Moonshot AI · Answers
Kimi-User
Someone in a Kimi session pastes a link and asks what it says; that is the whole trigger, and Moonshot's own examples are summarising a specific article or answering a question that needs live web retrieval. The resulting traffic is the inverse of its two siblings': sparse, bursty, one page deep, and paced by human demand rather than a crawl calendar. What network verification cannot do is confirm that shape: the range file published at this agent's own URL, `kimi-user.json`, returns the same four `/32` host addresses as the files published under the other two agents' names, down to a shared `creationTime`. An address match therefore places the request inside Moonshot's fleet and leaves the choice between its three agents to the user-agent header, which anyone can type.
- Operated by
- Moonshot AI
- Purpose
- Answers
- robots.txt token
- Kimi-User
- Verification
- IP verified
Fetches a page in real time to answer a question someone just asked.
How to verify Kimi-User
Moonshot AI publishes the IP ranges Kimi-User crawls from, and we fetch that list on a schedule. A request claiming to be Kimi-User can therefore be checked against 4 published ranges: one that does not match is not this crawler.
Published ranges last confirmed by us on .
User agent
Moonshot AI publishes this user agent for Kimi-User. Match on the Kimi-User product token rather than the whole string: vendors revise the surrounding version and URL fragments without notice.
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Kimi-User/1.0; +https://www.kimi.com/policies/kimi-crawlersrobots.txt for Kimi-User
Qualified, and Moonshot is unusually candid about the qualification. Its policy applies robots.txt to its crawlers in general, then adds for this token specifically that "because actions are user-triggered, robots.txt rules may not directly apply". So a disallow here is a signal the vendor may honour rather than a rule it binds itself to: worth knowing before you rely on one.
Block
User-agent: Kimi-User
Disallow: /Allow
User-agent: Kimi-User
Allow: /robots.txt is a request, not an enforcement mechanism. It is honoured by convention, and a crawler that ignores it is stopped at your edge, not in a text file.
What blocking Kimi-User costs you
When a person hands Kimi your URL and asks what is on it, a block turns that into a failed fetch and an answer drawn from stale index data or from nothing, and the person had already chosen you by name, which is warmer intent than an index impression. Moonshot's own phrasing is that disallowing "may reduce your site's visibility in user-directed web searches performed through our products". Set that against the caveat it attaches in the same document, that robots.txt "may not directly apply" to user-triggered actions. The uncomfortable consequence is that you can absorb the loss without acquiring the control.