All crawlers

Moonshot AI · Answers

Kimi-User

Someone in a Kimi session pastes a link and asks what it says; that is the whole trigger, and Moonshot's own examples are summarising a specific article or answering a question that needs live web retrieval. The resulting traffic is the inverse of its two siblings': sparse, bursty, one page deep, and paced by human demand rather than a crawl calendar. What network verification cannot do is confirm that shape: the range file published at this agent's own URL, `kimi-user.json`, returns the same four `/32` host addresses as the files published under the other two agents' names, down to a shared `creationTime`. An address match therefore places the request inside Moonshot's fleet and leaves the choice between its three agents to the user-agent header, which anyone can type.

Operated by
Moonshot AI
Purpose
Answers

Fetches a page in real time to answer a question someone just asked.

robots.txt token
Kimi-User
Verification
IP verified

How to verify Kimi-User

Moonshot AI publishes the IP ranges Kimi-User crawls from, and we fetch that list on a schedule. A request claiming to be Kimi-User can therefore be checked against 4 published ranges: one that does not match is not this crawler.

Published ranges last confirmed by us on .

User agent

Moonshot AI publishes this user agent for Kimi-User. Match on the Kimi-User product token rather than the whole string: vendors revise the surrounding version and URL fragments without notice.

Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Kimi-User/1.0; +https://www.kimi.com/policies/kimi-crawlers

robots.txt for Kimi-User

Qualified, and Moonshot is unusually candid about the qualification. Its policy applies robots.txt to its crawlers in general, then adds for this token specifically that "because actions are user-triggered, robots.txt rules may not directly apply". So a disallow here is a signal the vendor may honour rather than a rule it binds itself to: worth knowing before you rely on one.

Block

User-agent: Kimi-User
Disallow: /

Allow

User-agent: Kimi-User
Allow: /

robots.txt is a request, not an enforcement mechanism. It is honoured by convention, and a crawler that ignores it is stopped at your edge, not in a text file.

What blocking Kimi-User costs you

When a person hands Kimi your URL and asks what is on it, a block turns that into a failed fetch and an answer drawn from stale index data or from nothing, and the person had already chosen you by name, which is warmer intent than an index impression. Moonshot's own phrasing is that disallowing "may reduce your site's visibility in user-directed web searches performed through our products". Set that against the caveat it attaches in the same document, that robots.txt "may not directly apply" to user-triggered actions. The uncomfortable consequence is that you can absorb the loss without acquiring the control.

Vendor documentation

Other Moonshot AI tokens we track