When you set up a Depra AI project for your own site, DepraBot checks whether the site is an online store. If it is, DepraBot reads the store's product list, so Depra AI knows which products are yours. DepraBot is the web reader behind Depra AI.
A Depra AI app for Shopify is coming to the Shopify App Store. When it is listed, it will read your products, collections and store pages. Until then, setup needs no Shopify app and no access token. This page says what DepraBot asks your store for, how often, and how to allow or block it.
Note: Depra AI never changes a store. DepraBot only reads.
How does Depra AI read a store's product list?
How DepraBot reads the list depends on the platform your store runs on. It asks the platform's product API first. An API is an address that returns data for software to read. If no API lists products, DepraBot reads the store's sitemaps.
| Store | What DepraBot asks for |
|---|---|
| On Shopify | The Shopify Storefront API on the store's own myshopify.com address, without an access token. Then /products.json, when the Storefront API did not return the full list. |
| Not on Shopify | The WooCommerce Store API, at /wp-json/wc/store/v1/products. |
| No API lists products | The store's sitemaps, then up to 3 product pages listed in them. |
A sitemap is the file in which a site lists its pages. To learn whether a store runs on Shopify, DepraBot asks for /meta.json, and then for /.well-known/ucp if needed.
In what order does DepraBot ask for files?
One scan asks for these files, in this order, and skips the ones that do not apply.
- 1.robots.txt: for its rules and the sitemaps it names.
- 2./meta.json, then /.well-known/ucp if needed: to see whether the store runs on Shopify.
- 3.The Shopify Storefront API: on the store's own myshopify.com address, without an access token.
- 4./products.json: on a Shopify store, when the Storefront API did not return the full list.
- 5.The WooCommerce Store API: on a site that is not on Shopify.
- 6.The store's sitemaps: when none of the APIs above lists any products.
- 7.Up to 3 product pages: listed in those sitemaps.
- 8.The homepage: only when nothing above shows that the site sells products.
What are the limits of one scan?
Every scan stays inside these limits.
| Limit | Value |
|---|---|
| Files asked for | At most 80 in one scan, not counting robots.txt |
| Request rate | At most one request a second to any host |
| Time | No new request starts after 2 minutes |
| Redirects | At most 3 per file |
| Download size | At most 3 MB of a page, 2.5 MB of a JSON file and 10 MB of a sitemap |
| Product pages | Up to 3, taken from the sitemaps |
| Scans at once | Only one scan runs for a project at a time |
| Headless browser | Never used. A headless browser loads a page with its scripts, the way a normal browser does. |
When does a scan run?
A scan runs at three moments: at setup, once a week, and when someone starts one with Fetch.
- At setup: when you set up the project for your site.
- Once a week: scheduled between 00:30 and 02:30 UTC, which is 06:00 to 08:00 in India. The weekly scan does not run if you have told Depra AI that you do not sell products.
- With Fetch: when someone at your brand starts a scan with Fetch.
| Plan | Fetch scans per project per day |
|---|---|
| Starter | 3 |
| Growth | 3 |
| Scale | 5 |
| Enterprise | 5 |
What if robots.txt blocks DepraBot?
DepraBot obeys robots.txt, the file that tells bots what they may read. If your robots.txt keeps DepraBot out, a scan reads nothing past robots.txt itself. You can upload your product list as a file instead.
If your robots.txt answers with a server error, or does not answer at all, DepraBot treats the whole site as disallowed and comes back later. The one exception: if it read the file successfully in the previous 24 hours, it keeps using that copy.
Warning: DepraBot uses no proxies and never disguises itself. A firewall or bot filter may answer it with a 403 or 429 error, or with a challenge page that asks the visitor to prove it is human. DepraBot records each of these as a block.
How do I allow DepraBot in robots.txt?
Add a group for DepraBot to your robots.txt. A group is a User-agent line with the rules under it. DepraBot looks for a group named DepraBot first, then the group for all bots, which is marked with a star. Under the robots.txt standard, a bot obeys the group that names it and falls back to the star group only when no group names it (RFC 9309, checked 7 Oct 2026). So the DepraBot group decides, even when the star group blocks everything.
User-agent: DepraBot
Allow: /The user agent token, the name robots.txt rules use for a bot, is DepraBot. Every request carries the user agent string DepraBot/1.0 (+https://depra.ai/about-bot). DepraBot obeys robots.txt as written in RFC 9309. It also honours a Crawl-delay line, which asks a bot to wait between requests, of up to 10 seconds.
To keep DepraBot out, use Disallow in the same group.
User-agent: DepraBot
Disallow: /DepraBot re-reads robots.txt within six hours, so a change takes effect within that time. If you want DepraBot kept out and cannot change robots.txt, email team@depra.ai with your domain. The team will add it to the exclusion list.
What does DepraBot never read?
A store scan stays on your own store. It never reads the following.
- Other sites: it reads only your own site, its subdomains and the store's own myshopify.com address.
- A myshopify.com address typed into Depra AI: it is asked only for its robots.txt and /meta.json, unless that file names your site.
- Redirects to another site: they are not followed.
- Marketplaces and social sites: a marketplace or social site entered as a brand's website gets no request at all.
- Anything behind a login: DepraBot does not sign in, fills in no forms and uses no access token. It cannot read orders or customers.
- Images and media: no images, media, fonts, scripts or stylesheets are requested.
- Pages robots.txt disallows: DepraBot obeys robots.txt for every page and file it asks for.
Nothing DepraBot reads is used to train AI models, and nothing is republished. The full policy is on About DepraBot.