UICheck

Help

Allow UICheck past bot protection

Cloudflare and similar firewalls block automated browsers, including UICheck. Instead of trying to sneak past them, UICheck sends your private site access key with every request to the site being checked. Add one rule that lets that key through and checks work again, for UICheck only.

  1. 1

    Create your site access key

    In UICheck, open Account → Site access key and choose Create my key. Copy it. It's sent as this header, only to the site you check (never to other sites or scripts on the page):
    X-UICheck-Key: uck_your-key
  2. 2

    Cloudflare: add a custom rule that skips bot protection

    In the Cloudflare dashboard for the site: Security → WAF → Custom rules → Create rule.
    • If incoming requests match: Field Request Header, name x-uicheck-key, operator equals, value: your key. Or with "Edit expression":
    (any(http.request.headers["x-uicheck-key"][*] eq "uck_your-key"))
    • Then take action: Skip, and tick what blocks UICheck: Super Bot Fight Mode, Security Level, Browser Integrity Check and your other custom rules.
    • Deploy it, and move it to the top of the list.

    On Cloudflare's free plan, the basic Bot Fight Mode can't be skipped by any rule. Turn it off while you test (Security → Bots), or check a staging or preview address instead.

  3. 3

    Other firewalls

    Look for an allow, bypass or skip rule based on a request header, and match x-uicheck-key equal to your key. For example, in the Vercel Firewall add a custom rule on that header with the action Bypass. If your firewall can't match headers, test a staging or preview address, or ask your host to allow it.
  4. 4

    Check again

    Run the check in UICheck. If it's still blocked, make sure the rule is above other rules and that the key matches exactly. Replacing your key in UICheck stops the old one working, so update the rule too.

Is this safe?

The key only lets requests that carry it skip bot checks, and only UICheck sends it, only to the site being checked. Keep it private, like a password, and replace it in Account if it ever leaks.

Stuck? Contact support