AI crawler・agent trafficを識別し、許可・課金・検証する
最終確認: 2026-08-02
対象: 自分の Web site、API、MCP server、machine-readable data へ来る automated traffic を、検索流入・権利・安全性を壊さず事業判断したい個人開発者
この章は技術・事業・計測の一般的な教材であり、法律、税務、会計、金融規制、著作権、暗号資産その他の個別助言ではない。provider の提供地域、plan、招待、preview、API version、手数料、規約は変わる。live 化する主体・商品・国・決済 rail について、実行時点の公式資料と必要な専門家へ確認する。
本文、pack、SQLite companion の ID、主体、resource、件数、金額、期間、結果は完全な架空例であり、実績、予測、需要、価格、成功率、外部 benchmark ではない。
この章の役割
Section titled “この章の役割”10 章は platform と agent 委任、17 章は AI 面への掲載から履行・銀行着金、19 章は小標本の因果判断を扱った。本章は 自分の入口へ届いた machine request を対象にする。
request → traffic purpose → actor identity evidence → resource / rights → current policy → free | limit | block | license | authenticate | quote → authorization → settlement → entitlement → delivery → cash / reversal / cost → maturity → decision付属物は次の二つである。
- machine traffic monetization pack: 判断契約、program snapshot、resource・rights、identity、policy、offer、payment、delivery、cash、risk、週次判断を複製できる 14 書式。
- SQLite companion: User-Agent だけの本人確認、human/search への誤課金、settlement 前 delivery、replay、二重計上、rights
UNKNOWN、未成熟 cash を fail closed にする完全架空の参考実装。
章、書式、event、decision snapshot は machine_access_contract_id で相関する。この文字列自体に権限はなく、opaque ID と version の組を正本で管理する。
SQLite companion の economics 集計は per-request paid access に限定する。license allocation、AI referral contribution、cannibalization が contract 上必要なら別の authoritative ledger と reconciliation を追加し、未実装のままゼロ扱いせず最終 KPI を UNKNOWN にする。付属 fixture の数値は実績、価格、需要、包括利益ではない。
- HTTP 402 は収益モデルではない。 現行 HTTP Semantics で
402 Payment Requiredは reserved であり、status code だけでは challenge、支払方法、検証、settlement、refund、権利を定めない。RFC 9110 §15.5.3 - 「AI bot」を一分類にしない。 search/index、training、live retrieval、user-triggered fetch、browser agent、API/MCP、unknown automation は近接価値も制御も違う。
- User-Agent は本人確認ではない。 UA は自己申告であり spoof できる。署名、credential、provider の公式 IP/rDNS、検証主体、時刻、失敗理由を別 evidence にする。
- robots、identity、authorization、payment、rights は別の面である。 robots.txt は crawler への規則であり access authorization ではない。RFC 9309
- 検索 discovery と premium delivery を分ける。 公開 landing page や引用可能 preview を一律 402 にせず、価値・原価・権利が明確な API、tool action、fresh data、machine-readable derivative を狭く商品化する。
- challenge を売上にしない。
402 → authorization → verified settlement → entitlement → accepted delivery → reversal maturity → cash reconciliationを通した一件だけを管理上の貢献へ入れる。 - primary KPI は成熟後の増分 net machine contribution である。 crawl 数、block 数、quote 数、wallet submission、gross payment を事業成果へ置換しない。
- 14 日で search の長期効果を断定しない。 search crawler は維持し、shadow 計測から、低リスク resource、test mode、上限付き live へ進む。
- 自動支払いは信頼を代替しない。 支払意思があっても、危険な action、許諾外利用、機密 data、identity 不明を許可しない。
- 現在のこの公開サイトには 402 や新しい block を有効化しない。 本章の release は知識・書式・検証 model の追加であり、実 traffic policy の変更ではない。
六つの問いを順番に解く
Section titled “六つの問いを順番に解く”| 問い | 正本 | 未確認時の扱い |
|---|---|---|
| 誰の request か | signature、API credential、公式 IP/rDNS、検証 provider | UNKNOWN |
| 何をしようとしているか | observed request、declared purpose、behavior tag、route | 推測を事実にしない |
| その resource を売れるか | ownership、license、customer contract、data provenance | live 課金を PAUSE |
| 何を許可するか | traffic_policy_id / policy_revision と exact action |
default deny または既存 free policy 維持 |
| 支払・配信は成立したか | challenge、proof、settlement、entitlement、delivery receipt | 売上・履行に数えない |
| 利益と長期価値が残るか | cash、reversal、variable cost、referral control、maturity | UNKNOWN / INCONCLUSIVE |
下流の成功を上流へ逆流させない。たとえば paid request が一件あっても、その UA 全体が verified になったわけではない。settlement が成功しても、再配布や training の権利を自動付与しない。引用 referral が増えても、特定 crawler の crawl が原因と断定しない。
traffic と resource を直交分類する
Section titled “traffic と resource を直交分類する”traffic purpose
Section titled “traffic purpose”一つの actor が複数 purpose を持つ場合があるため、排他的な bot_type 一列に押し込まない。HUMAN_BROWSER / SEARCH_INDEXER / AI_SEARCH_RETRIEVAL / AI_TRAINING / USER_TRIGGERED_AGENT / AUTHENTICATED_API_CLIENT / UNKNOWN_AUTOMATION / MALICIOUS_ABUSE の actor class と、business_channel、複数の behavior_tags[]、それらの source/version を別に持つ。次表は business channel / behavior の分類である。
| traffic class | 目的 | 近接価値 | 基本仮説 |
|---|---|---|---|
HUMAN_AI_REFERRAL |
AI 回答等の link から人が訪問 | 登録、購入、広告、信頼 | 通常の human として allow・計測 |
SEARCH_INDEX |
search/RAG index の作成 | 将来の発見、引用、referral | verified なら public resource を free allow |
TRAINING_COLLECTION |
training、fine-tune、dataset 作成 | license 価値、代替・権利 risk | observe 後に allow / block / license |
LIVE_RETRIEVAL |
回答生成時の取得・grounding | 即時の引用可能性 | public preview は allow、premium は meter |
USER_TRIGGERED_FETCH |
人の依頼に基づく取得 | 購買意図・task completion | verified・低原価なら allow、premium は auth |
BROWSER_AGENT |
閲覧、入力、予約、購入等 | task outcome | read/write、scope、consent、limit を分離 |
API_MCP_TOOL |
API/RPC/tool execution | accepted action、structured output | principal 認証、quota、idempotency、課金 |
UNKNOWN_AUTOMATION |
自己申告・偽装・不明な自動化 | 原価・abuse の可能性 | rate limit / challenge / block、需要に数えない |
OpenAI は search 用 OAI-SearchBot、training 用 GPTBot、user action 用 ChatGPT-User を分けている。OpenAI crawler documentation Anthropic も Claude-SearchBot、ClaudeBot、Claude-User を分ける。Anthropic crawler guidance Perplexity は PerplexityBot と user-triggered Perplexity-User を分け、後者の robots の扱いも明記する。Perplexity crawler docs
