The probe
Who reads your site when Lens probes it
Lens reads a site the way an AI agent meets it: over plain HTTP, and over the agent protocols the site publishes. It says who it is on every request, and it never pretends to be a person's browser.
- User-Agent
IntegraLens/0.1.0 (+https://lens.integraledger.com/probe)- robots.txt token
IntegraLens- Added by the platform
CF-Worker: integraledger.com- From another Cloudflare zone
CF-Connecting-IP: 2a06:98c0:3600::103- Presented to UCP businesses
- https://lens.integraledger.com/.well-known/ucp
- Signed requests carry
Signature-Agent: "https://lens.integraledger.com"- Web Bot Auth key directory
- https://lens.integraledger.com/.well-known/http-message-signatures-directory
Identities
Each request names the identity that made it
A report says which identity produced each finding.
- anon
- An anonymous HTTP client: the User-Agent above, an Accept header, and no cookies, credentials or stored session.
- ucp
- A UCP platform presenting Integra's agent profile (UCP 2026-08-25) in each tool call.
- signed
- The anonymous client plus a Web Bot Auth signature (HTTP Message Signatures, RFC 9421, Ed25519) over each request's host and its Signature-Agent header, valid for 60 seconds. It fetches your home page and the well-known documents again, so a report can say whether your site treats a verified agent differently. The public key is in the key directory above. While Lens holds no signing key, these steps are skipped and their criteria are reported as not tested.
- lens
- Lens's own infrastructure: DNS over HTTPS, public chain reads and the model API. It never sends a request to your site.
Cloudflare Worker on zone integraledger.com; CF-Worker header added by the platform
Limits
What it never does, and how it paces itself
- It never renders a page, runs a site's scripts, or presents a browser's User-Agent.
- It never writes to a site: no cart, checkout, form, order or account, and never a request to a cart link.
- One request at a time to a site's registrable domain, at least half a second apart.
- At most 48 requests to the site in one probe, one probe of a domain at a time, and ten probes of a domain an hour.
- A Retry-After on a 429 or 503 is honoured once, for up to 30 seconds.
- It reads one catalogue page, one product page and at most three policy documents. It measures; it does not crawl.
Opting out
Disallow IntegraLens in robots.txt
The probe honours robots.txt under the token IntegraLens, falling back to the rules for every agent.
User-agent: IntegraLens
Disallow: /A few documents stay readable, because a site publishes them for automated clients: robots.txt itself, everything under /.well-known/, /llms.txt, and the endpoints a site declares for agents in its own agent documents. A site that tells agents to stay out has made a choice about agent readiness, so a disallow is reported, citing the robots.txt bytes, rather than routed around.
Checking a report
A report is its bytes, and its name is their SHA-256
Every report is served as the exact bytes Lens stored, and its fingerprint is the SHA-256 of those bytes. Hash what you receive and compare: nothing needs to be taken on trust. The HTTP door sends the hash in the Lens-SHA256 header; the MCP door sends it in the result's _meta.
curl -s https://lens.integraledger.com/reports/<fingerprint>.json | shasum -a 256A report names its capture manifest, which lists every request the probe made, and its analysis manifest, which holds any model judgement with the evidence it cites. Each item is served by hash under the report. The report also names the rubric version and the SHA-256 of the rubric that scored it.