All posts

Is your shop turning ChatGPT away at the door?

Published 9 October 2026 5 min read

Two settings can stop ChatGPT's search robot reading your shop: robots.txt and the firewall. How to check both today, and what to leave blocked.

Two doors between ChatGPT and your shop

Before ChatGPT can recommend a product from your shop, it has to be able to read the page. Before it answers a buyer, it searches the web, and OpenAI runs a separate robot to fetch pages for that search. It's called OAI-SearchBot.

That robot has to get through two doors on your site. The first is robots.txt. The second is the firewall, the protection that keeps harmful bots out. If either one says no, your product pages don't exist for ChatGPT search, however good they are. You won't get a message about it.

OpenAI puts it plainly: to be eligible for ChatGPT search results, a site must allow OAI-SearchBot. A site that turns it away can still appear, but in OpenAI's words as “just the link and page title”.

Which of OpenAI's robots matter

OpenAI runs three robots, and each does a different job. It's easy to block the wrong one.

  • OAI-SearchBot reads pages for ChatGPT search. Whether your products can appear in answers depends on it. Let it in.
  • ChatGPT-User opens a page when someone's chat needs it, for example when a buyer pastes a link to your product. OpenAI says it isn't used to decide what appears in search, and that robots.txt rules may not apply to it.
  • GPTBot collects pages that may be used to train OpenAI's models. Blocking it does not affect search. If you'd rather your product descriptions stayed out of training, blocking it is a fair choice.

Other assistants have their own search robots: Perplexity has PerplexityBot, and Anthropic's Claude has Claude-SearchBot. Buyers ask those assistants too, so if you let ChatGPT in, it makes sense to let them in as well.

Door one: check robots.txt

robots.txt is a small public file that tells robots which pages of your site they may read. It always sits at the same address, and you can open it in a browser like any page. These two lines shut every robot out of the whole shop:

User-agent: *
Disallow: /
  1. Type your shop's address followed by /robots.txt, for example yourshop.com/robots.txt.
  2. Look for the line User-agent: OAI-SearchBot. If the lines under it include Disallow: /, ChatGPT's search robot is shut out of the whole shop.
  3. Look for User-agent: *, which means “every robot”. If Disallow: / sits under it and no separate group names OAI-SearchBot, the shop is closed to it too.
  4. Read the other Disallow lines in those groups. A line like Disallow: /product/ closes every address that starts that way, which may be all your product pages.
  5. An empty Disallow:, with nothing after the colon, blocks nothing. That one is fine.

If you find a block nobody meant to put there, remove it, or ask whoever builds your site to. On Shoper, IdoSell or Shopify the file is usually set up by the platform, so its settings or support will tell you how to change it. OpenAI says changes to robots.txt take about 24 hours to reach ChatGPT search.

Door two: check your bot protection

robots.txt is a polite request. A firewall is a guard: it turns visitors away before they reach the page. Many shops sit behind one, from Cloudflare or a similar service, or from their hosting company. It can block ChatGPT's robot even when robots.txt lets it in. The robot then gets an error such as 403 (access denied) instead of your page.

OpenAI asks sites to make sure their host or CDN (the network that delivers the site to visitors, such as Cloudflare) allows traffic from OAI-SearchBot's published IP addresses.

Since July 2025 Cloudflare asks every new domain whether to allow AI crawlers. Its block aims at robots that collect for training, assistants and archives. ChatGPT's search robot sits in a separate group, AI Search, which Cloudflare has left allowed by default since 15 September 2026. So if it's blocked on your site, someone blocked it by hand, or an older rule is still doing it.

  1. If you use Cloudflare, open your domain's bot and AI crawler settings and find OAI-SearchBot on the list. Make sure it's allowed. GPTBot can stay blocked if you prefer.
  2. Look through any custom firewall rules too. A rule written years ago to stop “all bots” may catch it.
  3. If your hosting company or shop platform handles security for you, ask them one question: “Do you let OAI-SearchBot in from OpenAI's published IP addresses?”

Being let in is only the start

An open door doesn't make ChatGPT recommend you. It only means ChatGPT can read you. Much of what decides lies off your own site: links from other sites, and a place in the rankings and comparison sites that ChatGPT's searches turn up.

So fix a block the day you find it. Then look at what ChatGPT finds about your shop everywhere else.

Want to see it for your shop?

Monitoring reads what your site tells the assistants' robots, and then what the assistants answer.

Sign up, describe your shop, and choose the buyer questions to ask and the AI assistants to ask them of. Each question is asked three times for a baseline report, usually ready within the hour, then again on the days you choose, with every answer kept word for word.

Your site is read again at every check, and we email you if it starts shutting ChatGPT's robots out.

Start monitoring From $9 a month.

Sources