名前から別 provider の挙動を推定しない。Google-Extended は独立した UA ではなく、Googlebot が取得する data の一部利用を制御する token で、Google Search の inclusion/ranking control とは別である。Google common crawlers
resource class
Section titled “resource class”traffic class だけで action を決めない。同じ verified agent でも、marketing page と顧客 data では policy が違う。
companion SQL では安定した上位 class を PUBLIC_MARKETING / PREMIUM_CONTENT / API_COMPUTE / TOOL_ACTION / CUSTOMER_DATA とし、次表の細分類を resource subtype として保持する。たとえば discovery/full content は PUBLIC_MARKETING、machine derivative/fresh data は契約に応じて PREMIUM_CONTENT、compute は API_COMPUTE、write は TOOL_ACTION、private data は CUSTOMER_DATA へ写像する。秘密・安全上重要な資産は課金対象へ入れない。
| resource class | 例 | default の出発点 |
|---|---|---|
PUBLIC_DISCOVERY |
landing page、docs index、引用用 summary | free allow、検索・referral 計測 |
PUBLIC_FULL_CONTENT |
公開記事、manual | allow / rate limit / training control を検討 |
MACHINE_DERIVATIVE |
JSON、CSV、clean markdown、structured excerpt | narrow offer の候補 |
FRESH_DATA |
更新頻度が価値の feed、監視結果 | subscription / per-call / license 候補 |
COMPUTE_ACTION |
search、transform、generation、validation | accepted unit と原価で meter |
WRITE_ACTION |
form 入力、予約、設定変更、注文 | auth、consent、scope、idempotency が先 |
CUSTOMER_PRIVATE |
account data、非公開 document | customer entitlement 以外は deny |
SECRET_OR_SAFETY_CRITICAL |
credential、admin、security artifact | payment に関係なく deny |
rights は resource version ごとに持つ
Section titled “rights は resource version ごとに持つ”resource_contract_id / resource_revision:canonical_uri / content_hash:owner / commercial_owner:source / third_party_components:permitted purposes: index: quote: live retrieval: training: derivative: redistribution: retention:territory / term / attribution:customer or contributor restrictions:rights_state: PASS | FAILED | UNKNOWN | N/Aevidence / reviewed_at / recheck_at:FAILED は rights gate の結果で、STOP はその結果を受ける decision state と分ける。HTTP payment は著作権 license そのものではない。金額を払った事実から training、再配布、derivative、永久保存の許可を推定しない。日本で AI と著作権を扱うときは、文化庁の資料を入口に個別事実を確認する。文化庁 AI と著作権
identity の信頼階層
Section titled “identity の信頼階層”evidence を一列の boolean にしない
Section titled “evidence を一列の boolean にしない”| level | evidence | 許される主張 | 許されない昇格 |
|---|---|---|---|
| A | API key/OAuth、mTLS、検証済み HTTP signature | credential principal または署名者を検証した | end-user consent、purpose、権利、payment 済み |
| B | UA + 公式 IP/CIDR、forward-confirmed rDNS | 公式資料と network evidence が整合 | 個別 request の委任・契約 |
| C | UA/self-declared name のみ | その文字列を観測した | verified operator、需要 |
| D | behavior/fingerprint 推定 | automation の可能性 | provider identity、支払意思 |
課金の verified eligible 分母は原則 A とし、program が B を正規の verification とする場合だけ source snapshot と限界を明示して含める。C/D の request 数は abuse・capacity 診断には使えるが、buyer demand、conversion 分母、price acceptance に使わない。
Web Bot Auth の境界
Section titled “Web Bot Auth の境界”HTTP Message Signatures 自体は RFC 9421 の Proposed Standard である。RFC 9421 一方、automated traffic の Web Bot Auth protocol は 2026-08-02 時点で active な個人 Internet-Draft で、IETF の承認済み標準ではない。Web Bot Auth Internet-Draft
署名検証は、covered component、key、時刻等の整合を示す。次は別に確認する。
- signer が customer のために行動する authorization。
- request の business purpose。
- resource の利用権と再利用範囲。
- state-changing action への user consent。
- payment proof と settlement。
- replay、nonce、expiry、key revocation。
複数署名があっても委任 chain が自動的に成立するわけではない。payment credential と bot identity signature の nonce を混用しない。
robots.txt は authorization ではない
Section titled “robots.txt は authorization ではない”Robots Exclusion Protocol は crawler への取得規則であり、resource access authorization ではない。RFC 9309 も security measure の代替でないことを明確にする。秘密 URL、顧客 data、有料 data は authentication と entitlement で守る。
robots.txt、meta/directive、provider content signal は次の用途に限る。
- public resource に対する crawling/indexing/training preference の伝達。
- provider ごとの policy との整合。
- policy revision と取得結果の観測。
Content Signals for AI Preferences は work in progress として提出された individual Internet-Draft だが、2026-08-02 時点では失効している。成立済みの普遍標準・契約・法的許諾として扱わない。Content Signals draft
control plane を分ける
Section titled “control plane を分ける”action mode
Section titled “action mode”| action | 意味 | 主な利用場面 |
|---|---|---|
ALLOW_FREE |
無償で delivery | public discovery、verified search |
MEASURE_ONLY |
現行 response を変えず分類・原価計測 | 最初の shadow period |
RATE_LIMIT |
上限内で delivery | 高頻度・identity 弱い取得 |
SECURITY_CHALLENGE |
bot/security challenge。payment challenge ではない | identity 不明、abuse 疑い |
BLOCK |
delivery を拒否 | abuse、secret、rights failed |
CONTRACT_LICENSE |
相対契約の entitlement で許可 | training、bulk archive、特殊権利 |
HTTP_402 |
compatible client へ payment challenge | 狭い premium machine resource |
AUTHENTICATED_API |
API key/OAuth、quota、invoice/subscription | 継続 buyer、API/MCP/tool |
SERVE_ENTITLED |
current entitlement を検証して delivery | license/subscription/payment 済み retry |
PAUSE |
現行 free policy 維持または safe deny で調査 | rights/identity/settlement 不明 |
decision と action を混ぜない。たとえば INCONCLUSIVE は証拠に関する判断で、resource の access action ではない。decision の優先順は次とする。
STOP > PAUSE > UNKNOWN > INCONCLUSIVE > CHANGE > MAINTAIN > EXPANDpolicy resolution
