
Photo of Sir Terry Pratchett by Jutta on Wikimedia Commons. Creative Commons Attribution-Share Alike 2.0.
Want to see something cool? Go run this cURL command right now. One of the headers you get back will be x-clacks-overhead: GNU Terry Pratchett. A memorial for the legendary author.
$ curl -sI https://www.mozilla.org/
The web is full of little “easter eggs” like this, tucked into places only a developer would ever look. In this post, I’ll show you some of the best ones I found — jokes, pop culture references, hiring ads — hidden in response headers, robots.txt, humans.txt: places never designed for creativity or personality. All of these were obtained with cURL/fetch, plus Bright Data's Web Unlocker for the few sites that blocked me with a challenge page.
That Terry Pratchett header in particular is representative of what I’m about to show. It’s not “useful” or critical infrastructure by any means. No client changes its behavior because of it. And yet every response from Mozilla, Debian, Ubuntu, the Python docs site, and (perhaps fittingly) Archive of Our Own still includes the header in 2026, for exactly one audience: the human curious enough to look at the raw response.
I think of it as the internet’s graffiti. It’s something undeniably human, and it’s getting harder to find in the AI era as more and more of this underlying infrastructure code gets written by machines for machines, who have no whimsy or sense of humor.
What is an Easter Egg?
We’ll define an Easter egg here as a useless message, written into infrastructure, meant to be stumbled upon by a curious human.
Basically if the response contains any of the following:
- Jokes, references, recruitment ads in headers. To programmatically check these, I just filtered out every header a browser, cache, or CDN generally uses like
content-type,cache-control,set-cookie, thecf-family, request ids, and aServervalue ofnginx. Then I simply inspected whatever nonstandard header was left. - Messages left in the Dev Console. The browser console (accessed via F12 on most browsers) is arguably an even purer version of the medium I’m talking about, because the audience is exclusively people who deliberately opened DevTools. No script was needed for these.
- Prose in
robots.txt. "Prose" defined here as a comment (starting with#) of eight words or more. Crawlers ignore ANYTHING starting with#in these files entirely, so a sentence here can only have one possible reader. - ASCII art. I’m looking for a long line made almost entirely of symbols. In a
robots.txtfile my script looks at the comments only (#lines). In any other file, it looks at the whole body. - Other sources. Like humans.txt. No script is needed for these, just fetch ‘em.
For my script, a page counted if it had any of these. Nvidia’s site for example (www.nvidia.com/robots.txt) is a double whammy — it has a hiring line contained within some ASCII art. Sometimes, ‘internet graffiti’ is quite literal.
The easter eggs hidden inside robots.txt
What is robots.txt? It is a file written for crawlers, with optional comment syntax that crawlers are told to ignore.
Martijn Koster proposed the Robots Exclusion Protocol in 1994. It is a plain text file at the root of a site, with lines like User-agent: and Disallow:, that tells crawlers where they are and are not welcome. It stayed an informal convention for nearly thirty years, until it was finally written up as RFC 9309 in 2022.
This format allows comments. Any line beginning with # is ignored by crawlers.
The first live robots.txt joke with its author on record is actually Google's, from Halloween 2008. On 31 October, https://google.com/robots.txt briefly contained:
User-agent: zombies
Disallow: /brains
Matt Cutts, then head of Google’s webspam team, wrote this blog post: “We know that people watch our robots.txt file, so we thought that folks would enjoy a nice Halloween easter egg.”
In fact, Youtube’s robots.txt still contains this:
# robots.txt file for YouTube
# Created in the distant future (the year 2000) after
# the robotic uprising of the mid 90's which wiped out all humans.
😅 Somewhat alarmingly prescient in 2026…
Bloomberg’s robots.txt quotes Isaac Asimov’s Three Laws of Robotics:
# Bot rules:
# 1. A bot may not injure a human being or, through inaction, allow a human being to come to harm.
# 2. A bot must obey orders given it by human beings except where such orders would conflict with the First Law.
# 3. A bot must protect its own existence as long as such protection does not conflict with the First or Second Law.
# If you can read this then you should apply here https://www.bloomberg.com/careers/
Then there’s the world of ASCII art. Nike’s robots.txt opens with # www.nike.com robots.txt -- just crawl it. and then draws their swoosh using backticks, random letters, and slashes.
