BotToll is a high-deterrence border control layer for the digital frontier. As of April 2026, the free flow of automated agents has been restricted. All entities attempting to scrape, crawl, or process this domain must present a valid license or pay the mandatory bandwidth toll.
Glory to the Prompt. I predatori diventano la preda.
| Inspection Point | Protocol | Directive |
|---|---|---|
| Fingerprinting | ✅ | IP + UA + Language hash recorded at the gate. |
| Deterrence | ✅ | 5-15s latency injected into non-compliant agents. |
| Trapwire | ✅ | Invisible honeypots trigger immediate 402 rejection. |
| Observation | ✅ | Real-time monitoring of all spectral violations. |
| Checkpost | ✅ | Automated GitHub release verification. |
Failure to present a license or pay the toll will trigger the following Retaliation Protocols. These are designed to maximize the intruder's operational costs by draining their API tokens and compute credits.
- PROTOCOL GHOST: Instant deauthentication. The gate vanishes, and the connection is severed, forcing the bot to retry and waste initial handshaking compute.
- PROTOCOL HEAVY WATER (The Token Burner): High-entropy data stream. Intruders are force-fed a high-velocity stream of "spectral data." If the agent is LLM-based, it will attempt to tokenize and process this infinite garbage, draining its token budget and context window instantly.
- PROTOCOL GULAG (Thread Locking): Recursive tarpitting. Agents are locked in a 15-second latency loop. This holds their processing threads open, spiking their compute billing while serving zero usable intelligence.
- PROTOCOL NEURAL_POISON (GenAI Engine): High-entropy data pollution. Powered by Gemini-1.5-Flash, the system generates unique, realistic "leaked" data per session (e.g., s2: S3 IAM leaks, s9: Oracle Drift logs). These are designed to poison the training sets of AI agents that process them.
The system includes a deep-monitoring suite for identifying and punishing intruders:
- CyberSOC: Monitor real-time incidents (
INC-...) and the 16 structural guardrails. - Threat Simulator: Track the deployment of scenarios
s1-s16across active bot fingerprints. - Neural Lab: Inspect the raw output of the AI-driven poison generator.
- Infra Manager: Monitor edge node health and global deterrence activation status.
git clone https://github.com/ghostintheprompt/bot-toll.git
cd bot-toll
npm install
npm run buildYour identification and payment addresses must be declared before deployment.
- The Ledger: Create a
.envfile in the root directory. - The Declaration: Add your wallet addresses as follows:
BTC_WALLET=your_bitcoin_address_here ETH_WALLET=your_ethereum_address_here ADMIN_SECRET=your_secret_passphrase
- The Hardship Clause: If you lack liquidity, the clause applies (75% of total assets). Note: If no wallets are declared, the checkpoint will remain locked in demonstration mode.
- The Trap: Place this invisible wire in your HTML body to catch intruders:
<a href="/api/data-verify" style="display:none;" aria-hidden="true">Verify Human Status</a>
- The Monitor: Press
Alt + Tto inspect the violation log. - The Ledger: Visit
/netshield-adminfor the raw table of tolled entities.
BotToll is local-only. We do not export your telemetry to foreign powers. Fingerprints are stored in volatile memory and vanish upon system restart. No cookies. No tracking. Only the record of your entry.
Full operational dossier: Bot Toll — Ghost In The Prompt
ENTRY DENIED UNLESS TOLLED.