Section titled “policy resolution”traffic_policy_id / policy_revision:machine_access_contract_id / contract_version:environment: SYNTHETIC | SANDBOX | LIMITED_LIVE | LIVEaccounting_environment: TEST | REALtraffic class / behavior tags:identity minimum / accepted methods:resource_contract_id / revision:request method / route / purpose:action mode:rate / quota / price book:required entitlement:fallback / cache behavior:effective_from / effective_until:loss cap / kill switch:owner / reviewer / evidence:解決順の一例は kill switch / secret / rights FAILED → human safety → current entitlement → verified search free → contract license / authenticated API / paid machine route → security challenge / rate limit → unknown deny である。rights gate の FAILED は decision の STOP を強制する。MEASURE_ONLY は response を変えない横断 mode とし、実装時はそれ以外の一 request に一つの authoritative terminal action を返す。複数 rule の偶然の順番へ依存させない。
provider の control と自社正本を分ける
Section titled “provider の control と自社正本を分ける”edge dashboard は便利だが、provider classification、sampling、retention、UI label が変わり得る。保存するのは raw credential でなく、次の source snapshot と request receipt である。
provider / product:documentation URL / retrieved_at:program_status: CURRENT | PREVIEW | INVITE_ONLY | DEPRECATED | UNKNOWN | FAILEDprovider display stage: GA | BETA | CLOSED_BETA | PREVIEW | WAITLIST | CONTACT_SALES | UNAVAILABLE | UNKNOWNaccount / region / plan eligibility:config or ruleset version:identity method / known limitation:available metrics / sampling / retention:pricing / fee / payout owner:API/schema version:superseded_at / recheck trigger:2026-08-02 の product・protocol 地図
Section titled “2026-08-02 の product・protocol 地図”HTTP 402 を使うという一点だけで相互運用できるとは限らない。header、body、payment rail、facilitator、identity、settlement、receipt が違えば別 contract である。
| 選択肢 | current position | seller / resource 側の特徴 | 主な境界 |
|---|---|---|---|
| Cloudflare Pay Per Crawl | closed beta | verified crawler を Allow / Block / Charge、成功した HTTP 200 を crawl 単位で課金 | Cloudflare 固有 header・pricing・MoR。x402/MPP と同一ではない |
| AWS WAF AI traffic monetization | CloudFront と WAF の current offering | x402、Base/Solana USDC、test mode、WAF rule で対象・倍率を制御 | 対応 client、wallet、数秒の latency、origin 成否、crypto/accounting を要確認 |
| x402 | Linux Foundation 傘下の open protocol | PAYMENT-REQUIRED / PAYMENT-SIGNATURE / PAYMENT-RESPONSE、facilitator を選択可能 |
IETF RFC ではない。network/currency/scheme support は実装ごと |
| MPP / Stripe machine payments | MPP は open protocol、Stripe は crypto / SPT rail を提供 | Payment HTTP authentication draft を基礎に、Stripe object・receipt・refund と接続 |
preview/request access、国・主体・rail・最低額・API version を都度確認 |
| 相対 license | 個別契約 | purpose、期間、量、派生、再配布、retention、監査を交渉 | 自動化が弱いが training/bulk rights を明確にしやすい |
| 通常 API subscription | 広く確立 | API key/OAuth、quota、月額・従量 invoice | onboarding 摩擦はあるが反復 buyer と返金・会計を運びやすい |
AP2 は intent/mandate によって human・agent の権限と監査証跡を表す authorization layer、UCP は商品発見から checkout/order までの commerce layer であり、個別 HTTP resource の 402 rail そのものではない。identity、authorization、commerce、payment の層を補完し得るが、名前に payment や commerce があるだけで置換可能と判断しない。Google AP2 / FIDO / UCP overview
Cloudflare Pay Per Crawl は 2026-08-02 時点で closed beta であり、Cloudflare が Merchant of Record になる。現行 docs は成功した HTTP 200 に最低 $0.001、同じ URL の recrawl も charge、error response は非課金と説明する。標準 402 の普遍実装ではなく、crawler-price、crawler-exact-price、crawler-max-price、crawler-charged 等の product contract を使い、AI owner 向け current docs の protocol 値は cloudflare である。Pay Per Crawl overview / price / crawler flow / FAQ
publisher payout には dashboard から作る専用 Stripe Connect account が必要で、既存 Stripe account は使えない。Cloudflare は charge を集約・照合し good standing の publisher へ月次 payout する一方、current dashboard は accrued balance を表示せず、settlement period と minimum payout threshold の具体値も公開していない。gross crawl charge を当月 bank cash や retained contribution にしない。Pay Per Crawl payouts
AWS WAF の current docs は CloudFront distribution、WAF Web ACL、Bot Control を使い、Coinbase facilitator と x402 の Base/Solana USDC を示す。minimum は $0.001、機能自体の追加料金はないが通常の WAF/Bot Control 費用があり、price multiplier、test mode、payment latency、bot classification の限界を product contract として読む。origin が 2xx の場合に synchronous settlement と receipt が進み、4xx/5xx の扱いを分ける。payment-id を client が使った場合の重複防止窓は最大15分であり、自社の永続 idempotency ledger を代替しない。AWS launch / pricing / request flow
AWS も price と利用許諾を別に扱い、RSL 等で license terms を伝える案を示す。WAF が作る 402 自体にその Link header を自動付与すると仮定せず、resource response と commercial contract を明示する。AWS license terms
x402 V2 は独自 header と payment payload を定義し、exact、upto、batch 等を扱う。open protocol であることと、HTTP status の IETF 標準化は別である。client の予算、human approval、session policy、商業上の refund は core だけで完結しない。x402 HTTP 402 / x402 repository Idempotent retry には payment identifier extension 等を exact version で採用する。payment identifier
MPP は WWW-Authenticate: Payment と Authorization: Payment の形を使うが、基礎となる Payment HTTP Authentication Scheme は 2026-08-02 時点で active な個人 Internet-Draft で、IETF endorsed RFC ではない。Payment HTTP Authentication Scheme Stripe machine payments は crypto と Shared Payment Token の current eligibility、minimum、PaymentIntent、refund、account balance を別に記載する。日本の個人主体が live に使えると推定せず、account で request access と current docs を再確認する。Stripe machine payments / MPP integration
