IndexNow on Cloudflare Workers: key file, submission, and what it feeds

IndexNow lets a Cloudflare Worker prove site ownership and notify search engines, but it does not guarantee indexing or direct AI-search inclusion.

IndexNow lets a site notify participating search engines when a URL is added, updated, or removed. On this site, a Cloudflare Worker serves the verification file from a Worker secret, while a separate request submits the URLs. That can help Bing-backed web retrieval, but it is not a direct feed to ChatGPT or Copilot and it does not guarantee indexing.

IndexNow key facts

  • IndexNow notifies search engines about URLs that were added, updated, or removed. The notification asks an engine to fetch the URL. It does not promise that the URL will be indexed.
  • An IndexNow key must be 8 to 128 characters and may contain letters, numbers, and hyphens. The key file proves control of the host.
  • The current registry, read on 2026-10-06, lists Bing, Yandex, Seznam.cz, Naver, Yep, the Internet Archive, and Amazonbot. It contains no Google endpoint.
  • A site can host the key at a custom path and send that URL as keyLocation. A key file at the host root covers URLs under that host.
  • One participating endpoint can share a submission with the other IndexNow participants. The registry and protocol do not promise that every participant will index the URL.
  • HTTP 200 means the URL was submitted successfully. HTTP 202 means the URL was received while key validation is pending.

IndexNow targets search engines, not answer systems. A successful notification is a signal for crawling and indexing, not a command to ChatGPT or Copilot.

Microsoft's documentation says web search in its declarative agents relies on content that Bing indexes for configured public websites. OpenAI's general ChatGPT help says ChatGPT search sometimes works with third-party search providers. Its Enterprise and Edu documentation names Bing as a provider for web results in those workspaces.

That creates a qualified link: an IndexNow notification may help a changed page reach Bing, and a Bing-backed retrieval path may later use Bing's indexed copy. It does not guarantee that Copilot or ChatGPT will select the page. Amazonbot appears in the IndexNow registry, but the registry does not say which Amazon products consume its data, so do not claim that IndexNow feeds Alexa or another product directly.

Use IndexNow with an XML sitemap. IndexNow reports recent changes; the sitemap remains the site's URL inventory.

Serving an IndexNow key from a Cloudflare Worker secret

IndexNow verifies host ownership before accepting a submission. The protocol supports two key-file layouts:

  • Root file: host {key}.txt at the domain root.
  • Custom location: host a text file elsewhere on the same host and pass its URL in keyLocation. A file at /indexnow-key.txt is at the root path, so it covers URLs under https://insidetheloop.dev/.

This site's src/worker.ts reads the Worker secret INDEXNOW_KEY and serves it at /indexnow-key.txt:

// IndexNow ownership proof (indexnow.org); the key is the Worker secret INDEXNOW_KEY.
if (url.pathname === "/indexnow-key.txt" && env.INDEXNOW_KEY) {
	return new Response(env.INDEXNOW_KEY, { headers: { "content-type": "text/plain; charset=utf-8" } });
}

Set the secret with Wrangler:

npx wrangler secret put INDEXNOW_KEY

The deployed route returned HTTP 200 with a plain-text response during the 2026-10-06 check. The body is redacted here:

HTTP/2 200 
content-type: text/plain; charset=utf-8

[redacted IndexNow key]

This route serves the ownership file only. It does not submit URLs to IndexNow. A publish hook, scheduled job, or separate script still has to call the API.

Submitting IndexNow URLs and reading response codes

The protocol supports one URL with GET or up to 10,000 URLs in one POST. This example uses the shared endpoint and a custom key location:

curl -i -X POST "https://api.indexnow.org/indexnow" \
  -H "Content-Type: application/json; charset=utf-8" \
  -d '{
    "host": "insidetheloop.dev",
    "key": "<your-indexnow-key>",
    "keyLocation": "https://insidetheloop.dev/indexnow-key.txt",
    "urlList": [
      "https://insidetheloop.dev/"
    ]
  }'

The documented response codes are:

  • 200 OK: The endpoint says the URL or set of URLs was submitted successfully. This is not proof of indexing.
  • 202 Accepted: The endpoint received the URL while key validation is pending. A later request may return 200 after verification.
  • 400 Bad Request: The request format is invalid or a required field is missing.
  • 403 Forbidden: The key is invalid, missing, or does not match the key file.
  • 422 Unprocessable Entity: A URL does not belong to the declared host, or the request violates the protocol schema.
  • 429 Too Many Requests: The service is rate-limiting submissions. Honor Retry-After when present and reduce repeated notifications.

The live checks for this site produced 202 with a pending key, 200 after verification, 400 when urlList was missing, and 422 when a submitted URL did not match the host. Those checks show the protocol response, not a guarantee that a page entered an index.

{"errorCode":"InvalidRequestParameters","message":"One or more URLs are not related to your verified domain. Please verify URLs before submitting.","details":null}

Cloudflare Crawler Hints and a custom Worker route

Cloudflare Crawler Hints uses cache signals to tell search engines when content has likely changed. Cloudflare's documentation read on 2026-10-06 says it uses cache-status MISS, does not report origin responses with status codes greater than 4xx, and is a global setting for the zone. A custom Worker route gives you a place to serve the key, but it does not create a submission trigger by itself.

Question

Cloudflare Crawler Hints

Worker route plus a submitter

Trigger

Cache signals such as MISS

An explicit call from a publish hook, job, or script

Key handling

Cloudflare manages the integration

The Worker reads INDEXNOW_KEY

Submission control

Cloudflare decides when to emit a hint

Your code chooses URLs, batching, and logging

Important limit

Responses above 4xx are not reported

The key route does nothing until another component calls IndexNow

For this site, the safe sequence is simple: store the key as a Worker secret, confirm the public key-location URL returns plain text, submit only changed URLs, and record the response code. Keep the sitemap as the complete inventory and treat 200 or 202 as submission responses, not indexing results.

Sources

Last verified: 2026-10-06.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.