Skip to content

Verified Bot

OptinStack-Bot

OptinStack-Bot is the automated agent OptinStack uses when reading customer websites on behalf of authenticated workspace users. It is not a public web crawler and does not index the open internet.

It powers tracker scans, install verification, published-banner checks, and AI design sync in the OptinStack dashboard.

Requests use the OptinStack-Bot/1.0 (+https://optinstack.com/bot) user agent and Web Bot Auth signatures when signing keys are configured.

View as Markdown for AI tools and reviewers.

User agent

OptinStack-Bot/1.0 (+https://optinstack.com/bot)

Optional purpose header: X-OptinStack-Bot-Purpose with values scanner, verifier, or design-sync.

What it does

  • Discovers pages from sitemaps (preferred) or homepage links before tracker scans.
  • Loads pages in a real browser to inventory trackers and consent platforms.
  • Fetches published HTML to verify OptinStack script installation.
  • Reads public pages for AI-assisted banner theme sync.

See the domain scan disclosure for page selection, plan limits, access restrictions, and result variability.

Crawl scope

  • Who initiates: authenticated OptinStack workspace users (or jobs they enable for their projects).
  • What hosts: only hostnames registered on that customer project.
  • What paths: same-host URLs from sitemap or homepage links, after robots.txt filtering, within the plan page limit.
  • What it does not do: open-web indexing, unsolicited bulk crawls, credential stuffing, or form login attempts.

robots.txt

OptinStack-Bot honors robots.txt directives for OptinStack-Bot and the * fallback group. Disallowed paths are excluded from scan URL discovery. When a site publishes Crawl-delay, OptinStack-Bot waits before fetching additional URLs from that host.

Rate limits and security

Scans are initiated only by authenticated OptinStack customers. The API enforces per-account and global concurrency caps on active scans. Browser runs are queued and batched. OptinStack does not perform unsolicited bulk crawling of the public web. Discovery and page loads use HTTPS only.

Verification

Public signing keys are published at /.well-known/http-message-signatures-directory. Signature-Agent is https://optinstack.com. OptinStack registers OptinStack-Bot with Cloudflare Verified Bots using Web Bot Auth (Request Signature) in the Monitoring & Analytics category.

Contact and abuse

Questions or abuse reports: hello@optinstack.com. Include UTC time, target URL, User-Agent, and Signature headers when reporting suspected misuse.

FAQ

What is OptinStack-Bot?
OptinStack-Bot is the user-agent identity for automated HTTPS requests OptinStack makes when an authenticated customer starts a domain scan, install verification, published-banner check, or AI banner design sync. It is not an open-web search crawler.
What user agent does it send?
OptinStack-Bot sends: OptinStack-Bot/1.0 (+https://optinstack.com/bot). Optional purpose header: X-OptinStack-Bot-Purpose with values scanner, verifier, or design-sync.
Does OptinStack-Bot honor robots.txt?
Yes. OptinStack-Bot honors robots.txt rules for the OptinStack-Bot user-agent group and the * fallback group. Disallowed paths are excluded from scan URL discovery. When a site publishes Crawl-delay, OptinStack-Bot waits before fetching additional URLs from that host.
What is the crawl scope?
Only hostnames the customer has registered in their OptinStack workspace. URL discovery uses the site sitemap when available, otherwise homepage links, subject to plan page limits. OptinStack does not perform unsolicited bulk crawling of the public web.
How is traffic rate limited?
Scans start only from authenticated OptinStack customers. The API enforces per-account and global concurrency caps on active scans. Browser runs are queued and batched; OptinStack does not open unbounded parallel crawls against a target host.
How can operators verify requests?
Public signing keys for Web Bot Auth are published at https://optinstack.com/.well-known/http-message-signatures-directory. Signature-Agent is https://optinstack.com. OptinStack registers OptinStack-Bot with Cloudflare Verified Bots using Request Signature authentication in the Monitoring & Analytics category when the application is approved.
Where do I report abuse or ask questions?
Email hello@optinstack.com. Include the request time (UTC), target URL, full User-Agent, and any Signature or Signature-Agent headers if present.