product availability と需要を分ける
Section titled “product availability と需要を分ける”protocol conformance PASS≠ program eligibility PASS≠ buyer client support≠ verified buyer demand≠ payment authorization≠ settlement≠ accepted delivery≠ retained cash≠ positive contributionwaitlist、closed beta、preview、coming soon を current revenue forecast へ入れない。docs にある network や国を、自分の account の live eligibility と同一視しない。
402 challenge contract
Section titled “402 challenge contract”status code だけを返さない
Section titled “status code だけを返さない”Payment authentication Internet-Draft は、支払いが主 barrier で、fulfillable な challenge を構築できる場合に 402 を使い、authentication failure は 401、payment は成功したが policy で拒否する場合は 403 とする案を示す。ただし draft であるため、採用する product/protocol の exact semantics を正本にする。
challenge_id:machine_access_contract_id / contract_version:environment: SYNTHETIC | SANDBOX | LIMITED_LIVE | LIVEaccounting_environment: TEST | REALprotocol / protocol_version:payment_offer_id / offer_revision:resource_contract_id / resource_revision / resource_hash:request method / target / body digest:principal / identity evidence:amount / asset / network / decimals:payment method / facilitator:purpose / rights / entitlement scope:issued_at / expires_at:nonce / single-use rule:idempotency_key / retry window:cache directives:success / failure status mapping:terms / refund / support reference:challenge artifact hash:price は server の再計算結果を使う
Section titled “price は server の再計算結果を使う”client が返す amount、asset、recipient、network、offer revision を信用しない。server は challenge の正本から expected tuple を再構成し、proof と一致させる。
expected = resource_contract_id + resource_revision + payment_offer_id / offer_revision + principal scope + amount / asset / network / recipient + purpose / entitlement + expiry / nonce + request digest where applicable不一致は fresh quote または fail closed とし、都合のよい古い価格、別 resource の proof、別 network の同額、期限切れ quote を通さない。
replay、retry、side effect
Section titled “replay、retry、side effect”- challenge ID、nonce、payment identifier、provider transaction ID は用途を宣言し、一度使った proof の再利用を検出する。
- network timeout で outcome が不明なら、自動再課金せず authoritative status を read back する。
- GET delivery でも同じ proof を無制限に再利用させない。entitlement が複数回取得を許すなら count/term を明示する。
- write action は payment idempotency と business action idempotency を分ける。二重支払い防止だけでは二重注文を防げない。
- response cache が別 principal へ premium body を配らないよう
Vary、private/no-store、cache key を設計する。 - 4xx/5xx、timeout、partial delivery の課金・refund 規則を事前に固定する。
- 402 response body は machine-readable challenge を含み得るため、HTTP response bytes は 0 固定にしない。一方、未決済の protected resource bytes delivered は 0 であることを別 field で検査する。
payment、entitlement、delivery を一段ずつ閉じる
Section titled “payment、entitlement、delivery を一段ずつ閉じる”REQUEST_OBSERVED → CLASSIFIED → POLICY_RESOLVED → QUOTED → AUTHORIZED → SETTLED → ENTITLEMENT_ISSUED → DELIVERY_STARTED → DELIVERY_ACCEPTED | DELIVERY_FAILED → REFUND_OR_REVERSAL_MATURED → CASH_RECONCILED| stage | authoritative evidence | まだ言えないこと |
|---|---|---|
QUOTED |
server challenge/offer revision | demand、payment |
AUTHORIZED |
rail-specific authorization | final settlement、cash |
SETTLED |
provider/network authoritative read | correct delivery、retained cash |
ENTITLEMENT_ISSUED |
internal append-only entitlement | delivery accepted |
DELIVERY_ACCEPTED |
exact resource/action receipt | reversal-free、利益 |
CASH_RECONCILED |
wallet/bank/provider ledger bridge | 将来 refund/rights incident なし |
MATURE |
predeclared reversal/outcome window | 因果的な増分利益 |
delivery gate
Section titled “delivery gate”delivery 前に最低限、次を atomic に近い形で再確認する。
- request と principal が current policy に合う。
- resource revision と rights が current
PASS。 - offer と payment proof の tuple が一致する。
- authoritative settlement が必要状態にある。
- nonce/proof/idempotency が未使用または許可された retry。
- entitlement の scope、期限、量が足りる。
- kill switch、incident、reversal hold が開いていない。
- delivery receipt を一度だけ作り、cash/cost と join できる。
transaction を一 DB に閉じられない外部 rail では outbox/inbox、unique key、read-back、reconciliation job を使う。結果不明を success にしない。
license、subscription、per-request payment を選ぶ
Section titled “license、subscription、per-request payment を選ぶ”| 条件 | free discovery | contract license | API subscription | per-request 402 |
|---|---|---|---|---|
| search/referral が主価値 | 強い | 弱い | 弱い | 弱い |
| training・bulk rights の交渉 | 弱い | 強い | 中 | 弱い〜中 |
| repeat buyer | 中 | 強い | 強い | 中 |
| buyer client の互換性が不明 | 強い | 中 | 中 | 弱い |
| 一回ごとの原価・価値が明確 | 弱い | 中 | 強い | 強い |
| refund、invoice、support が重要 | 弱い | 強い | 強い | rail 依存 |
| onboarding を最小化したい | 強い | 弱い | 中 | 強い可能性 |
training data、archive、再配布、exclusive use は request 数だけで権利を表しにくい。purpose、term、territory、retention、derivatives、attribution、audit、revocation を相対 license にする方がよい場合がある。
継続 API/MCP buyer は、machine payment が技術的に可能でも、通常の account、API key/OAuth、quota、invoice、subscription の方が support、refund、税務、購入稟議、価格差別を運びやすい。402 は buyer の一回取得摩擦を下げる option であって、既存の商流を必ず置き換えるものではない。
個人開発者の優先順位
Section titled “個人開発者の優先順位”- public landing/summary は discovery 用に残す。
