SiteLensBot

If SiteLensBot shows up in your server logs, someone added your site to Site Lens and started an audit. Here is how it behaves and how to turn it off.

User-Agent header

Mozilla/5.0 (compatible; SiteLensBot/1.0; +https://sitelens.coolify.meethubapp.com/bot)

How to verify it

Each request carries an Ed25519 signature in the Signature and Signature-Input headers (Web Bot Auth, RFC 9421). Signature-Agent names the directory with our public key, so a firewall can tell SiteLensBot from anyone who copies its User-Agent.

https://api-sitelens.coolify.meethubapp.com/.well-known/http-message-signatures-directory

When it visits

Only when someone starts an audit of a site they added to their account. It does not roam the web and does not come back on its own.

One audit fetches at most as many URLs as that person’s plan allows. On the free plan, 25.

Pace

2 requests a second by default; the person running the audit can set 1 to 5. A Crawl-delay in robots.txt takes precedence.

After a 429 or 503 it waits (as long as Retry-After asks, too) and tries at most twice more. When a WAF starts answering with a challenge page, the audit stops.

What it fetches

URLs on the audited domain, found in links and sitemaps. Links to other domains are recorded but not visited. Links with rel="nofollow", "sponsored" or "ugc" are not followed.

It does not run JavaScript, submit forms or sign in.

How to block it

The bot reads robots.txt at the start of every audit. A group for SiteLensBot wins over the * group. To block it entirely:

User-agent: SiteLensBot
Disallow: /