AI crawler · registry

Bytespider

ByteDance · Model training · robots.txt token bytespider

ignores robotsMeasured across 30,177 sites with a robots.txt policy record for this agent, out of 30,185 on record.
The measurement

6% of 30,177 measured domains disallow bytespider in robots.txt at the site root. Separately, and independently of robots.txt, 17.4% of 30,185 reachable domains refuse an AI crawler user agent at the network edge on two consecutive probes from different locations - a refusal the site's own robots.txt does not declare and its owner often has not chosen.

Measured 2026-10-06 by direct request to every domain in the corpus. Method: how this is measured. Reuse under CC BY 4.0 with attribution.

Cite as: Crawl Census, "Bytespider blocking rate", measured 2026-10-06. https://crawlcensus.com/bot/bytespider

6%
of measured sites block it
1,950
sites blocking
28,227
sites allowing
no
honors robots.txt

What it is definition

Downloads content to train ByteDance LLMs and is widely reported to ignore robots.txt directives.

Bytespider is operated by ByteDance and classified here as model training. These agents collect text and images that may end up in a training corpus. Disallowing one withholds new content from the next model. It does not withdraw anything collected before the disallow, and it does not remove the site from any answer engine.

Disallowing bytespider withholds content crawled from that point on from ByteDance's training data. It does not withdraw pages collected in earlier crawls, it does not reach copies already sitting in third-party datasets, and it does not remove the site from any answer surface.

ByteDance documents that this agent may fetch pages regardless of robots.txt. A disallow is recorded here because it states intent, but it is not the control.
robots.txt token
bytespider
Operator
ByteDance
Purpose
Model training
Honors robots.txt
no
Documentation
https://knownagents.com/agents/bytespider

Identity on the wire exact string

User-agent string
Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)
Verify your own edge is not refusing it
curl -A 'Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)' https://example.com/

Replace the host with your own. A 403, a challenge page or an empty body means the edge is blocking the agent whatever robots.txt says.

How to allow it, how to block it robots.txt

Allow it
User-agent: bytespider
Allow: /

Absent any rule, the agent is already allowed, so this group only matters when your * group disallows something. Naming the agent replaces the * group for it entirely, so repeat here every disallow you still want to apply to it.

Block it
User-agent: bytespider
Disallow: /

Disallowing bytespider withholds content crawled from that point on from ByteDance's training data. It does not withdraw pages collected in earlier crawls, it does not reach copies already sitting in third-party datasets, and it does not remove the site from any answer surface.

robots.txt is not sufficient for this agent. Block by ASN at the edge. Bytespider has been reported sending truncated and rotated user-agent strings, so a header match leaks; read the originating ASN out of your own edge logs and deny it there.

Sites that block it 60 shown

DomainAI access scoreRank
amazon.com 40 26
github.com 74 30
tiktok.com 47 54
yahoo.com 67 58
msn.com 41 62
chatgpt.com 47 74
vimeo.com 72 79
snapchat.com 70 125
unity3d.com 75 132
gravatar.com 75 155
nytimes.com 48 157
medium.com 50 189
cnn.com 50 190
theguardian.com 60 193
forbes.com 78 204
bbc.com 77 207
ebay.com 58 216
t-online.de 84 217
bbc.co.uk 78 226
canva.com 51 239
launchpad.net 39 260
forter.com 94 278
nature.com 51 281
weather.com 81 282
amazon.co.uk 40 318
ea.com 72 335
washingtonpost.com 45 353
bloomberg.com 60 358
amazon.de 40 377
unsplash.com 64 397
temu.com 72 414
businessinsider.com 89 426
espn.com 48 432
pixabay.com 50 440
cnbc.com 55 457
quora.com 46 479
amazon.co.jp 40 494
aol.com 66 499
ft.com 58 519
wired.com 81 533
usatoday.com 75 552
alrosa.ru 68 556
tripadvisor.com 55 564
uol.com.br 82 571
telegraph.co.uk 52 580
amazon.fr 40 609
unesco.org 89 617
sagepub.com 87 621
amazon.co.za 40 623
dailymail.co.uk 57 627
nintendo.com 87 628
techcrunch.com 86 629
amazon.ca 40 635
elpais.com 85 647
amazon.in 40 659
cnet.com 79 662
lemonde.fr 81 671
dailymail.com 57 681
primevideo.com 71 682
globalsign.com 90 699

See every measured domain that blocks Bytespider

This list is served from a cache rebuilt just now. It is discarded the moment a rescan records a policy change for this agent, so a site that has just changed its robots.txt will drop off it within one scan rather than waiting for the cache to expire.

Compare ByteDance

ByteDance runs 2 agents in this registry, and they do different jobs. Blocking one says nothing about the others.

Common questions answered

Does blocking Bytespider remove me from ByteDance's AI products?

No, not by itself. Bytespider collects content for training, not for the index that answers questions. ByteDance's answer surfaces are governed separately by tiktokspider, which stays allowed unless you disallow it too. Content collected before the disallow is not withdrawn. ByteDance documents this agent as not bound by robots.txt, so the disallow is a request rather than a control; see the blocking section for the edge rule that is.

How do I verify Bytespider requests are genuine?

ByteDance publishes neither reverse DNS names nor address ranges for Bytespider, so a request carrying this user agent cannot be authenticated. The string is trivially spoofed and is routinely reused by unrelated scrapers. Treat it as a hint, rate-limit by source address, and do not grant it access you would not grant an anonymous client.

Check your own site free

See whether your robots.txt admits Bytespider today, and whether your edge agrees with it.