Cloudflare's Pay Per Use Pays for More. The Buyer Holds the Meter.
This morning Cloudflare published the shape of a payment. It is one line of JSON: a timestamp, the URL a page came from, and an event ID. An AI company sends that line each time it uses a publisher's page. Cloudflare adds up the lines, charges the company, and pays the publisher monthly. The product is called Pay Per Use, and it entered beta today, next to a Monetization Gateway that charges agents over HTTP 402. Both are what I have argued on this site since July: every anti-bot system is a pricing system. But read who writes the line. Pay Per Crawl counted at the door. Pay Per Use lets the buyer define the use, set the price and report the count. The model that promises publishers more is the one they cannot audit.
What the turnstile counted
Pay Per Crawl, launched in 2025, is a turnstile. A site sets one price, the same for every crawler it chooses to charge. A signed crawler asks for a page, gets a 402, pays, and gets the page. Cloudflare's docs fix the unit. The charge is "for each successful content retrieval (HTTP 200 response)", and "error responses are not billed". The wall counts, and the publisher sees the same fetches in its own server log. Two ledgers record one event.
Cloudflare says why that stopped being enough. "AI products fetch far more than they use", the Pay Per Use post says. The Monetization Gateway post gives the reverse case: "a page might be crawled once and used a thousand times." In July the company said more than half of AI crawler traffic re-fetches pages that have not changed. A fetch is not value in either direction. So Pay Per Use, in its own words, "pays for what happens next".
Who writes the line
Each AI company "defines the use it will pay for and sets a price". A use can be "a cited answer in AI search" or "a product review weighed by a shopping agent". The publisher sees the offer in its Cloudflare dashboard and accepts or declines. The buyer downloads the list of domains that accepted, then "reports each use as one line of JSON". Cloudflare adds them up, charges the buyer, and pays the publisher monthly.
Then the sentence the product rests on: "Usage is self-reported: the program terms require complete reporting, and Cloudflare checks that each reported use maps to an enrolled publisher."
Read that as a publisher. The buyer chose what counts as a use. The buyer chose the price of one. The buyer counts them. Cloudflare's check is that the URL belongs to someone enrolled. It is not a check that the use happened, or that every use was reported. The dashboard shows "reported uses", and the word reported is doing honest work. The event happens inside the buyer's product, where no wall and no publisher log can see it.
View data table
| Model | Row | Text |
|---|---|---|
| Pay Per Crawl (2025) | Who sets the price | the site, one price for every charged crawler |
| Pay Per Crawl (2025) | What is counted | a successful fetch (HTTP 200) |
| Pay Per Crawl (2025) | Who counts | Cloudflare's wall, at the door |
| Pay Per Crawl (2025) | What the publisher can check | the same fetch, in its own server log |
| Pay Per Use (today) | Who sets the price | the AI company, per kind of use |
| Pay Per Use (today) | What is counted | a use inside the buyer's product |
| Pay Per Use (today) | Who counts | the buyer, one JSON line per use |
| Pay Per Use (today) | What the publisher can check | that the URL is its own; Cloudflare checks that too |
The meter has moved before
Advertising ran this experiment. In September 2016 Facebook told ad buyers that for about two years it had overstated the average time people spent watching video ads, by 60 to 80 percent, because it counted only views longer than three seconds. Advertisers sued. Their complaint put the overstatement at 150 to 900 percent. Facebook settled for 40 million dollars in 2019 and kept saying the suit had no merit. Nobody outside could catch it, because the count lived inside the company paid on it. Within five months Facebook agreed to an audit by the Media Rating Council, the advertising industry's auditor.
Pay Per Use launches with the platform-side count and without the auditor. Its identity layer is solid: buyers arrive as "verified buyers", signed through the scheme I wrote about two weeks ago. Identity is solved. The count is not.
The number the wall still has
Cloudflare has one thing it does not use here: the fetch log. Enrolled publishers sit behind its wall, so most pages a buyer reports as used passed through Cloudflare on the way in. The two ledgers will not match one to one, since a page can be fetched once and used a thousand times, but they can be compared. A buyer that reports using a page it never fetched is a flag. A page fetched a thousand times with zero reported uses is another. The post promises nothing of the kind. It promises "an account of what happened", and the account is written by the buyer.
Where I stand
I wrote in August that the bot's passport is a rate card. Today the wall priced the thing it cannot see. Advertising's count was disputed, then audited. I expect the same here, and I will date it.
By the end of 2027, Pay Per Use will either add an independent check on the count, such as matching reported uses against the wall's own fetch log, a sampled audit, or a use ledger the publisher can read, or it will produce its first public dispute between a publisher and an AI company over a number. I am wrong if at the end of 2027 the program still runs on self-reported counts alone, with no check added and no dispute made public.
Publishers get a dashboard of reported uses and a monthly payment. The fetch count is still in their own logs. It just stopped being the invoice.