Skip to main content
How-To GuidesAllowlist OnChange

Allowlist OnChange in Cloudflare and other firewalls

Bot protection sometimes stops OnChange's checks before they reach your page. When that happens the monitor is marked as blocked and can't see changes. One allow rule on your side fixes it for good.

Last updated: September 20265 min read

How OnChange checks identify themselves

Checks look like a normal browser visit, so there is no bot user agent to match. Instead, every check carries two things your firewall can trust:

A verification header (preferred)

X-OnChange-Verify with a value that starts with ocv1_. The value is unique to your OnChange account and your website, and it is only ever sent to that website.

A fixed IP address

Checks leave from:

Loading current addresses…

Find your header value: open the monitor in OnChange, go to Settings, and look for Let OnChange through the site's firewall. A blocked monitor also shows the values right on its page, with copy buttons and a ready-made Cloudflare rule.

Monitors that run from a proxy region reach your site from that region's network, not from the IP above. The header rule covers them; an IP rule does not.

Cloudflare

Which rule you need depends on your plan. Cloudflare's free-plan Bot Fight Mode cannot be skipped by custom rules, so free zones allow the IP instead.

Pro, Business and Enterprise: skip rule on the header

  1. In the Cloudflare dashboard, select your website, then open Security and go to the security rules page. Choose Create rule, then Custom rules.
  2. Name it “Allow OnChange”.
  3. Choose Edit expression and paste the expression from your monitor. It contains your own value and looks like this:
    any(http.request.headers["x-onchange-verify"][*] eq "ocv1_…")
  4. Under Choose action, select Skip and tick All remaining custom rules, All rate limiting rules, All Super Bot Fight Mode rules and All managed rules.
  5. Place the rule first, then deploy it.

Cloudflare stores header names in lowercase, which is why the expression uses x-onchange-verify.

Free plan, Bot Fight Mode, or “I'm Under Attack”: allow the IP

  1. In the Cloudflare dashboard, select your website and open IP Access rules (under Security; search the dashboard for “IP Access rules” if the menu has moved).
  2. Enter OnChange's IP address from above.
  3. Set the action to Allow, apply it to this website, add the note “OnChange monitoring”, and save.

Cloudflare evaluates IP Access rules before Bot Fight Mode, so an allowed IP is not challenged. Only OnChange checks come from this address.

Vercel

  1. Open your project, then Firewall.
  2. For the header: add a custom rule where the request header X-OnChange-Verify equals your value, with the action Bypass.
  3. For the IP (also covers Attack Challenge Mode and system mitigations): add OnChange's IP address to System Bypass Rules.
  4. Publish the changes.

AWS WAF (CloudFront, ALB, API Gateway)

  1. Open the web ACL in front of your site and choose Add rules, then Add my own rules.
  2. Create a rule that inspects the single header x-onchange-verify, match type Exactly matches string, with your value.
  3. Set the action to Allow and give the rule a lower priority number than Bot Control and your managed rule groups, so it runs first.
  4. Save the web ACL.

To allow by address instead, create an IP set with OnChange's IP and an Allow rule that references it.

Other firewalls and bot managers

The same two options work everywhere: allow requests whose X-OnChange-Verifyheader equals your value, or allow OnChange's IP address. Menu names change between versions, so search for the terms below.

  • Akamai (Bot Manager, App & API Protector): Add OnChange's IP to a client list used as an allow list, or define a custom bot that matches the header and set its action to allow.
  • Imperva: Add OnChange's IP to the site's allowlist in the WAF or bot protection settings.
  • HUMAN (PerimeterX) and DataDome: Add an allowlist entry for the header value or the IP in the bot protection console.
  • Sucuri: Add OnChange's IP under Access Control, Allowlist IP addresses.
  • Wordfence (WordPress): Add OnChange's IP under Firewall options, Allowlisted IP addresses.
  • nginx, HAProxy, or your own rate limiter: Exempt requests that carry the header value (or come from the IP) from bot checks and rate limits.

Confirm it works

  1. In OnChange, open the monitor and press Check now.
  2. The blocked notice disappears and the status returns to OK once the check reaches your page.
  3. In Cloudflare, the request appears in Security Events with your “Allow OnChange” rule and the Skip action.

Still blocked? Check that the rule sits above other rules, that the value was pasted in full, and that the rule is on the same website (zone) the monitor watches. Our support team can look at the blocked response with you.

Questions

Why not allowlist OnChange's user agent?
OnChange checks send a normal browser user agent, because a bot-style one gets blocked more often. User agents are also trivial to fake, so a rule based on one would let anybody through. The header value is secret to your account and the site, which makes it safe to trust.
Is the header value secret?
Treat it like a password for this one rule. It is unique to your OnChange account and this website, and OnChange sends it only to that website, never to other sites, CDNs, or scripts the page loads. Another site owner who sees their own value cannot use it on your site. If you think it leaked, contact us and we will rotate it.
Do I need both the header rule and the IP rule?
No. One is enough. The header rule is preferred because it keeps working if OnChange's addresses change and it covers monitors that run from a proxy region. Use the IP rule where your firewall cannot match headers, such as Cloudflare's free-plan Bot Fight Mode.
What if I don't manage the website?
Send this page and the two values from your monitor's settings to whoever runs the site. Until they add a rule, OnChange keeps retrying and marks the monitor as blocked instead of reporting false changes.

These rules only let OnChange's checks skip bot protection. They do not open anything else on your site, and OnChange never sends the header to any other website.