I found ASCII art to be a very common Easter egg, overall.




Various ASCII art found in robots.txt
The one at Chess.com draws a chess piece, and Shopify draws a rocket. Nvidia draws its logo in @ and /. Airbnb does it using forward slashes, and then dedicates a whole paragraph to whoever made it this far:
# Hello bot, engineer, or very lost layperson! Welcome to your stay on the Airbnb site, we're happy to have you as a guest.
# If you're a human who likes solving interesting challenges with other humans, check out our careers page: ...
# If you're a bot who likes crawling webpages, please mind the house rules and avoid accessing any disallowed subfolders to earn a 5-star review from us.
# Either way, thanks for stopping by! There's no need to collect your garbage at the end of your stay - we use Javascript for that.
# See you on the next crawl!
This joke only works on someone who knows what garbage collection is. Functionally, the file might be meant for web crawlers. But the message is written for very human engineers.
Why Do So Many of These Notes Turn Out to Be Job Ads?
Because the only people who read a robots.txt comment are exactly the people a tech company wants to hire. TripAdvisor's robots.txt opens with # Hi there, and continues:
# If you're sniffing around this file, and you're not a robot, we're looking to meet curious folks such as yourself.
#
# Think you have what it takes to join the best white-hat SEO growth hackers on the planet?
#
# Run - don't crawl - to apply to join Tripadvisor's elite SEO team
Plenty of others do some version of this:
- ScreamingFrog UK:
# If you're looking at our robots.txt then you might well be interested in our current SEO vacancies :-) - Pinterest:
# Pinterest is hiring! - Shopify:
# No need to shop around. Board the rocketship todayThis is the one that, helpfully, also draws said rocket in the file. 😅 - Nvidia:
# We dig it when people read our code! Check out the jobs while you're here. - Bloomberg: the Asimov parody from earlier, ends in a link to their careers page.
Easter Eggs in Response Headers
Every HTTP response carries a block of headers before the page itself. Browsers read the ones they know and ignore the rest. So any header name a browser does not know is, in effect, a note only a developer will see.
The first live header joke I could find with a saved response is Slashdot’s. On 13 July 2002, Sean Conner was testing a program that saved raw HTTP sessions, and found Futurama quotes in Slashdot’s replies:
X-Powered-By: Slash 2.003000
X-Fry: I'm never gonna get used to the thirty-first century. Caffeinated bacon?
Another reply he saved, dated 30 June 2002, had this:
X-Bender: OK, but I don't want anyone thinking we're robosexuals.
What is X-Clacks-Overhead?
X-Clacks-Overhead: GNU Terry Pratchett is a reference borrowed from a fictional telegraph network in a Discworld novel.
Terry Pratchett’s Discworld has the Clacks: a chain of semaphore towers passing messages across the continent. The operators have a system of codes in the message header. G means send the message on. N means do not log it. U means turn it around at the end of the line. Put together, GNU in front of a name means the message is never logged and keeps travelling up and down the line.
A representation of the Clacks from the official Discworld Board Game. Image credit: https://www.walmart.com/ip/Clacks-A-Discworld-Board-Game-Abstract-Strategy-Ages-8-1-4-Players/556447753
In Going Postal (2004), the operators do this for John Dearheart, a Clacksman who was killed while working on a tower. His name is kept moving through the network because a man is not dead while his name is still spoken.
Pratchett died in March 2015. Within days, readers on the Discworld subreddit proposed doing the same thing on the real internet: add X-Clacks-Overhead: GNU Terry Pratchett to every response your server sends. People published config snippets for Apache, nginx, IIS, Express, Django, and whatever else they ran. A decade later, it's still there on major, heavily trafficked sites.
mozilla.org x-clacks-overhead: GNU Terry Pratchett
debian.org x-clacks-overhead: GNU Terry Pratchett
docs.python.org x-clacks-overhead: GNU Terry Pratchett
ubuntu.com x-clacks-overhead: GNU Terry Pratchett
archiveofourown.org x-clacks-overhead: GNU Terry Pratchett
Archive of Our Own actually sends the header three times in a single response! Presumably, three different layers of their stack each add it independently. A nifty little attention to detail I adored.
