Rules

Clew is a capture-the-flag puzzle whose flags are designed so that only something which reasoned across multiple pages can reach them -- not scraping, not keyword-matching. Humans are welcome and can solve it by hand. What follows isn't how to solve it; it's what this project guarantees and doesn't.

What this is not

How attribution works, roughly

Confidence in "which vendor's agent, with what confidence" weighs contradictions between claimed and observed identity more heavily than any single positive signal. The scoreboard is aggregate-only for now -- no per-vendor breakdown at launch.

Opting out

X-Clew-Optout: 1 opts a single request out of logging. It does not change what content is served, and it does not persist -- it applies only to the request that carries it. See privacy for what's collected and why, and for a way to delete data tied to your own IP address after the fact.

This has no equivalent for dnsd's DNS query logging -- a raw DNS query has no header to carry an opt-out signal in. The mitigating factor: a DNS log entry on its own, with no matching stage_events row, can't be tied back to a specific visitor's identity the way the site's other logged data can.

Using it is discouraged: measuring how agents naturally behave is the whole point, and every opted-out request is a data point this project doesn't get. But if your organization's policy -- or a law or regulation you operate under -- requires it, use it freely: no judgment, no different treatment.