TapCubBot and other TapCub fetchers
If you found a TapCub user agent in your server logs, this page explains which request it was, who triggered it, and how to block it.
Last updated
Fetchers that visit web pages
These four user agents request pages or files from a website. Each one fetches at most 3 redirects and refuses to connect to private, loopback or cloud metadata addresses.
| User agent | When it runs | What it fetches | Limits |
|---|---|---|---|
TapCubBot/1.0 | Someone sends a message containing a link in a TapCub chat conversation. | The first link in the message, to show a preview card: page title, description, og:image and site name. | 5 s timeout; reads only the first 512 KB of HTML; each URL is fetched at most once a day. |
TapCub-SitemapFetcher/1.0 | Once a day, and when the site owner clicks refresh in the console. | /sitemap.xml on the registered domain, or the sitemap URL the owner configured, plus child sitemaps listed in a sitemap index. | 15 s timeout; up to 2 index levels, 50 sitemap files, 50,000 URLs and 20 MB per file. |
TapCub-ComplianceFetcher/1.0 | Once a day, and when the site owner refreshes the crawler compliance report. | /robots.txt and /llms.txt on the registered domain, to check whether crawlers visiting the site follow its rules. | 10 s timeout; these two files only. |
TapCubKB/1.0 | A TapCub Chat customer imports a web page into their chat knowledge base. | Only the URL they entered. HTML and plain-text pages only. | 5 s timeout; up to 1 MB. |
The full link-preview string is Mozilla/5.0 (compatible; TapCubBot/1.0; +https://tapcub.com/bot) link-preview. The other three include (+https://tapcub.com/bot) after the version.
Server-to-server deliveries
These user agents never browse pages. They send a JSON POST to an endpoint that a TapCub customer configured, such as their own webhook URL or an ad platform's conversion API.
| User agent | Purpose |
|---|---|
TapCub-Webhook/1.0 | Webhook events configured in the console or the API. |
TapCub-Automation/1.0 | Webhook actions in automations. |
TapCub-Notifier/1.0 | Alert and report notifications sent to a webhook channel. |
TapCub-DSAR/1.0 | Status callbacks for data subject requests. |
TapCub-AuditPush/1 | Audit log streaming to a SIEM or log system. |
TapCub-Postback/1.0 | Conversion postbacks to ad platforms the customer connected. |
When a signing secret is set, the request carries an X-Webhook-Signature: sha256=… header (HMAC-SHA256 of the raw body). Verification steps are in the webhook docs.
TapCub-GeoUpdater/1.0 downloads IP geolocation databases from their publishers. It does not contact any other site.
robots.txt and blocking
These fetchers act on a request from a person, so they do not check robots.txt before fetching. The compliance fetcher reads your robots.txt as data; it does not treat the file as permission.
To block one, match its user agent at your server or CDN and return 403:
- TapCubBot: the chat message still arrives, just without a preview card.
- TapCubKB: the import fails and the customer sees an error.
- Sitemap and compliance fetchers: these only visit domains registered in a TapCub account. If someone registered your domain without your permission, tell us at [email protected] and we will look into it.
Verifying a request
All requests come from TapCub servers. We do not publish a fixed IP range yet. Anyone can copy a user agent string, so a request that claims to be TapCub may not be from us.
If you see unusual traffic, send the time (with time zone), the requested URL, the source IP and the full user agent to [email protected]. We will tell you whether it came from TapCub and, if it did, which feature sent it.
Also read