- buyer が得る accepted unit を定義する。
- machine-readable derivative、fresh data、bounded compute、tool action の一つを選ぶ。
- authenticated API/subscription または一社 license で支払意思を確認する。
- compatible buyer が実在し、一回課金が onboarding を減らす場合だけ 402 rail を追加する。
- search crawler 全体の一律課金は、referral の成熟証拠と buyer support が揃うまで後順位にする。
unit economics
Section titled “unit economics”primary management metric
Section titled “primary management metric”matured_incremental_machine_contribution= matured paid-access gross from eligible, accepted, cash-reconciled deliveries+ allocated matured license contribution+ incremental matured gross contribution from AI-referred humans- refunds / reversals / fraud / unreconciled delivery loss- unreconciled cash shortfall not already excluded or allocated- seller-borne tax- protocol / facilitator / network / PSP fees- edge / origin / egress / storage / external API / AI variable cost- support and founder rescue minutes × internal hourly value- measured cannibalized contributionこれは管理用 metric で、法定会計利益ではない。positive gross/value だけを accepted + cash-reconciled の成功 gate で限定し、refund、reversal、fraud、fee、variable cost、support/founder time は失敗・離脱・paid-undelivered を含む全 mature eligible cohort から控除する。measured、allocated、estimated を別列にし、推計を実 cash に混ぜない。未照合 cash shortfall は他項目で除外・配賦済みでなければ一度だけ控除し、配賦不能な残差があれば KPI は UNKNOWN とする。未照合 wallet value、将来 LTV、未成熟 renewal、未検証 cannibalization は別欄に置く。
matured contribution per eligible verified request= matured_incremental_machine_contribution / eligible verified requests assigned before cutoff and matured by snapshotsuccessful delivery だけを分母にすると refusal、quote abandonment、payment failure、delivery failure の費用を隠す。principal 単位と request 単位を併記し、一 buyer の大量 request で需要の広がりを誤認しない。
price floor
Section titled “price floor”price_floor(resource_class)= ( expected variable service cost + payment / refund / fraud cost + required contribution + measured risk or cannibalization reserve ) / expected successful settled deliveries架空値や他社平均から price を決めない。static article、fresh data row、accepted tool action、compute second、batch、license term は価値と原価の unit が違う。少額 rail では minimum、network fee、facilitator fee、support 一件の影響が大きい。
free の価値も測る
Section titled “free の価値も測る”paid route と比較する control は必ずしも zero revenue ではない。
- verified search crawl 当たりの AI referral session、qualified outcome、gross contribution。
- public preview から API/license inquiry への assisted conversion。
- citation・discovery を失ったことによる lagged effect。ただし14日で断定しない。
- block/rate limit による origin・egress cost reduction。
- 既存 subscription/API 購入を per-request が置き換えた cannibalization。
Cloudflare の crawl-to-referral ratio 等は ecosystem の観測であり、自社 target ではない。native app が Referer を送らない等の限界があるため、UTM、server log、conversion、cash を合わせる。Cloudflare crawl-to-refer methodology
KPI contract
Section titled “KPI contract”primary、driver、guardrail、data quality
Section titled “primary、driver、guardrail、data quality”| role | metric | 分母・条件 |
|---|---|---|
| primary | matured incremental net machine contribution | cutoff 前 assigned、maturity 到達、control と比較可能 |
| driver 1 | verified eligible request/principal share | machine-labeled 全件。UA-only は verified にしない |
| driver 2 | priced → settled → accepted delivery rate | stage ごとの独立分母を併記 |
| guardrail 1 | human/search discovery contribution | human session、known search crawler、既存 conversion |
| guardrail 2 | safety/reliability veto | false block/charge、5xx、p95 latency、replay、unpaid delivery、incident |
| data quality | unknown/duplicate/late/reconciliation delta | request、payment、delivery、cash の join |
target は baseline、buyer、resource、rail、capacity、最大損失が揃うまで空欄にし、target_state=NOT_DUE とする。外部の crawl/referral ratio、provider minimum price、架空 fixture を成功閾値へ使わない。
metric_id / metric_version:machine_access_contract_id / contract_version:environment: SYNTHETIC | SANDBOX | LIMITED_LIVE | LIVEaccounting_environment: TEST | REALrole:question:unit / eligible denominator:numerator:event/source of truth:deduplication key:occurred cutoff / ingestion snapshot:maturity rule:currency / FX source / valuation time:estimated vs observed fields:missing / unknown / late handling:target_state: NOT_DUE | UNKNOWN | OBSERVEDtarget: blank until baseline | exact approved valueveto / loss cap:query hash / reviewer:UNKNOWN、N/A、0、FAILED を分ける
Section titled “UNKNOWN、N/A、0、FAILED を分ける”| state | 意味 |
|---|---|
N/A |
contract 上 stage が存在しない。理由と再確認 trigger がある |
UNKNOWN |
必要だが未確認、期限切れ、矛盾、join 不能 |
0 |
分母と観測窓が確定した上でのゼロ |
FAILED |
実行した検査・delivery・settlement 等が明示的に失敗 |
OBSERVED |
定義した evidence を肯定観測 |
NOT_DUE |
maturity 時点がまだ来ていない |
402=0 は需要ゼロではない。eligible verified buyer が zero なのか、quote を出していないのか、client が非対応か、price を拒否したのかを分ける。未成熟 refund を zero にしない。
event と二つの時計
Section titled “event と二つの時計”common envelope
