Overview
GPT-Actions is retained as an observed detection pattern associated with GPT Actions.
OpenAI’s current crawler documentation states that ChatGPT users may interact with external applications through GPT Actions, but it documents ChatGPT-User for certain user-triggered web visits and does not publish GPT-Actions as a separate verified fixed HTTP User-Agent.
Do not treat the string GPT-Actions alone as proof of OpenAI origin.
Identity
- User-Agent
GPT-Actions- HTTP Agent Examples
GPT-Actions- Robots.txt Token
GPT-Actions- Identity Type
- Observed
- Evidence Method
- Treat `GPT-Actions` as an observed string only. Use current OpenAI documentation and network/authentication evidence for any request that claims OpenAI origin.
Classification
- Type
- AI
- Kind
- Agent
- Family
- OpenAI
- Purpose
- ai-assistant
Behavior and handling
- Common Use
- Observed/historical detection pattern associated with GPT Actions integrations; current first-party crawler documentation uses ChatGPT-User for certain user-triggered web visits.
- Detection Notes
- Current OpenAI documentation references GPT Actions as a capability but does not publish a separate `GPT-Actions` crawler User-Agent. Preserve the string only for log matching pending stronger evidence.
- Respects robots.txt
- Unknown
- Spoofing Risk
- High because the standalone string is not a current first-party authenticated identity and can be copied trivially.
- Risk
- Neutral
- Recommended Handling
- Depends
Rules and controls
- Robots.txt Snippet
# Observed pattern only; do not rely on this as a current verified OpenAI robots token.