All services / Security / Bot Management
πŸ€–
Security

Bot Management

Score every request 1–99 for how human it is, and act on it β€” stopping abuse without CAPTCHAs for real users.

What it is

Cloudflare scores every request from 1 (definitely a bot) to 99 (definitely human) using machine learning trained on trillions of requests per day. Bot Management lets you challenge or block automated trafficbotAutomated software making requests instead of a human. Some bots are good (search engines); many are malicious. β€” credential stuffingcredential stuffingUsing stolen username/password lists to try to break into many accounts at once., scraping, inventory hoarding β€” while letting real users and verified good bots through untouched.

Why it helps the client

  • Stops credential stuffing, content scraping, and checkout/inventory bots.
  • Protects conversion and data without adding friction for real users.
  • Precise control β€” act on the 1–99 score and auto-allow verified bots like search engines.
  • Network-wide ML β€” new attack patterns learned across all of Cloudflare benefit everyone.

Why they'd want it

  • Reduce fraud, API abuse, and infrastructure cost from junk traffic.
  • Protect logins and inventory without annoying customers with CAPTCHAs.
  • Board-ready bot analytics that show the threat is handled.

πŸ”¬ How it actually works

  • Every request gets a bot scorebot scoreCloudflare's 1–99 rating of how likely a request came from a bot (1) versus a real human (99). from 1 (bot) to 99 (human), produced by machine learning trained on trillions of requests per day plus heuristics, behavioral analysis, and fingerprinting. Verified good botsbotAutomated software making requests instead of a human. Some bots are good (search engines); many are malicious. (Googlebot and friends) are identified via a maintained allowlist so you don't block useful crawlers.
  • You act on the score with rules β€” challenge or block below a threshold, or only on sensitive paths (login, checkout, gift-card, APIAPIApplication Programming Interface β€” how software talks to other software, e.g. a mobile app calling a server.). JA3/JA4 TLSTLSTransport Layer Security (formerly SSL) β€” the encryption behind HTTPS and the padlock in your browser. fingerprints and 'likely automated' signals catch tools that spoof a browser user-agent.
  • Enterprise BotbotAutomated software making requests instead of a human. Some bots are good (search engines); many are malicious. Management exposes the full 1–99 score and analytics; lower tiers get Bot Fight Mode / Super Bot Fight Mode, which are simpler on/off challenges.
  • Because the model learns across all of Cloudflare, an attack pattern seen on one customer improves detection for everyone β€” and Managed Challenge stops botsbotAutomated software making requests instead of a human. Some bots are good (search engines); many are malicious. without CAPTCHAs for real users.

πŸ“– Key terms on this page hover any underlined term anywhere on the site for its definition

bot
Automated software making requests instead of a human. Some bots are good (search engines); many are malicious.
credential stuffing
Using stolen username/password lists to try to break into many accounts at once.
API
Application Programming Interface β€” how software talks to other software, e.g. a mobile app calling a server.
bot score
Cloudflare's 1–99 rating of how likely a request came from a bot (1) versus a real human (99).
TLS
Transport Layer Security (formerly SSL) β€” the encryption behind HTTPS and the padlock in your browser.
WAF
Web Application Firewall β€” inspects web requests and blocks malicious ones (like SQL injection and XSS) before they reach your site.

Live demo walkthrough

5 steps

Screens below are annotated recreations of the Cloudflare dashboard. The numbered orange pin marks exactly where to click.

1

Select the website

πŸ‘† Account Home β†’ example.com
πŸ”’dash.cloudflare.com
example.com β–Ύ
Test Account NickN

πŸ‘‰ Do this

Open the site you want to protect from automation.

πŸ’¬ Say this

β€œLet's look at how Cloudflare separates real users from bots on this site.”

2

Open Security β†’ Bots

πŸ‘† Left nav β†’ Security β†’ Bots
πŸ”’dash.cloudflare.com/example.com/security/bots
example.com β–Ύ
Test Account NickN

Security

Bots

Bot Fight ModeChallenge traffic from definitely-automated sources.
Bot score distribution (last 24h)
Automated
Likely bot
Likely human
Verified human
Definitely automated β†’ BlockBot Management lets you act on the 1– 99 bot score with precision.

πŸ‘‰ Do this

Expand Security and click Bots.

