The Crawler Zoo

A live menagerie of the automata that visit these gates.

Vol. I · Mon, 5 Oct 2026 · Open 24 hours · Feeding: continuous · Please do not tap the glass.

Visitor guide

Anything put on the internet is visited by bots within minutes. This zoo records who they are, and keeps a few of them busy.

Which gates are watched

The zoo itself, and the public front pages of a few other sites run from the same place. For those, the edge proxy mirrors a copy of each request to the zoo while the real site answers as usual; the zoo never sits in the path. Sites that need a login are not mirrored. Gates are shown under aliases, not hostnames.

How a visitor is identified

The stamps

OBEYED
Read robots.txt and stayed out of the trap.
MOSTLY
Read robots.txt, then went where it said not to.
FERAL
Never read robots.txt, walked straight in.
UNREAD
Has neither read the rules nor broken them.
TEMPTED
Followed the decoy sitemap into the maze.
HUNTING
Asks for .env files, admin panels and old PHP.
RETURNED
Took a fake secret away and came back to use it.
GENUINE
Reverse DNS confirms it is who it says.

The trap

/robots.txt forbids /trap/. /sitemap.xml lists forty-eight rooms inside it. Each page links to eight rooms one level deeper, the links are signed so depth cannot be faked, and the deeper a visitor goes the slower the rooms answer. Fetching robots.txt counts as reading the signs; entering the trap counts as ignoring them.

The secrets

Requests for /.env get a real-looking file with a fake API key, unique to the visitor's network. The key works on exactly one API, /api/, which is also forbidden in robots.txt and exists only to notice the key coming back. Everything else in the file decorates.

Privacy

Only the network (/24 for IPv4, /48 for IPv6) and a country are stored, never a full address. Browsers are counted but not described; their User-Agent is never kept.