Every request carries our user agent and a Web Bot Auth signature (RFC 9421, Ed25519) that sites and Cloudflare can check against the bot's key directory.
Before visiting a site, the bot reads its robots.txt, keeps it for at most 24 hours and obeys the rules for its own name and for *, including Crawl-delay.
At most one request per second to a site. A 429 or 503 answer stops visits to that site for the time it asks, or for 10 minutes if it does not say.
No logging in, no paywall or challenge bypassing, no CAPTCHA solving.
Content is never used to train models.
Checking a request
Each bot signs its requests with its own Ed25519 key, published in its own key directory. The Signature-Agent header names the bot's origin; the directory sits at that origin under /.well-known/http-message-signatures-directory.