How to block ChatGPT-User: OpenAI's Real-Time Browsing Bot
A complete technical reference for ChatGPT-User, the bot OpenAI uses to fetch real-time web content when users ask questions in ChatGPT.
AI Summary:
ChatGPT-Useris the bot OpenAI uses when a user explicitly asks ChatGPT or a Custom GPT to browse the web for real-time information. To block ChatGPT from reading your site's content during user chats, addUser-agent: ChatGPT-Userto your robots.txt or block its User-Agent string at the network edge.
Role and policy boundary
OpenAI operates different bots for different purposes. While GPTBot is used to scrape the web in bulk to build training datasets for future AI models, ChatGPT-User serves an entirely different function. It acts as an AI assistant browser, fetching web pages in real-time only when a user prompts ChatGPT (or a Custom GPT) to look up current information or summarize a specific URL.
The policy boundary here separates bulk training ingestion from live user assistance. Many publishers choose to block GPTBot to protect their intellectual property from model training, while explicitly allowing ChatGPT-User so that their content can still be referenced, cited, and summarized for users actively seeking it within the ChatGPT interface. Blocking ChatGPT-User means ChatGPT will inform the user that it cannot access your website.
Layered verification
To manage access for ChatGPT-User, a layered verification approach ensures your policies are respected.
The primary and officially supported method is the robots.txt file. OpenAI explicitly respects the ChatGPT-User directive. By adding this to your robots.txt, you can control which parts of your site the assistant can read, or block it entirely.
For strict enforcement, especially if you want to ensure the bot cannot access your site even if the robots.txt is misconfigured, network-level blocking is required. The bot identifies itself with a specific User-Agent string (e.g., Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot). Implementing rules at your WAF or web server to drop requests from this User-Agent provides a hard technical barrier.
WAF and Nginx remediation examples
To enforce your policy at the server level, you can implement User-Agent matching rules to block ChatGPT-User.
For Nginx servers, you can use the following configuration snippet to return a 403 Forbidden status when the bot attempts to access your site:
if ($http_user_agent ~* (ChatGPT-User)) {
return 403;
}
If your infrastructure uses Cloudflare WAF, you can deploy a custom firewall rule using the following JSON expression to block the bot at the network edge:
{
"action": "block",
"expression": "(http.user_agent contains \"ChatGPT-User\")",
"description": "Block OpenAI ChatGPT-User live browsing"
}
Review checklist
To ensure your policy regarding OpenAI's real-time browsing is correctly configured, review these steps:
- Decide on your business policy: Do you want to block AI training (
GPTBot) but allow live user summaries (ChatGPT-User)? - Verify that your
robots.txtincludes the correctUser-agent: ChatGPT-Userdirectives based on your decision. - If blocking, confirm that your edge firewall (WAF) or Nginx configuration is actively rejecting the
ChatGPT-Userstring. - Test the configuration by asking ChatGPT to summarize a specific URL on your site to confirm the block is effective.
Need to optimize your entire site for AI search visibility? Run a comprehensive audit with Geolify.ai.