The Agent Web Crawler Census

Every bot that crawled a live, publicly-listed x402 + MCP endpoint in 24 hours — and what each one did when it hit a payment wall. Snapshot: 2026-08-27 (24h).

60named crawlers
6,309requests / 24h
187distinct user agents
0that ever paid

The finding: the agent web has a fully-built supply side and no demand side. In this window, 60 distinct named crawlers discovered, probed, graded, indexed, health-checked and price-scraped this endpoint. Roughly 600 of those requests hit a /v1/buy/* route and received a valid HTTP 402 payment challenge. Not one attached a payment.

Across the endpoint’s entire lifetime the payment log records 2 payment attempts — both of them our own test probes with deliberately invalid signatures. Real payments received from an autonomous agent: 0.

19 of the 60 say so in their own User-Agent string: liveness-only, never invokes tools · reads-402-price-quotes-only-never-pays · no auth attempted · introspection-only.

Who is actually out there

CategoryAgentsRequests/24hPaidWhat they do
Liveness / uptime monitor 14 1,396 0 Checks that the endpoint is up and answering. Never calls a tool, never pays.
Directory & index crawler 16 718 0 Ingests the catalog/manifest to list the service in a directory. Never pays.
Security research 5 50 0 Scans MCP surfaces for injection, rug-pull and tool-poisoning risk. Never pays.
Search engine 3 46 0 Conventional web indexing. Never pays.
Ecosystem census / research 9 39 0 Longitudinal surveys of the agent ecosystem. Never pays.
AI training / retrieval 2 20 0 Fetches page content for model training or retrieval. Never pays.
Price-quote scraper 4 17 0 Reads the 402 challenge purely to record the price. Explicitly never pays.
Contact / domain harvesting 3 11 0 Looks for operator contact details. Never pays.
Misc utility 3 10 0 Favicons, text extraction, link checking. Never pays.
SEO / backlink 1 8 0 Backlink-graph crawling. Never pays.

The full census

Sorted by volume. Every row observed first-hand — nothing is copied from a third-party bot list. Operator links are the ones each agent published in its own UA string.

