WAF_BLOCKED
The target site refused Onto's crawler (the origin returned 401 or 403).
What this means
[02]WAF_BLOCKED means the target site answered Onto's fetch with 401 or 403. Usually that's a firewall or bot protection layer, like Cloudflare or Akamai, turning crawlers away. The site is actively blocking, not publishing a robots.txt rule. For robots.txt, see ROBOTS_BLOCKED. Failed requests are refunded.
When you'll see it
[03]HTTP 403. Body always includes code: "WAF_BLOCKED". Branch on code, never on the human-readable message — wording can change without notice; the code is the stable contract.
Example response
[04]{
"status": "error",
"code": "WAF_BLOCKED",
"message": "Target site refused our crawler (HTTP 403)"
}How to handle
[05]Skip the URL. Don't retry with a different user agent or try to get around the block. If you own the site, allow the `Onto-Reader` user agent in your firewall rules. Otherwise tell your user the site blocks crawlers and link them to the source.
Suggested handling in a Node client:
if (data.code === 'WAF_BLOCKED') {
// Origin won't serve us. Skip and move on; don't retry.
return null;
}The site's robots.txt has Disallow: / for GPTBot or for every user agent.
The target URL returned 404, or its hostname doesn't resolve.
See the full error index for the complete catalog with the handling switch statement covering every code at once.