Section titled “common envelope”event_id / event_type / event_revision:machine_access_contract_id / contract_version:request_id / principal_id / resource_contract_id / resource_revision:traffic_policy_id / policy_revision:payment_offer_id / offer_revision:challenge_id / challenge_revision:payment_proof_id / proof_revision / payment_event_id / event_sequence / settlement_id:entitlement_event_id / delivery_event_id / delivery_receipt_id:accepted_outcome_event_id / cash_reconciliation_id / maturity_snapshot_id:provider / environment: SYNTHETIC | SANDBOX | LIMITED_LIVE | LIVEaccounting_environment: TEST | REALoccurred_at / recorded_at / ingestion_sequence:outcome_cutoff_at / snapshot_as_of:source_object_ref / evidence_class / artifact_hash:supersedes_event_id:actor / reviewer:occurred_at は business event 時刻、recorded_at は trusted ingestion 時刻である。cutoff 前に起きたが snapshot 後に届いた settlement/refund は旧 snapshot を静かに変更せず、新 revision として再計算する。
必要 event
Section titled “必要 event”machine_request: actor、purpose、identity evidence、resource、policy、status、bytes、cache/origin、latency、variable cost。payment_quote: quote ID、price、asset、network、scope、expiry。payment_state: authorized、settled、failed、refunded、reversed。entitlement_delivery: exact resource/action、attempt、accepted/failed、retry。human_referral_session: referrer、UTM、landing、native-app unknown、conversion link。license: operator、purpose、rights、term、territory、retention、derivatives、revocation。cash_cost: gross、fee、tax、FX、refund、bank/wallet reconciliation、origin/API/support/founder time。incident_veto: false classification、replay、duplicate charge、rights、privacy、security、availability。
raw IP、credential、wallet secret、signature private material、customer content を分析 pack や Codex prompt へ貼らない。opaque ID、検証結果、最小 metadata、権限制御した正本 reference を使う。
read/resource delivery は delivered bytes と content digest、204 や zero-byte tool action は first-party action/result receipt で成功を表す。全 delivery に bytes > 0 を強制せず、HTTP status、technical delivery、accepted business outcome を分ける。
event chronology は request occurred → challenge issued → authorization occurred → settlement occurred → entitlement grant/valid_from → delivery occurred → accepted outcome occurred → cash observed の順序を検査する。recorded_at は遅着し得る。cutoff 前に occurred した event が snapshot 後に届いた場合、時刻を改変したり拒否したりせず、現 snapshot から除外して次の superseding snapshot で再計算する。
security・privacy・rights gate
Section titled “security・privacy・rights gate”平均利益で相殺しない veto
Section titled “平均利益で相殺しない veto”- human または free search route を誤って block/charge した。
- UA-only actor を verified buyer にした。
- secret、customer-private、rights
FAILED/UNKNOWNresource を提供した。 - payment proof、nonce、entitlement、delivery の replay/duplicate がある。
- settlement 前または reversed payment で delivery を許した。
- paid but undelivered、delivered but unpaid、二重課金を説明・修復できない。
- identity/payment credential、wallet key、個人 data の漏えい・過剰保存がある。
- write action の principal、scope、human consent、idempotency が不明。
- 4xx/5xx、partial response、timeout の課金・refund contract が不明。
- provider/account/region eligibility、terms、税務・会計処理が
UNKNOWNのまま live にした。
上記が current なら positive contribution があっても STOP または PAUSE である。
threat model
Section titled “threat model”| threat | control |
|---|---|
| UA spoofing | credential/signature/IP/rDNS evidence、UA-only を unverified |
| signature replay | covered target/body、created/expires、nonce store、key revocation |
| payment replay | unique proof/transaction/payment identifier、authoritative read-back |
| price substitution | server-side offer tuple、amount/asset/network/recipient binding |
| confused deputy | principal と end-user scope、resource/action permission、consent |
| cache leak | principal-aware cache key、private/no-store、paid body isolation |
| double charge/delivery | independent idempotency keys、unique ledger、outbox/inbox |
| resource drift | content hash、revision、freshness、supersession |
| high-cost abuse | preflight、quota、cost cap、timeout、circuit breaker |
| policy drift | source snapshot、effective time、recheck trigger、kill switch |
日本の個人事業で live 前に確認する
Section titled “日本の個人事業で live 前に確認する”- 売る権利: 自作部分、third-party content/data、customer data、共同著作、license の目的・再配布・training・派生・保持。
- 契約主体と表示: seller/MoR、相手、商品、価格、税、refund、support、準拠法、利用条件、電子的同意。
- 決済 rail: stablecoin/暗号資産、wallet、custody、交換、送金、本人確認等の関与。自分の行為と provider の役割を金融庁等の現行資料・専門家へ確認する。金融庁 FinTech サポートデスク
- 税務・会計: 売上認識、円換算時点、手数料、refund/reversal、wallet/provider/bank 差、消費税・invoice、暗号資産の取得・処分等。国税庁の現行資料と税理士へ確認する。国税庁 暗号資産 FAQ
- 電子記録: offer、注文、receipt、settlement、invoice、refund、相手、時刻、換算根拠を検索可能な形で保存する。電子取引 data の保存要件を確認する。国税庁 電子帳簿保存法
- privacy/security: IP、signature metadata、principal、request content、wallet address、referral identity の必要性、目的、保存、委託、国外、削除、incident response。
この checklist は適法判断ではない。provider が MoR を担っても、resource の権利、data protection、記録、所得・税務、顧客 support 等の自分の責任が自動的になくなるとは限らない。
14 日の最小 pilot
Section titled “14 日の最小 pilot”対象を狭める
Section titled “対象を狭める”検索掲載の影響は14日で成熟しにくい。公開 search crawler の allow/block を treatment にせず、次の一つを選ぶ。
- low-risk archive の machine-readable derivative。
- freshness を持つ非個人 data feed。
- bounded compute endpoint。
- read-only API/MCP tool の accepted action。
- 一社と合意した test license resource。
PII、login 後 data、secret URL、customer private、write/payment action、権利不明 resource は初回対象外にする。stable な resource_contract_id + content_hash で control/treatment を固定する。
Day 1–2: shadow baseline
Section titled “Day 1–2: shadow baseline”- response を変えず
