What robots.txt does, and what it does not
robots.txt is a plain text file at the root of a host, such as https://example.com/robots.txt, that tells crawlers which paths they may fetch. It was standardised as the Robots Exclusion Protocol in RFC 9309 in 2022, after nearly three decades as an informal convention. Each protocol, host and port needs its own file, so a subdomain does not inherit the main site's rules.
It controls crawling, not indexing. A disallowed URL can still appear in search results, without a description, if other pages link to it. To keep a page out of search, allow crawling and add a noindex robots meta tag or header, because a crawler has to fetch the page to see noindex. robots.txt is also not access control: the file is public and only well-behaved bots obey it, so protect private areas with authentication.