User-agent: * Allow: / # Behind a login — nothing here is useful in a search result, and crawling it # just burns crawl budget on redirect chains. Disallow: /dashboard/ Disallow: /auth/ Disallow: /billing/ Disallow: /register/ Disallow: /settings/ Disallow: /profile/ Disallow: /usage/ Disallow: /notifications/ Disallow: /memory/ Disallow: /octopus/ Disallow: /workspace/ Disallow: /admin/ # One-time and per-account flows. Indexing these can only ever surface a stale # or already-consumed link. Disallow: /oauth/ Disallow: /accept-invitation/ Disallow: /verify-email/ Disallow: /reset-password/ Disallow: /forgot-password/ # PRIVACY: /s/ is one customer's share link to their own file. It carries no # noindex of its own, so without this line a share URL that leaks into a crawler # — a referrer header, a pasted link, a public bookmark — could be indexed and # the file becomes findable by search. (Added 5 Sep 2026.) Disallow: /s/ # Not content. /faro/collect is the browser telemetry sink; it was the single # most-crawled path on the whole domain (197 requests in 24h, measured in # Cloudflare AI Crawl Control on 5 Sep 2026) and every one of those was wasted. Disallow: /faro/ Disallow: /dev/ # NOTE THE TRAILING SLASH. "/api/" blocks the proxied API paths but NOT the page # at "/api", which is the Developer API landing page and IS in the sitemap. # Removing the slash here would de-index a page we are actively trying to rank. Disallow: /api/ Sitemap: https://johnsessentials.com/sitemap.xml