← Bot Directory/Anchor Browser
Bot directory / ai-assistant

How to block Anchor Browser: The AI Agent Headless Browser

A complete technical reference for Anchor Browser, a headless browser platform used by AI agents to interact with web pages like human users.

AI Summary: Anchor Browser is a headless browser platform optimized for AI agents, allowing them to render pages, run JavaScript, and interact with websites on behalf of users. To block Anchor Browser from accessing your site, add User-agent: Anchor-Browser to your robots.txt or block its specific User-Agent signature at your firewall.

Role and policy boundary

Unlike traditional bulk web crawlers that scrape the internet to build search indexes or training datasets, Anchor Browser operates on behalf of specific AI agents or users. It provides a cloud-based, headless browsing environment that can execute JavaScript, render full DOM trees, and perform interactions just like a human user using a standard browser.

This places Anchor Browser in the category of AI assistants or user-triggered agents. The policy boundary here involves deciding whether you want to allow third-party AI agents to perform tasks on your website (such as reading content, filling out forms, or extracting specific data for a user). Allowing it can enhance user experience for those utilizing AI tools, but blocking it may be necessary if you wish to strictly control automated interactions or prevent agent-driven scraping.

Layered verification

To manage access for Anchor Browser, a layered verification strategy is required.

Anchor Browser generally self-identifies in its User-Agent string, allowing site owners to apply standard robots.txt rules. By specifying Anchor-Browser in your robots.txt, you can request that the browser abstain from interacting with specific paths or your entire site.

However, because Anchor Browser is designed to mimic human browsing behavior—running full JavaScript and rendering the page exactly as Chrome or Safari would—it can be challenging to detect if it chooses to spoof its User-Agent. For robust protection, you must rely on network-level blocking and advanced bot management solutions that can detect headless browser characteristics, in addition to explicit User-Agent blocks in your WAF.

WAF and Nginx remediation examples

If you choose to block Anchor Browser at the server level, you can implement rules based on its declared User-Agent.

For Nginx servers, you can add the following configuration to return a 403 Forbidden status when Anchor Browser is detected:

configuration / code
if ($http_user_agent ~* (Anchor-Browser)) {
    return 403;
}

For environments utilizing Cloudflare WAF, you can deploy a custom firewall rule using the following JSON expression to block the agent before it consumes server resources:

configuration / code
{
  "action": "block",
  "expression": "(http.user_agent contains \"Anchor-Browser\")",
  "description": "Block Anchor Browser AI agent access"
}

Review checklist

To ensure your policy regarding Anchor Browser is correctly enforced, review the following steps:

  1. Verify that User-agent: Anchor-Browser is included in your robots.txt file with the appropriate Disallow directives.
  2. Confirm that your edge firewall (WAF) is actively blocking the Anchor-Browser User-Agent string if you require strict enforcement.
  3. Consider implementing advanced bot protection (like Cloudflare Bot Management) to detect headless browsers that may attempt to spoof standard User-Agents.
  4. Test your configuration to ensure legitimate human traffic is not inadvertently affected by headless browser mitigation rules.

Need to optimize your entire site for AI search visibility? Run a comprehensive audit with Geolify.ai.