πŸ’¬ Say this

β€œThis is the Bots surface. Every request through Cloudflare gets a bot score, and this is where we decide what to do with it.”

3

Turn on Bot Fight Mode

πŸ‘† Bots β†’ Bot Fight Mode toggle
πŸ”’dash.cloudflare.com/example.com/security/bots
example.com β–Ύ
Test Account NickN

Security

Bots

Bot Fight ModeChallenge traffic from definitely-automated sources.
3
Bot score distribution (last 24h)
Automated
Likely bot
Likely human
Verified human
Definitely automated β†’ BlockBot Management lets you act on the 1– 99 bot score with precision.

πŸ‘‰ Do this

Toggle Bot Fight Mode on (Super Bot Fight Mode / scoring on higher plans).

πŸ’¬ Say this

β€œOn lower tiers, Bot Fight Mode challenges obviously-automated traffic with one switch. On Enterprise Bot Management, every request gets a precise 1–99 score instead.”

4

Read analytics & act on the score

πŸ‘† Bots β†’ Score distribution β†’ Manage rules
πŸ”’dash.cloudflare.com/example.com/security/bots
example.com β–Ύ
Test Account NickN

Security

Bots

Bot Fight ModeChallenge traffic from definitely-automated sources.
Bot score distribution (last 24h)
Automated
Likely bot
Likely human
Verified human
Definitely automated β†’ BlockBot Management lets you act on the 1– 99 bot score with precision.

πŸ‘‰ Do this

Point to the score distribution, then open Manage rules to act on the score.

πŸ’¬ Say this

β€œThis distribution shows how much traffic is automated. From here we write a surgical rule β€” 'if bot score is under 30, block' β€” which stops the bad bots while real users sail through with no CAPTCHA at all.”

5

Prove it in Security Analytics

πŸ‘† Left nav β†’ Security β†’ Analytics
πŸ”’dash.cloudflare.com/example.com/security/analytics
example.com β–Ύ
Test Account NickN

Security

Analytics

Last 24 hours β–Ύ
Requests & mitigations
Total requests48.2M
Mitigated1.24M+3%
Blocked918K
Challenged322K
Top events by service
ServiceRule / signatureActionEvents
WAFSQLi – ManagedBlock612K
Bot ManagementScore < 30Managed challenge288K
Rate limitingLogin throttleBlock141K
DDoSHTTP flood – L7Block96K
5

πŸ‘‰ Do this

Open Security β†’ Analytics and point to the bot-driven challenge/block events.

πŸ’¬ Say this

β€œIn Security Analytics you can see the automated traffic we challenged and blocked in aggregate β€” hundreds of thousands of events β€” while conversion-critical human traffic was never touched. That's the difference between a blunt CAPTCHA wall and a precise score.”

Questions clients ask

Tap a question to reveal the answer to say
Will real users get annoying CAPTCHAs?β€Ί
No β€” Managed Challenge picks the least-friction check, often invisible, and real users usually pass without seeing anything. Because you act on the score, humans (90+) sail through while automation is challenged or blocked.
How do you tell a good bot from a bad one?β€Ί
Verified botsbotAutomated software making requests instead of a human. Some bots are good (search engines); many are malicious. β€” search engines, monitoring, payment webhooks β€” are on a maintained allowlist and pass; malicious automation is caught by ML and behavioral signals even when it fakes a browser user-agent.
What problems does this actually solve for us?β€Ί
Credential stuffingcredential stuffingUsing stolen username/password lists to try to break into many accounts at once. and account takeover, content and price scraping, inventory and checkout hoarding, gift-card cracking, and APIAPIApplication Programming Interface β€” how software talks to other software, e.g. a mobile app calling a server. abuse β€” all of which look like ordinary 'traffic' to a WAFWAFWeb Application Firewall β€” inspects web requests and blocks malicious ones (like SQL injection and XSS) before they reach your site. but are really automation.
Can bots evade the score by pretending to be a browser?β€Ί
That's exactly what fingerprinting (JA3/JA4), behavioral analysis, and ML are designed to catch β€” spoofing a user-agent isn't enough to look human to the model.
Do we have to train it on our traffic?β€Ί
No training on your side β€” it's pre-trained on Cloudflare's network-wide traffic and works out of the box. You just choose the thresholds and actions.