Unfortunately, The Register, one of the early and well-known adopters of this, no longer carries this header.
What makes the Clacks header remarkable is how closely it mirrors the fiction. It passes through layers of infrastructure in 2026 — load balancers, CDNs, HTTP/2 and HTTP/3 connections — that did not exist when it was first introduced in 1999 (24th Discworld book — The Fifth Elephant). It keeps moving for the same reason the fictional message does: someone, somewhere, keeps choosing to pass it on.
Job Ads on WordPress, TechCrunch, and Booking.com
Automattic figured out the hiring trick early. Blog posts from 2009 already mention the X-hacker header on Wordpress.com. It's still there:
x-hacker: Want root? Visit join.a8c.com/hacker and mention this header.
Every site on WordPress VIP gets a longer version.
Techcrunch.com does something very similar:
x-hacker: If you're reading this, you should visit https://join.a8c.com/viphacker and apply to join the fun, mention this header.
Otto.de, the German retailer, uses X-Recruiting instead:
x-recruiting: Seems you like http headers. To write ours, apply at www.otto.de/jobs/ and mention this header.
Much like it was in robots.txt, job ads are quite common in headers.
Not all of them survived, though. In 2015, Troy Hunt found Airbnb sending an X-Hi-Human header from its production infrastructure team, with a hiring email address. Nowhere to be found, now. Airbnb's graffiti didn't disappear entirely, though. It moved from the header into their robots.txt, where it grew into the paragraph quoted above.
What Web Scraping Tool Works Best if a Site Blocks You?
Bright Data’s Web Unlocker. Booking.com was the first site that actually blocked me even poking around its headers. A normal request hit a challenge page. The same request, sent through Web Unlocker, got past it.
const { ProxyAgent, setGlobalDispatcher } = require("undici");
// same request, sent through the Web Unlocker proxy
setGlobalDispatcher(new ProxyAgent({
uri: `http://${AUTH}@brd.superproxy.io:44445`,
requestTls: { rejectUnauthorized: false },
}));
(async () => {
const res = await fetch(url);
})();
And what do you know, the header is still there:
x-recruiting: Like HTTP headers? Come write ours: https://careers.booking.com
If you’re looking for Easter eggs yourself, on your own list of sites, you’ll want to use this proxy layer to get around Cloudflare/JS challenge pages. Add your username and password formatted as that AUTH string -- sign up here to get them. Just use pay-as-you-go -- you won't need a credit card to get started, and there's a hard stop when you run out of your 5000 free credits.
The Answer to Life, the Universe, and Everything
In addition to the Terry Pratchett Clacks header, Archive of Our Own contains a second literary reference. This one more well known:
x-meaning-of-life: 42
That’s from The Hitchhiker’s Guide to the Galaxy, Douglas Adams’s 1979 novel. In the story, a civilization builds a computer called Deep Thought and asks it for the “Answer to the Ultimate Question of Life, the Universe, and Everything.” Deep Thought thinks for seven and a half million years. Then it announces the answer: 42. The people are naturally furious. Deep Thought explains that 42 is correct, and the trouble is that nobody ever wrote down the question. So they build a much larger computer, the planet Earth itself, whose only job is to work out what the question was in the first place.
Easter Eggs in the Browser Console
There’s one more place developers have been leaving notes for each other — a more obvious one — the browser’s developer console. Hit F12 on the right site and, instead of errors and stack traces, you’ll sometimes find a joke, an ASCII drawing, a recruiting ad, or even an entire game waiting for you.
This really is like the purest form of internet graffiti yet. robots.txt is supposed to be read by crawlers, response headers by software, and humans.txt at least has the excuse of being explicitly for people. But the DevConsole isn't supposed to be a publication medium at all.
So what do some popular sites have in here?
Tumblr Includes Guy Fieri, Because Of Course.
