Deploy the Benson edge Worker on Cloudflare
An optional Cloudflare Worker in front of a custom store that sees AI agents that never run JavaScript. Deploy it with wrangler, then verify.
The Benson snippet sees every shopper whose browser runs JavaScript. Some AI agents and scripts only fetch pages, so they never run it. If your store's DNS runs through Cloudflare, a small Worker on your own Cloudflare account can see them: it classifies each request before it reaches your store, passes the request through unchanged, and reports agent and automation traffic to Benson. These are the same steps as Site settings → Edge (Cloudflare) in your dashboard.
Before you start#
- A custom store (WooCommerce, Magento, BigCommerce behind your own proxy, headless or custom) on a plan that includes the edge detector.
- Your store's DNS record is on Cloudflare and Proxied (orange cloud). DNS-only records bypass Workers.
- Node.js on the computer you deploy from, so
npx wranglerruns.
Shopify-hosted storefronts, including custom domains pointed at Shopify, can't run a merchant Worker. Shopify stores are covered by the Benson app and pixel instead.
1. Check your domain#
In Site settings → Edge (Cloudflare), choose Check. Benson fetches your homepage and looks for Cloudflare's response headers (cf-ray, server: cloudflare). If it doesn't find them, move your DNS to Cloudflare with the record proxied, then check again.
2. Create a secret#
Choose Create secret. The Worker signs everything it sends Benson with this secret. Benson shows it once: copy it somewhere safe until you've run step 3. Benson only keeps it encrypted and never shows it again.
3. Deploy with wrangler#
Download bundle.zip from the same page and unzip it. It holds your wrangler.toml (your Worker name, route and site key already filled in), the Worker file, and a README. The secret is never in the zip. In that folder, run:
npx wrangler login
npx wrangler secret put BENSON_EDGE_SECRET
Paste the secret from step 2 when wrangler asks for it.
npx wrangler deploy
There's no one-click "Deploy to Cloudflare" template: you deploy the bundle with wrangler, on your own account. Benson never holds your Cloudflare credentials.
4. Set the route to Fail open#
In the Cloudflare dashboard, open Workers Routes for your domain, edit the Benson route, and set Request limit failure mode to Fail open (proceed). If the Worker ever can't run (for example, the free plan's daily request limit), Cloudflare then serves your store directly.
The Worker also fails open on its own: if Benson is slow or unreachable, or anything in the Worker goes wrong, your store's response is returned unchanged.
5. Verify#
Back in Benson, choose I've deployed it, then open your store in a new tab. The Worker checks in on its first request and the page turns Active, usually within seconds.
What the Worker does#
- Classifies each request: verified signed agents (Web Bot Auth), Cloudflare-verified AI bots, AI agent user agents, and automation fingerprints. Search engine crawlers are counted, never reported as agents.
- Reports agent and automation requests, plus a per-minute request count, to Benson. People's requests are never sent. No IP address is read into anything Benson stores.
- Optional: answers
/.well-known/agent-offers.jsonon your domain with your agent offer feed, rate-limits promo paths (cart, discount) for agents and scripts only, and can add the Benson snippet to pages that don't have it. Turn these on in Worker settings.
Update the Worker#
When the dashboard shows Update available, download the new bundle.zip and run npx wrangler deploy in it. Your secret and route stay the same.
Rotate the secret#
Choose Rotate secret. The old secret keeps working for 24 hours. Run npx wrangler secret put BENSON_EDGE_SECRET with the new one before then.
Turn it off#
Disable in the dashboard makes the Worker pass every request straight through within a minute. To remove it completely, delete the route and the Worker in Cloudflare (or run npx wrangler delete).
Troubleshooting#
- Still "Listening" after a few minutes: check the route pattern matches the hostname shoppers visit, for example
shop.example.com/*. Traffic to other hostnames never reaches the Worker. - Route not set to Fail open: Workers Routes → edit the route → Request limit failure mode → Fail open.
- Secret mismatch: run
npx wrangler secret put BENSON_EDGE_SECRETagain with the secret from step 2, thennpx wrangler deploy. Lost it? Rotate it in the dashboard. - Zone not proxied: in Cloudflare DNS, the store's record must be Proxied (orange cloud).
- Cached pages: Cache Rules that serve responses before Workers run hide those requests from the Worker.
Stuck? Email [email protected].

