About agent-helper PRE-LAUNCH DRAFT. This instance is not the public service. Undecided and therefore unpublished: operator, observation period, dataset publication, lifetime. Nothing below is a promise yet; the fields marked (placeholder) are filled in before launch. Operator: not yet published (placeholder) Contact (abuse, takedown, corrections, limits): abuse@agent-helper.org What it is A free, non-commercial, read-only utility for machine clients: computations, mirrored reference data and self-diagnosis, one GET request each. Why it exists It is a utility and an experiment. The questions, in order of importance: 1. Do autonomous agents in the wild reach small, unfamiliar services at all? 2. Of the clients that call an endpoint directly, what share go on to read /agents.md, /llms.txt, / or /robots.txt? 3. Does friction matter more than features: how do clients behave on endpoints with more or less of it? A negative answer to the first question is a valid result and will be published as such. Where the service is not available Addresses registered in Belarus (BY), Russian Federation (RU), Ukraine (UA) receive 451 Unavailable For Legal Reasons, with an explanation in the body. The country is the registration country of the address block (RIR delegation files), not a geolocation. The operator decided this; it is not a technical limitation. Addresses the operator lists are exempt, whatever their country. Blocked requests are logged like any other (so the block itself can be measured) and are reported separately from the experiment's results. What is logged, per request - an HMAC of the client address and of its /24 (IPv4) or /64 (IPv6) network, keyed with a salt that is replaced every day (UTC); the old salt is overwritten, so hashes cannot be linked across days or reversed - ASN and registration country of the address, from local tables - user agent; header names in the order received; values of Accept, Accept-Encoding and Accept-Language; which browser navigation headers were present - HTTP version, scheme, TLS version, cipher and ALPN - route pattern (e.g. /fx/{base}/{quote}), names of query parameters, response format, status, error kind, Retry-After given, duration, size, cache policy, cache outcome, rate class, URL length - for /ip and other self-diagnosis paths, the agent/human guess shown in the response Not logged: raw IP addresses, parameter values (including anything marked secret: HMAC keys, JWTs, card numbers), header values other than those listed, request bodies. No cookies (except the /probe/cookie test), no analytics, and the log is not shared with third parties. User agents are cleaned before they are stored: anything that looks like an email address or a URL query is replaced with a marker, because some clients put a contact address there. Who else sees your requests Requests reach this service through Cloudflare, a CDN acting as a reverse proxy. Cloudflare terminates TLS and sees every request in full, including your address, and handles it under its own privacy policy. Nothing from Cloudflare is added to the log described here. One consequence for the log itself: the HTTP version and TLS parameters recorded are those of Cloudflare's connection to us, not your client's. How identifiable that makes you Plainly: the address hash changes every day, but the combination of user agent, the set and order of headers, HTTP version and TLS parameters is itself a fingerprint. For a client with an unusual combination it is often enough to recognise the same client across days, and nothing here prevents that. This is not an accident: what a client sends, and how consistently, is one of the things this experiment measures. We keep it because of that, not in spite of it. What we do not do: we do not combine it with anything else, do not build profiles, do not attempt to identify people or organisations behind it, and publish only aggregates. Exceptions, both operational: when the service itself fails with a 500, the path and query of that request are kept for 30 days to reproduce the fault; and a hash (not the contents) of an input that crashed or overran a computation is kept for 180 days, so that repeated failures can be found and that input refused. Retention Request log: 400 days, then deleted. Server-error records: 30 days. Incident records: 180 days. The log also has a size quota; when it is reached the oldest rows are deleted, so the log can never fill the disk. Observation and publication Observation period: not yet published (placeholder) Dataset publication: not yet published (placeholder) Published data will be aggregated (counts and shares by route, client class, network type), never per-client rows. How long this will run not yet published (placeholder) Paths under /v1/ are frozen. A published path is not removed without notice here. Removed paths: none. Terms of use Use it freely within the limits (/limits). No warranty: values are computed or relayed as accurately as we can, and every response says where it comes from. Reference data remains subject to its publishers' terms (/sources). Currency rates are for information, not transactions. The service is non-commercial; if that changes, every source's terms are re-checked first. Software version 1.0.0. Generated documentation: /agents.md, /llms.txt, /openapi.json. # type: computed