MEASURE_ONLY。 - human、search、training、user fetch、API/tool、unknown を分類。
- UA、公式 IP/rDNS、WBA、credential の evidence と expiry を保存。
- request、bytes、cache/origin、latency、error、概算変動原価を観測。
- current referral、conversion、license/API inquiry を control として凍結。
Day 3: contract freeze
Section titled “Day 3: contract freeze”machine_access_contract_id、resource、rights、policy、principal、owner を承認。- control と一つの treatment を宣言。
- primary、driver、guardrail、DQ、cutoff、maturity を固定。
- price は baseline と loss cap の根拠が揃ってから決める。
- maximum request、cash、origin cost、founder minutes、incident を固定。
- kill switch と rollback を rehearsal する。
Day 4–6: identity と negative path
Section titled “Day 4–6: identity と negative path”- spoofed UA、invalid signature、expired key、wrong resource、wrong price、expired quote を test。
- human/search free route が 402 を受けないことを確認。
- result unknown、duplicate retry、replay、settlement failure、origin 5xx を test。
- test/sandbox receipt を live cash へ混ぜない。
Day 7–9: compatible client の test mode
Section titled “Day 7–9: compatible client の test mode”- 自分の client または合意済み buyer の sandbox だけで challenge を実行。
- challenge→authorization→settlement/test receipt→entitlement→exact delivery を trace。
- payment と business delivery の idempotency を別々に検証。
- refund/reversal と reconciliation を一度通す。
Day 10–12: capped live または license probe
Section titled “Day 10–12: capped live または license probe”次がすべて current PASS の場合だけ、一 principal・一 resource・一 rail・小さな上限で live にする。
- rights、provider/account/region eligibility、terms、accounting route。
- verified principal と compatible client。
- authoritative settlement、refund、reconciliation。
- delivery receipt、replay protection、kill switch。
- human/search guardrail と support owner。
自動支払い需要がなく、bulk/training の権利需要があるなら 402 を強行せず CONTRACT_LICENSE probe にする。
Day 13–14: freeze、maturity、decision
Section titled “Day 13–14: freeze、maturity、decision”- 新規 policy/price change を止める。
- request、payment、delivery、refund、cash、cost の差を照合。
- mature cohort と
NOT_DUEを分ける。 - free/referral control と cannibalization を読む。
- individual principal の failure reason を確認する。
STOP / PAUSE / UNKNOWN / INCONCLUSIVE / CHANGE / MAINTAIN / EXPANDを evidence 付きで決める。
- human/known free-search crawler への誤 block・誤課金。
- duplicate charge、replay、paid-undelivered、unpaid-delivered。
- PII、credential、wallet、rights、security incident。
- 5xx、latency、origin cost、cash、founder time が事前上限を超えた。
- policy/resource/principal/payment/delivery ID が欠け、比較・照合不能。
- kill switch が働かない。
件数不足は自動的な失敗でなく INCONCLUSIVE である。verified eligible demand がゼロなら NO_SIGNAL と記録し、payment integration を拡張しない。
decision map
Section titled “decision map”| evidence | decision | 次の action 候補 |
|---|---|---|
| rights/security/human harm veto | STOP |
block/rollback、incident、修復 |
| program/identity/cash link 不明 | PAUSE / UNKNOWN |
source 再確認、shadow 継続 |
| verified eligible demand なし | INCONCLUSIVE または MAINTAIN |
402 拡張せず discovery/API sales を検証 |
| referral contribution が free cost を上回る | MAINTAIN |
ALLOW_FREE、検索を維持 |
| training/bulk の権利需要、auto-pay support なし | CHANGE |
CONTRACT_LICENSE |
| repeat principal、予測可能 usage | CHANGE |
AUTHENTICATED_API / subscription |
| one-shot compatible demand、正の成熟貢献 | EXPAND |
capped HTTP_402 |
| unverified abuse、負の contribution | CHANGE |
RATE_LIMIT / BLOCK |
| cash は入るが完全負荷後赤字 | CHANGE |
reprice、cache、batch、scope、停止 |
EXPAND は全 traffic への展開を意味しない。principal、resource、purpose、route、price、quota、期間のうち証拠が支える scope だけを広げる。
Codex に任せる範囲
Section titled “Codex に任せる範囲”- provider docs の current snapshot 候補と差分整理。
- traffic/resource taxonomy、schema、migration、fixture。
- policy-as-code、exact-match test、shadow logging。
- challenge/receipt parser、server-side tuple validation。
- idempotency、replay、expiry、cache、negative-path test。
- request→payment→delivery→cash reconciliation query。
- DQ report、plan-vs-result diff、release/rollback checklist。
- resource を売る権利と許諾範囲。
- provider program、主体、地域、account の live eligibility。
- buyer、price、refund、tax/accounting、wallet/custody の判断。
- high-impact action の scope と user consent。
- loss cap、kill switch、live authority、incident response。
- metric の経済的意味、因果主張、最終 decision。
handoff contract
Section titled “handoff contract”machine_access_contract_id / contract_version:allowed files / forbidden files:environment: SYNTHETIC | SANDBOX | LIMITED_LIVE | LIVEaccounting_environment: TEST | REALresource_contract_id / resource_revision:rights_basis_id / rights_revision:traffic_policy_id / policy_revision:payment_offer_id / offer_revision:meter_id / meter_revision:protocol / product / API exact versions:expected challenge/payment tuple:identity evidence accepted:positive / negative fixtures:human/search preservation tests:replay/idempotency/cache tests:settlement/delivery/reversal/reconciliation tests:maximum external effects:required approvals:release / rollback / kill-switch commands:redacted evidence output:Codex に live wallet secret、private key、raw customer data、full request content を渡さない。test fixture は synthetic identifier と test network/provider mode を使う。生成 code の conformance pass を legal approval、buyer demand、live cash へ昇格させない。