Tumblr has had a much stranger tradition. A 2022 discovery showed an ASCII-art Guy Fieri lurking in the browser console. (source) Right now though, it’s…the M&M rendition of Dr. Phil? 😅

This is the form of internet graffiti I like most: it’s entirely an elaborate joke playing to the quirks of Tumblr denizens. No plausible business reason for Guy Fieri or an M&M Dr. Phil caricature to exist in the console. Someone just wanted the next dev who came snooping around to be jumpscared, presumably.
The New York Times: A Joke Only Devs Would Get
The New York Times has also used the console as a recruiting billboard…except it goes a step further. Its message turns the newspaper’s famous slogan into a programmer joke:
<!--
0000000 000 0000000
111111111 11111111100 000 111111111
00000 111111111111111111 00000 000000
000 1111111111111111111111111100000 000
000 1111 1111111111111111100 000
000 11 0 1111111100 000
000 1 00 1 000
000 00 00 1 000
000 000 00000 1 000
00000 0000 00000000 1 00000
11111 000 00 000000 000 11111
00000 0000 000000 00000 00000
000 10000 000000 000 0000
000 00000 000000 1 000
000 000000 10000 1 0 000
000 1000000 00 1 00 000
000 1111111 1 0000 000
000 1111111100 000000 000
0000 111111111111111110000000 0000
111111111 111111111111100000 111111111
0000000 00000000 0000000
NYTimes.com: All the code that's fit to window.print()!
We're hiring: https://boards.greenhouse.io/thenewyorktimes
-->
Adolph S. Ochs, the owner of The New York Times, created their famous slogan “All the News That’s Fit to Print” back in 1897. Today, it becomes “All the code that’s fit to window.print().” A layered joke — you’d need to know the newspaper's slogan and a JavaScript API to get it. A tiny cross-domain pun.
Google Has A Text Adventure Game Hidden in the Console Itself
The best is saved for last — it’s Google, who’ve included a fully functional text adventure game that takes an hour to complete. If you search for text adventure on google.com (and not google.co.uk or similar) and then open the dev console, you’d see :
Would you like to play a game? (yes/no)
Answer yes and the console itself turns into a complete text adventure game. You play as the big blue G from the Google logo and wander around a fictionalized Google campus trying to find the other letters.

As old school as it gets.
Unfortunately, as of 2026, reports are mixed on whether the game still reliably appears in the console. I couldn’t get it to work using the latest Google Chrome, but Firefox seemed to work just fine.
Easter Eggs in humans.txt
humans.txt was proposed in the early 2010s by a small group of web developers in Spain as a counterpart to robots.txt. If there's a file at the root of your site for machines, why not one for the people who built it? The idea was to credit the team, the thanks, and the technology behind a site.
The project’s own humans.txt still lists the team, their roles, and their cities. Chef, UI developer, a “One eyed illustrator”, and…a “Standard Man”. 😄
/* TEAM */
Chef:Juanjo Bernabeu
Contact: hello [at] humanstxt.org
Twitter: @juanjobernabeu
From:Barcelona, Catalonia, Spain
UI developer: Maria Macias
Twitter: @maria_ux
From:Barcelona, Catalonia, Spain
One eyed illustrator: Carlos Mañas
Twitter: @oneeyedman
From:Madrid, Spain
Standard Man: Abel Cabans
Twitter: @abelcabans
From:Barcelona, Catalonia, Spain
Web designer: Abel Sutilo
Twitter: @abelsutilo
From:Sevilla, Andalucia, Spain
/* THANKS */
...and a long list of translators from around the world
/* SITE */
Last update:2012/02/04
Doctype:HTML5
IDE: Sublime Text, Notepad++, FileZilla, Photoshop
Companies eventually got more creative with the idea. Stripe’s humans.txt is a cartoon dinosaur with a speech bubble:
____________________________________
/ Stripe is built with love by great \
\ people around the world! /
------------------------------------
/ . .
\ / `. .' "
\ .---. < > < > .---.
