Bytespider: what it is, what it does with your content, and what blocking it costs

ByteDanceModel training

What Bytespider is

Bytespider collects pages to train future models. It does not decide whether ByteDance can cite you in an answer today — that is a different crawler with a different token. Blocking Bytespider is a decision about your content being learned from, not about your visibility.

Operator: ByteDance
robots.txt token: Bytespider
User-agent on the wire: not published by the operator
Category: Model training

What blocking it actually costs

Excludes your content from ByteDance's model training. Widely reported to crawl aggressively and to honour robots.txt inconsistently, so a block here is worth pairing with a rule at the edge.

How to block Bytespider

Add this to your robots.txt:

User-agent: Bytespider
Disallow: /

The token must appear on its own User-agent: line. A named group replaces the User-agent: * group rather than adding to it, so anything you also want disallowed for this crawler has to be repeated inside its group.

How to allow Bytespider

User-agent: Bytespider
Allow: /

An explicit allow is worth writing even when you have no blanket block: it documents the decision, and it survives someone later adding a restrictive User-agent: * rule without thinking about AI crawlers.

robots.txt is not the only thing that can block it

A permissive robots.txt does not mean Bytespider can reach you. WAF rules, Cloudflare's bot-management settings, rate limits and country blocks all sit in front of robots.txt and answer first. A site whose robots.txt welcomes Bytespider and whose edge returns 403 to it is blocked in every way that matters — and nothing in robots.txt will tell you so.

This is the gap the AI Crawler Access Checker was built to close: it reads robots.txt and sends a real request carrying the crawler's user-agent, so you see what the crawler sees.

Common questions

What user-agent does Bytespider send?

ByteDance does not publish an exact user-agent string for Bytespider. Match on the Bytespider token in robots.txt rather than on a full string you found elsewhere.

How do I block Bytespider?

Add a group to robots.txt naming the token exactly:

User-agent: Bytespider
Disallow: /

The group must name Bytespider on its own line. A User-agent: * group does not combine with a named one — under RFC 9309 the most specific matching group replaces the wildcard entirely, it does not inherit from it.

What does blocking Bytespider cost me?

Excludes your content from ByteDance's model training. Widely reported to crawl aggressively and to honour robots.txt inconsistently, so a block here is worth pairing with a rule at the edge.

Can I tell a real Bytespider request from a fake one?

Not reliably. ByteDance does not publish verified IP ranges for Bytespider, so the user-agent string is the only signal, and anyone can send it. Treat robots.txt as a statement of policy rather than as enforcement.

Is Bytespider blocked on your site right now?

Reading your own robots.txt only answers half of it — a firewall rule can block Bytespider while robots.txt says it is welcome. The checker tests both.

Check your site free

Related crawlers