The probe

Who reads your site when Lens probes it

Lens reads a site the way an AI agent meets it: over plain HTTP, and over the agent protocols the site publishes. It says who it is on every request, and it never pretends to be a person's browser.

User-Agent
IntegraLens/0.1.0 (+https://lens.integraledger.com/probe)
robots.txt token
IntegraLens
Added by the platform
CF-Worker: integraledger.com
From another Cloudflare zone
CF-Connecting-IP: 2a06:98c0:3600::103
Signed requests carry
Signature-Agent: "https://lens.integraledger.com"

Identities

Each request names the identity that made it

A report says which identity produced each finding.

anon
An anonymous HTTP client: the User-Agent above, an Accept header, and no cookies, credentials or stored session.
ucp
A UCP platform presenting Integra's agent profile (UCP 2026-08-25) in each tool call.
signed
The anonymous client plus a Web Bot Auth signature (HTTP Message Signatures, RFC 9421, Ed25519) over each request's host and its Signature-Agent header, valid for 60 seconds. It fetches your home page and the well-known documents again, so a report can say whether your site treats a verified agent differently. The public key is in the key directory above. While Lens holds no signing key, these steps are skipped and their criteria are reported as not tested.
lens
Lens's own infrastructure: DNS over HTTPS, public chain reads and the model API. It never sends a request to your site.

Cloudflare Worker on zone integraledger.com; CF-Worker header added by the platform

Limits

What it never does, and how it paces itself

  • It never renders a page, runs a site's scripts, or presents a browser's User-Agent.
  • It never writes to a site: no cart, checkout, form, order or account, and never a request to a cart link.
  • One request at a time to a site's registrable domain, at least half a second apart.
  • At most 48 requests to the site in one probe, one probe of a domain at a time, and ten probes of a domain an hour.
  • A Retry-After on a 429 or 503 is honoured once, for up to 30 seconds.
  • It reads one catalogue page, one product page and at most three policy documents. It measures; it does not crawl.

Opting out

Disallow IntegraLens in robots.txt

The probe honours robots.txt under the token IntegraLens, falling back to the rules for every agent.

User-agent: IntegraLens
Disallow: /

A few documents stay readable, because a site publishes them for automated clients: robots.txt itself, everything under /.well-known/, /llms.txt, and the endpoints a site declares for agents in its own agent documents. A site that tells agents to stay out has made a choice about agent readiness, so a disallow is reported, citing the robots.txt bytes, rather than routed around.

Checking a report

A report is its bytes, and its name is their SHA-256

Every report is served as the exact bytes Lens stored, and its fingerprint is the SHA-256 of those bytes. Hash what you receive and compare: nothing needs to be taken on trust. The HTTP door sends the hash in the Lens-SHA256 header; the MCP door sends it in the result's _meta.

curl -s https://lens.integraledger.com/reports/<fingerprint>.json | shasum -a 256

A report names its capture manifest, which lists every request the probe made, and its analysis manifest, which holds any model judgement with the evidence it cites. Each item is served by hash under the report. The report also names the rubric version and the SHA-256 of the rubric that scored it.