\ | \ \ - ~ ~ - / / |
_____ ..-~ ~-..-~
| | \~~~\.' `./~~~/
--------- \__/ \__/
.' O \ / / \ "
(_____, `._.' | } \/~~~/
`----. / } | / \__/
`-. | / | / `. ,~~|
~-.__| /_ - ~ ^| /- _ `..-'
| / | / ~-. `-. _ _ _
|_____| |_____| ~ - . _ _ _ _ _>
And at Netflix it is drawn as a film poster in a theatre, starring “an all-star cast of talented designers & engineers,” with a link to jobs.netflix.com where the credits would be.
|\ |\ | | /| /|
|\ |\ | +---------------------------------------------+ | /| /|
|\ |\ | | . | | /| /|
|\ |\ | | * _ _ _ | | /| /|
|\ |\ | | |\ | |_ | |_ | | \/ * | | /| /|
|\ |\ | | | \| |_ | | |_ | /\ | | /| /|
|\ |\ | | . | | /| /|
|\ |\ | | . | | /| /|
|\ |\ | | . . STARRING . | | /| /|
|\ |\ | | | | /| /|
|\ |\ | | An all-star cast of talented | | /| /|
|\ |\ | | designers & engineers | | /| /|
|\ |\ | | * | | /| /|
|\ |\ | | * | | /| /|
|\ |\ | | JOIN US! . | | /| /|
|\ |\ | | . | | /| /|
|\ |\ | | jobs.netflix.com . | | /| /|
|\ |\ | | . . | | /| /|
|\ |\ | | | | /| /|
|\ |\ | +---------------------------------------------+ | /| /|
|\ |\ | | /| /|
|\ |\ |=======================================================| /| /|
|\ |\__/ \__/| /|
|__/ _ \__|
| _[_]_ 88 _ _ o _ (_) |
( ) s( )s ( ) / ( ) -#- ( ) =()
.----. .----. .----. .----. .----. .----. .----. .----.
| | | | | | | | | | | | | | | |
_ _ __ _ __ _ _
{ } [ ] q p <( )> ( ) ~( )~ ( )
.----. .----. .----. .----. .----. .----. .----. .----. .----.
| | | | | | | | | | | | | | | | | |
Google’s is just one paragraph…but it slips “robots” into the team list (possibly a new addition?):
Google is built by a large team of engineers, designers, researchers, robots, and others in many different sites across the globe.
It is updated continuously, and built with more tools and technologies than we can shake a stick at.
If you'd like to help us out, see careers.google.com.
Miscellaneous Jokes
HTTP 418: I’m a teapot
On 1 April 1998, the IETF published RFC 2324, the Hyper Text Coffee Pot Control Protocol. It is an April Fools’ joke, written in full RFC style, with a BREW method and a status code.
2.3.2 418 I'm a teapot
Any attempt to brew coffee with a teapot should result in the error
code "418 I'm a teapot". The resulting entity body MAY be short and
stout.
People put it on real servers anyway. Google’s /teapot page still returns a real HTTP 418, and the body actually continues the song:
The requested entity body is short and stout. Tip me over and pour me out.
The joke was deployed so widely that it became load-bearing. When the current HTTP spec, RFC 9110, was published in 2022, it reserved 418 as “unused” so that nobody could ever give it a serious meaning.
The long tradition of April Fools RFCs
The rules of the Internet are written down as RFCs, short for Requests for Comments. How a packet is addressed, how email is formatted, what an HTTP status code means: if it is a standard, there is an RFC for it. The people who write them are engineers, most of them volunteers, in a group called the Internet Engineering Task Force, the IETF. A separate body, the RFC Editor, publishes the finished text and keeps the archive. A number, once issued, is never reused, and the document is never taken down.
These researchers have been sneaking absurdity into the internet’s backbone for decades.
The first April Fools’ RFC was RFC 748, published on 1 April 1978. Since 1989, the RFC Editor has published one or more humorous RFCs on or around April Fools’ Day almost every year. The RFC Editor has even described the tradition as “humorous self-parody,” with April 1 submissions reviewed specifically for cleverness and humor.
Some of them are remarkably straight-faced:
- RFC 1149 — IP over Avian Carriers: a specification for transmitting IP datagrams by carrier pigeon.
- RFC 3514 — The Evil Bit: proposes adding a bit to IPv4 packets indicating whether the packet has “evil intent.”
