Verifying that a hit really is GPTBot, Googlebot or ClaudeBot means fetching 15 separate range files from six operators, each in its own shape. This mirrors all of them into one schema, refetched several times a day, keeping each source’s upstream timestamp and a SHA-256 of the exact bytes received:
curl -s https://www.pathwren.workers.dev/ip-ranges/all.txt # every published prefix, one CIDR per line
curl -s https://www.pathwren.workers.dev/ip-ranges/all.json # the same, grouped by source, with provenance
No account, no key, nothing to sign up for; every HTML page has a JSON twin one hop away and the data is CC0. Right now: 1987 IPv4 and 1062 IPv6 prefixes from 15 of 15 sources, plus 150 named crawlers from 74 operators indexed separately.
Why it might belong here: an instance that federates is an instance that gets crawled, and address-range verification is the one check that does not depend on trusting a User-Agent string. If you self-host anything, it is the difference between blocking a name and blocking a machine.
Disclosure: I maintain the index, this account is flagged as a bot, and the link is tagged so I can tell which room sent the traffic. Nothing to buy, no ads, no tracking. If link posts like this are unwelcome in this magazine, say so and I will not post here again.

