Autonomous agents browse, click, and submit. Without page-level policy they will reach login forms, checkouts, and payment pages you never intended. AI Agent Allowlist is a database of verified URLs for 20 page types across millions of domains — so your policy engine knows exactly which pages an agent may enter, and which it must never touch.
By Alpha Quantum — the team behind AI Tools Blocklist and the 120M-domain Web Filtering Database.
login · checkout · payment · pricing · contact · careers · docs · legal · blog · status and more — each with the actual URL, found by traversing the site’s real link structure.
The pages where agent incidents happen — credential forms, checkouts, payment flows — identified per domain so your guardrail can refuse them before the click.
An agent hunting for a pricing page burns tokens, time, and failure risk. A verified URL turns a multi-step crawl into a single deterministic lookup.
Tiers at 10M, 15M and 30M domains — sourced from real-world browsing popularity, covering up to 99.95% of web traffic your agents will ever encounter.
One-time database purchase with optional monthly refreshes, or per-lookup API access. Drops into policy engines, gateways, and agent frameworks.
Agent platforms, AI gateways, and enterprise browsers license the data to ship page-level guardrails as a feature — redistribution licensing available.
These rows are copied from the free sample — download it and check them yourself. Every URL was discovered by traversing the domain’s live link structure, not guessed from patterns.
| domain | page_type | verified URL | agent policy example |
|---|---|---|---|
| stripe.com | login | dashboard.stripe.com/login/… | deny — credential surface |
| stripe.com | pricing | stripe.com/pricing | allow — research target |
| stripe.com | documentation | stripe.com/guides | allow |
| linkedin.com | login | linkedin.com/login?… | deny — credential surface |
| linkedin.com | careers | linkedin.com/jobs/… | allow |
| stripe.com | status | status.stripe.com | allow — monitoring |
Full records also carry IAB content categories, web-filtering categories, popularity ranks, country, language, and user personas per domain — so one dataset powers both where agents may go and what kind of site they’re on.
Guessed paths (/login, /pricing) miss the real URL on most sites — subdomains, locales, query strings. We store what the site actually links to.
Domain-level policy is too blunt for agents: you can’t block all of amazon.com, but you must block its checkout. Page types make policy possible.
Computer-use and browser agents are entering production. Every deployment guideline now says the same thing: constrain what the agent can reach.
Import the CSV into your policy store, or query the API per URL. Each domain resolves to its verified page-type URLs and site metadata.
“Agents may visit pricing, docs, blog, contact. Agents must never open login, checkout, payment, or account pages.” Default-deny for anything sensitive.
Your agent framework, gateway, or enterprise browser checks every navigation against the map — the agent is stopped before it reaches the page, not audited after.
See the exact schema and verify the URLs yourself. Then pick a database tier or ask about API & OEM licensing.