よくある失敗
Section titled “よくある失敗”全 AI crawler を一括 block/charge する
Section titled “全 AI crawler を一括 block/charge する”search、training、user fetch、API/tool の価値を混ぜ、referral と paid demand の両方を壊す。traffic purpose × resource × identity で policy を分ける。
UA を customer identity にする
Section titled “UA を customer identity にする”UA は spoof でき、同じ provider 内の purpose も違う。credential/signature/network evidence と限界を保存する。
402 を返した件数を revenue にする
Section titled “402 を返した件数を revenue にする”challenge は offer であり payment ではない。authorization、settlement、delivery、cash、maturity を通す。
wallet transaction を accepted delivery にする
Section titled “wallet transaction を accepted delivery にする”支払いと resource/action delivery は別 system である。entitlement と exact-once delivery receipt を持つ。
payment が rights を買ったことにする
Section titled “payment が rights を買ったことにする”price と purpose/retention/training/derivative/redistribution の license scope を別契約にする。
error response でも課金する
Section titled “error response でも課金する”product/protocol の contract と origin result を照合し、4xx/5xx、timeout、partial delivery、refund を precommit する。
test coin と live contribution を混ぜる
Section titled “test coin と live contribution を混ぜる”SYNTHETIC / SANDBOX / LIMITED_LIVE / LIVE、network、asset、provider account を event ごとに固定する。companion SQL へ投影するときだけ前二者を TEST、後二者を REAL に写像し、元の environment を正本から捨てない。
gross price だけで採算を見る
Section titled “gross price だけで採算を見る”facilitator/network/PSP、FX、tax、origin/egress/API、refund/fraud、support、founder rescue、cannibalization を引く。
preview と roadmap を current sales channel にする
Section titled “preview と roadmap を current sales channel にする”docs、account、region、role、API version、buyer support を snapshot にし、waitlist/coming-soon を forecast へ入れない。
robot policy を secret protection にする
Section titled “robot policy を secret protection にする”robots/content signal は public crawler への preference で、authentication/authorization ではない。
週次 review
Section titled “週次 review”machine_access_contract_id / contract_version:decision_snapshot_id:environment: SYNTHETIC | SANDBOX | LIMITED_LIVE | LIVEaccounting_environment: TEST | REALcutoff / snapshot_as_of / maturity:resource_contract_id / resource_revision:traffic_policy_id / policy_revision:payment_offer_id / offer_revision:meter_id / meter_revision:provider/program/API source snapshots:
requests: human / search / training / user fetch / agent / API-tool / unknown: verified A / verified B / UA-only / inferred: allow / measure / limit / block / license / auth / 402:
funnel: eligible verified principals / requests: quoted / authorized / settled: entitled / delivery accepted / failed: refunded / reversed / cash reconciled / mature:
economics: paid gross / license allocation / referral contribution: fees / tax / edge-origin-egress / external API / support / founder time: measured cannibalization / reconciliation delta: matured incremental net machine contribution:
guardrails: human/search false block or charge: referral/conversion change: p95 / 5xx / cost cap: replay / duplicate / payment-delivery mismatch: rights/privacy/security/refund incident:
DQ: unknown identity / unknown rights: duplicate / late / missing links: stale source or policy: immature units:
decision: STOP | PAUSE | UNKNOWN | INCONCLUSIVE | CHANGE | MAINTAIN | EXPANDscope / evidence / owner / due:next cheapest evidence:rollback or recheck trigger:最終チェックリスト
Section titled “最終チェックリスト”traffic・resource・identity
Section titled “traffic・resource・identity”- search、training、live retrieval、user fetch、agent、API/tool、unknown を分けた。
- resource class、content hash、freshness、rights purpose を version 化した。
- UA-only を verified principal または buyer demand にしていない。
- signature/IP/rDNS/credential の source、時刻、限界、expiry を残した。
- robots/content signal と authentication/authorization を分けた。
policy・payment・delivery
Section titled “policy・payment・delivery”- 一 request に一つの current policy action がある。
- 402 は compatible challenge を構築できる paid barrier に限定した。
- offer が amount、asset、network、recipient、scope、expiry、nonce、resource と結合した。
- replay、retry、business action、cache、4xx/5xx、refund を test した。
- settlement 前に delivery せず、entitlement と delivery receipt を分けた。
- test/sandbox と limited/live cash を分けた。
economics・decision
Section titled “economics・decision”- primary は成熟後の増分 net contribution である。
- free discovery/referral control と cannibalization を見た。
- gross から reversal、tax、fee、variable cost、support、founder time を引いた。
-
N/A / UNKNOWN / 0 / FAILED / NOT_DUEを混ぜていない。 - target は自社 baseline まで空欄かつ
NOT_DUEとした。 - safety、rights、human/search guardrail を平均利益で相殺していない。
-
EXPANDの principal、resource、purpose、route、quota、期間を限定した。
machine traffic の monetization は「crawler を見つけて 402 を返す」仕事ではない。誰が、何の目的で、どの resource を求め、どの権利と policy で、どの支払いを行い、何を受け取り、最終的に現金と利益が残ったかを一件ずつ結ぶ仕事である。
個人開発者の安全な順序は、公開 discovery を維持し、shadow 計測で traffic と原価を知り、価値の明確な machine resource を狭く商品化し、compatible な実 buyer だけを test mode から上限付き live へ進めることである。402 はその選択肢の一つにすぎない。最終判断は machine_access_contract_id に resource、identity、policy、payment、delivery、cash、maturity、guardrail を束ね、成熟後の増分 net machine contribution で行う。