Skip to main content

Grant Bot Management permission

Fix the 'API token lacks Bot Management → Edit permission' warning so AI crawlers can access your site.

If you see a warning saying your API token lacks Bot Management → Edit permission, your Worker deployed successfully, but MakerWrite couldn't unblock AI crawlers (like GPTBot or ClaudeBot) on your domain. This guide walks through granting the missing permission.

Why this happens

To let AI crawlers reach your site, MakerWrite needs to adjust your Cloudflare Bot Fight Mode and Bot Management settings on your behalf. This requires your API token to include the Bot Management → Edit permission. If the token you provided during setup doesn't include it, Cloudflare rejects the change and your site remains blocked to AI crawlers.

Add the permission to your token

  1. From your Cloudflare dashboard, go to Manage Account → API Tokens (this is the Account API Tokens page — distinct from the personal tokens under your user profile).
  2. Find the token you used to connect your site and click it to edit.
  3. Click + Add policy to open a new Edit policy panel.
  4. Change the scope dropdown from Entire Account to All Domains — Bot Management is a domain-level permission and won't show up under the account-wide scope.
  5. In the permission search box, search for Bot Management and check Edit next to it (this also grants Read).
  6. Click Continue to summary, then Update Token.

If you'd rather create a fresh token, it needs two separate policies: an Entire Account policy with Workers Scripts (Edit), Workers Routes (Edit), DNS (Edit), and Zone (Read); plus an All Domains policy with Bot Management (Edit).

Re-check your permission status

Granting the permission on the token itself isn't enough — MakerWrite needs to re-run the check with the updated token:

  1. Go to Settings → Cloudflare in your dashboard.
  2. On the AI Crawler Access card, click Check permissions.

This re-verifies AI crawler access immediately using your saved credentials — no need to re-enter your token. If the permission was added correctly, the badge switches to Allowed and the warning banner disappears. If it still shows blocked right after granting the permission, wait a few seconds and click Check permissions again — Cloudflare's settings can take a moment to propagate.

Still blocked?

If AI crawlers are still blocked after granting this permission and checking again, the cause is usually Bot Fight Mode or a Block AI Bots rule enabled directly in your Cloudflare dashboard, rather than a missing token permission. Turn those off under Security → Bots for your domain, then click Check permissions again.