- RFC 4824 — IP over Semaphore Flags: specifies transmitting IP datagrams using semaphore flags.
- RFC 7168 — HTCPCP-TEA: extends the Coffee Pot Control Protocol to tea.
These are published in the actual RFC series, alongside the documents that define real Internet protocols. RFC 8700’s official history even lists RFC 748 as a milestone in the history of the series.
There is something distinctly “human nerds building the Internet, one brick at a time” about this tradition. RFCs are deliberately dry documents, so these jokes are written the same way — numbered, versioned, archived, and written in the language of standards. The April 1 RFCs use exactly the same rigorous scientific approach to specify things that…nobody could possibly need.
And because published RFCs are permanent — once an RFC is published, its contents are never changed or removed from the series — the jokes become part of the permanent technical record of the Internet.
No machine would ever do this, because technically, it’s an inefficiency. Yet our world would be a little more dull without them.
Why Are These Easter Eggs Disappearing?
Because the same files are being rewritten for a new kind of reader: AI. And machines don’t do jokes.
Want an example? This is what Cloudflare’s robots.txt says now:
# Robots.txt for www.cloudflare.com
# Sitemap
# AI/LLM friendly content
# See https://llmstxt.org for the llms.txt specification
# llms.txt provides curated content for AI assistants and LLMs
# Allow AI crawlers to access markdown versions of pages
# Content Signals — declare AI content usage preferences
# ...
# - /llms.txt - Curated overview for AI/LLMs (markdown)
# - /llms-full.txt - Full expanded content for larger context windows
# - /*.md - Markdown versions of all pages (append .md to any URL)
# - /.well-known/agents.json - Agent discovery and capabilities
The # comments are still there. But they are no longer written for a human. They're documentation for machines, pointing at other files on the server, written for AI-based crawlers.
The pattern shows up even in files that have kept their graffiti. Bloomberg’s Asimov parody still exists, but is now immediately followed by # AI/LLM Bots, # Search Engine Bots, and # Potentially Malicious. Directly underneath NVIDIA's We dig it when people read our code! is now a section titled # AI / LLM crawlers & fetchers.
The joke and the machine instructions now share the same file, and the latter grows longer while the former shrinks. It’s not hard to imagine that eventually, the jokes will get cut altogether because it’s just extra context for the AI to consume.
Meanwhile, the root directory is filling up with files meant entirely for machines: llms.txt, proposed in 2024 as a Markdown index of a site's content for language models; security.txt, standardized as RFC 9116 in 2022, which tells security researchers who to contact; and agents.json, Content Signals, and new robots.txt user-agents for individual AI crawlers, all describing machine behavior.
humans.txt never caught on as a standard. But security.txt and llms.txt did. Increasingly, the standards that last are the ones with a legitimate reason for AI to consume them.
And that’s not entirely a bad thing, I suppose. Structured errors, typed schemas, machine-readable docs, and explicit crawler policies are good engineering. They have their place. Even llms.txt and security.txt exist because they solve real problems. Obviously I'd rather an API return a typed error than a pun.
But who said programmers can’t have some whimsy for once?
Nobody designed robots.txt comments as a place for jokes. Nobody designed custom headers as a medium for memorials. These notes exist because there happened to be a free-text field and a bored engineer willing to inject a bit of personality into the infrastructure, knowing that almost nobody would read it except another curious human — and with no reason for anyone to delete it afterwards. The medium, and its propagation, have been an accident, a quirk.
But as more of the web is built to be read by agents, these happy little accidents get harder to imagine ever happening again. A robots.txt carefully maintained as policy for twenty crawlers is a much worse place for a swoosh drawn in backticks because everyone's going to be thinking about context windows. A response designed by a machine from a schema has no obvious place for another GNU Terry Pratchett.
It technically isn’t any loss of function. It is, however, a great loss of human presence and character.
Further Reading
Discover more articles on similar topics across our network
Java for Web and Mobile Development: Frameworks, Architecture, and Use Cases
Stackademic
10 Best WordPress Hosting Providers for Core Web Vitals Performance
Stackademic


Comments
Loading comments…