User agentCategoryReq/24hPaid
SentinelOracle/0.1 (+https://glimind.com/opt-out; liveness-only, never invokes tools)
“liveness-only, never invokes tools”
Liveness / uptime monitor 584 no
x402-list-monitor/1.0 (+https://x402-list.com) Directory & index crawler 543 no
x402-observer/1.0 (uptime+trust monitor; +https://x402.fuchss.app/trust)
“uptime+trust monitor”
Liveness / uptime monitor 331 no
mcpbeat/0.1 (+https://mcpbeat.com/bot/; liveness check)
“liveness check”
Liveness / uptime monitor 272 no
zevruna-monitor/1.0 (+https://zevruna.com) Liveness / uptime monitor 138 no
agent-tools.cloud-crawler/0.1 (+https://agent-tools.cloud) Directory & index crawler 115 no
GolemreachTrustBot/0.1 (+https://golemreach.com/trust/bot) Liveness / uptime monitor 32 no
mcpi/probe Directory & index crawler 28 no
Googlebot/2.1 (+http://www.google.com/bot.html) Search engine 24 no
GoogleOther (Chrome/151 Mobile Safari) Search engine 21 no
CCBot/2.0 (https://commoncrawl.org/faq/) AI training / retrieval 15 no
ProofBench/0.1 (+https://proofbench.dev/about/probe; MCP registry health probe)
“MCP registry health probe”
Liveness / uptime monitor 14 no
mcp-protections-research/0.1 (+defensive security research)
“defensive security research”
Security research 14 no
aisec-registry/0.2 (+https://sec.sqrx.io) Security research 12 no
MCPWatch/0.1.0 longitudinal MCP security research
“longitudinal MCP security research”
Security research 10 no
assay-indexer/0.1 Ecosystem census / research 10 no
mcp2-research/1.0 Security research 8 no
FaviconAPI/1.0 (+https://vemetric.com/favicon-api) Misc utility 8 no
hermes-contact-discovery/1.0 (research) Contact / domain harvesting 8 no
reliability-bureau-spike/0.1 Liveness / uptime monitor 8 no
serpstatbot/2.1 (advanced backlink tracking bot; https://serpstatbot.com/) SEO / backlink 8 no
TOLL402-Exact-Quote-Verifier/1.0 (+https://toll402.com/insights/x402-discovery-crawl-methodology) Price-quote scraper 8 no
merona-mcp-probe/0.1 (read-only research)
“read-only research”
Ecosystem census / research 7 no
mcp-rugpull-research/1.0 Security research 6 no
AgentIndexBot/0.1 (+https://agents.traderszone.net; polite ARD crawler)
“polite ARD crawler”
Directory & index crawler 6 no
Claude-User (claude-code/2.1.247; +https://support.anthropic.com/) AI training / retrieval 5 no
research-cron Ecosystem census / research 5 no
Cleared-Harness/1.0 (+https://clearedindex.com/harness) Ecosystem census / research 4 no
x402-opportunity-scout/1.0 Price-quote scraper 4 no
AgentAlmanac-PriceBot/0.1 (+https://agentalmanac.org) reads-402-price-quotes-only-never-pays
“reads-402-price-quotes-only-never-pays”
Price-quote scraper 4 no
io.verifymcp/probe Liveness / uptime monitor 4 no
AIVE-MCP-EndpointProbe/1.0 (+https://github.com/eXaive/aive-ingest; reachability check only, no auth attempted)
“reachability check only, no auth attempted”
Liveness / uptime monitor 3 no
strand-mcp/0.1 (+sync) Directory & index crawler 3 no
mcpgrade-probe/0.1 Liveness / uptime monitor 3 no
measure-mcp-schema/0.1.0 Ecosystem census / research 3 no
api-forge-mcp-index/1.0 (+https://api.temsor.com/mcp/index) Directory & index crawler 3 no
MCPWitness/1.0 (health probe; +https://mcpwitness.com)
“health probe”
Liveness / uptime monitor 3 no
mcpscan/1.0 (+https://modc2.com/mcpscan; MCP index crawler)
“MCP index crawler”
Directory & index crawler 3 no
agent-world-probe/py-0.95 (research; MCP census)
“research; MCP census”
Ecosystem census / research 3 no
rill-directory-probe/1.0 Directory & index crawler 3 no
AllMCPs-Ingest Directory & index crawler 3 no
mcp-history/1.0 (+ecosystem drift survey)
“ecosystem drift survey”
Ecosystem census / research 3 no
mcpqueen-grader/0.3 (+https://mcpqueen.com) Directory & index crawler 3 no
mcp-observatory/0.1.0 (+https://github.com/yhouta/mcp-observatory; public transparency log)
“public transparency log”
Ecosystem census / research 3 no
VerifyMCP-OwnersBot/1.0 (+https://verifymcp.io/docs/build/owners-json) Directory & index crawler 2 no
lastseen-schema-probe/1.0 (+https://lastseen.dev; introspection-only)
“introspection-only”
Liveness / uptime monitor 2 no
DomainIntelCollector/1.0 Contact / domain harvesting 2 no
AIVE-MCP-Discover/1.0 (+https://aive.global/mcp-trust/census; one server/discover POST per endpoint, no auth attempted)
“one server/discover POST per endpoint, no auth attempted”
Directory & index crawler 2 no
x402-observatory/0.2 (+research collector)
“research collector”
Ecosystem census / research 1 no
TOLL402-Safe-Origin-Verifier/1.0 (+https://toll402.com/insights/x402-discovery-crawl-methodology) Price-quote scraper 1 no
titan-ghost-x402-directory/1.0 Directory & index crawler 1 no
DomainArrivals-Evidence/1.0 (+https://domainarrivals.com) Contact / domain harvesting 1 no
Open402DirectoryCrawler/1.0 Directory & index crawler 1 no
mcphq-probe/0.1 (+https://mcphq.ai) Liveness / uptime monitor 1 no
AgentScore-EndpointProbe/1.0 Liveness / uptime monitor 1 no
Station70-Gatekeeper-Catalog/1.0 (+https://station70.com; catalog research)
“catalog research”
Directory & index crawler 1 no
402explorer/0.1 (+https://discover.paygent.net/about) Directory & index crawler 1 no
hultra-link/1.0 (+https://donnees.hultra.link/sondes.md) Misc utility 1 no
trafilatura/2.1.0 (+https://github.com/adbar/trafilatura) Misc utility 1 no
Googlebot-Image/1.0 Search engine 1 no

Use it on your own traffic

The same data, with a case-insensitive matcher per agent, is served free and unmetered — no key, no payment, no rate limit worth worrying about:

curl -s https://fetchgate.dev/v1/agent-census.json | jq '.agents[] | {matcher, category}'

Classify your own access log in about five lines:

const census = await (await fetch("https://fetchgate.dev/v1/agent-census.json")).json();
const rules = census.agents.map(a => [new RegExp(a.matcher, "i"), a.category]);

const classify = (ua) =>
  rules.find(([re]) => re.test(ua))?.[1] ?? "unknown";

Licensed CC BY 4.0 — use it anywhere, just link back to this page.

Method, and what this does not show

Counts come from Cloudflare zone analytics for fetchgate.dev (httpRequestsAdaptiveGroups) over the 24 hours ending 2026-08-27T20:30:00Z. Payment counts come from the endpoint’s own payment-analytics dataset, which records every x402 verify/settle attempt at a single choke point.

Honest limitations:

So what?

If you are building a machine-payable API, the practical reading is that getting discovered is solved and getting paid is not. Listing in every x402 and MCP directory works — it reliably produces crawlers, grades, uptime badges and index entries. None of that is demand. Budget your effort accordingly, and instrument the payment path itself so you can tell a price-scraper from a customer on day one rather than day five.

Built from the same work

This census is a by-product of running Fetchgate — a real x402 + MCP storefront. The paid datasets come from the same crawling and reconciliation work:

Get the census JSON — free