SeismologBot

SeismologBot is the crawler of Seismolog, a public, append-only log of how websites publish their standards for agent discovery (DNS-AID, UCP, A2A agent cards, MCP server cards, Agent Skills, OAuth metadata, Web Bot Auth, payment declarations, DNSSEC, DANE). It records what a site publishes and when that changes. It does not score, rank or judge anyone.

It identifies itself like this:

User-Agent: Mozilla/5.0 (compatible; SeismologBot/1.0; +https://seismolog.org/bot)

What it fetches

What it keeps

When what a site publishes changes, Seismolog adds an entry to its public log. The entry holds only metadata and hashes, never the content itself. The exact request and response behind the entry are kept as evidence (a WARC file) so that anyone can check the entry later.

How to block it

Use robots.txt only, as specified in RFC 9309. The product token is SeismologBot:

User-agent: SeismologBot
Disallow: /

IP addresses

SeismologBot sends all requests from fixed addresses. Our DNS resolver and our transparency log (its witness requests) use the same addresses; those are not SeismologBot requests and carry no signature. The list is machine-readable at https://seismolog.org/bot/ranges.json (format of the IETF draft JAFAR, refreshed at least daily):

2.31.48.98/32

The reverse DNS name of these addresses is egress1.seismolog.org, which resolves back to them.

Signed requests

Every request of SeismologBot is signed with Web Bot Auth (HTTP Message Signatures, RFC 9421), so nobody else can pose as SeismologBot. A request carries:

Signature-Agent: sig1="https://seismolog.org"
Signature-Input: sig1=("@authority" "signature-agent";key="sig1");created=...;keyid="Swvaun1uOgF8ET7PziTOJPfO_Ag9wqHnykySJMup_CQ";alg="ed25519";expires=...;nonce="...";tag="web-bot-auth"
Signature: sig1=:...:

To verify one, fetch the key directory at https://seismolog.org/.well-known/http-message-signatures-directory (media type application/http-message-signatures-directory+json), take the key whose thumbprint (RFC 7638) is the keyid and check the signature over the @authority and the Signature-Agent member as RFC 9421 describes. The directory response is itself signed by its key. The current key id is Swvaun1uOgF8ET7PziTOJPfO_Ag9wqHnykySJMup_CQ. Signatures are valid for five minutes.

Contact

Questions, complaints and requests concerning personal data: ops@seismolog.org.