set
verified_bot_headerin theoa_configconfig store to the request header it stamps with anAI-CRAWLER/AI-FETCHER/AI-SEARCHsignal. That classification is trusted first.Only set
verified_bot_headerwhen a fronting Fastly service stamps the header itself and unsets any client-supplied copy first. This service cannot tell who set the header — if clients can reach it directly withverified_bot_headerconfigured, anyone can send the header and be reported as a verified bot. -
User-agent matching — matches against ~50 known AI bot UA patterns. Works on any Fastly service with no extra products.
Some bots aren't catchable by UA alone (OpenAI Operator disguises as Chrome, xAI Grok uses a fake Safari UA, Google AI training uses the standard Googlebot UA). Bot Management is the only way to catch those reliably.
npm install
fastly compute serve # local dev — uses the values in fastly.toml [local_server]To deploy to a Fastly service:
# 1. Point the `origin` backend at your site (fastly.toml or the Fastly UI).
# 2. Add the OA telemetry backend: host telemetry.openattribution.org, TLS, port 443, name "oa_telemetry".
# 3. Create a secret store "oa_secrets" with key "api_key" = your content-owner key:
fastly secret-store create --name oa_secrets
fastly secret-store-entry create --store-id <id> --name api_key # paste the key when prompted
# 4. Create a config store "oa_config" with telemetry_path = https://telemetry.openattribution.org/events
fastly compute publishThe service reports events about your own site, so it authenticates with a content-owner key (oat_pub_…) issued with telemetry:write scope for your verified domain — not a platform (oat_pk_…) key. Get one from the OpenAttribution dashboard after verifying domain ownership.
| Name | Where | Description |
|---|---|---|
origin |
backend | Your site's origin server |
oa_telemetry |
backend | telemetry.openattribution.org (TLS, port 443) |
oa_secrets / api_key |
secret store | Content-owner key (oat_pub_…), telemetry:write scope |
oa_config / telemetry_path |
config store | Telemetry endpoint URL (default https://telemetry.openattribution.org/events) |
oa_config / verified_bot_header |
config store | Optional — request header carrying a Fastly Bot Management AI signal. Set only behind a fronting service that strips the client-supplied copy (see Detection) |
When an AI bot is detected, one content_retrieved event containing:
- Request: URL,
User-Agent,Content-Telemetry-ID(if present) - Classification: bot category (
training/inference/search), whether verified, detection method - Response: HTTP status, response size (
Content-Length), cache status (if exposed viaX-Cache) - Network: ASN, ASN organisation, country code, JA4 TLS fingerprint
No visitor IP addresses, cookies, or request bodies are sent. Static resources (CSS, JS, images, fonts, …) are skipped entirely.
This service is open source (Apache 2.0) — run it yourself on your own Fastly account. OpenAttribution can also operate it for you against a scoped Fastly API token; ask in the dashboard.