Skip to content

CookieWavebot ​

CookieWavebot is the scanner CookieWave uses to find the cookies and trackers on a website. It visits a site, records which cookies get set and by which scripts, and hands the result to the site's owner so their consent banner can list them accurately.

If you found this page from a line in your server logs, the short version: the bot only visits sites that someone has registered in CookieWave, it reads pages rather than data, and it comes from a small, fixed set of dedicated IP addresses you can allowlist.

How to identify it ​

User agent

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko;
CookieWavebot/1.0; +http://www.cookiewave.com/docs/cookiewavebot)
Chrome/131.0.6778.0 Safari/537.36

The CookieWavebot/1.0 token is the reliable part to match on. The Chrome version around it changes when the scanner's browser engine is updated.

IP addresses

18.199.216.17
18.184.126.154

All scanner traffic leaves through this small, fixed set of dedicated IP addresses, so it can be allowlisted. They are stable and used exclusively by CookieWavebot, but if you build automation around them, match the user agent as well — an IP can be replaced, the token will not be.

Two kinds of visit ​

Almost everything below describes a site scan: the owner of a site registered it in CookieWave and asked for its cookies to be audited.

The other kind is the cookie checker — a public tool where anyone types in an address and gets a one-page cookie report. Because the visited URL is chosen by whoever is using the tool rather than by a site owner acting on their own domain, the checker runs as an intermediary lookup, not as the registered-site scan described in the rest of this page: a single request to a single URL, in headless Chrome, following redirects, with the same address never re-checked within 24 hours. No sitemap is read, and nothing else on the site is touched. If you see exactly one visit from the address below and never a second, that is what it was.

What it does ​

  • Requests pages over plain HTTP first. If a page looks like it sets cookies from JavaScript, the same page is loaded again in headless Chrome so client-side cookies and tag managers are seen too.
  • Records each cookie: name, domain, path, lifetime, Secure / HttpOnly / SameSite flags, and which script or network request set it.
  • Notes the third-party hosts a page loads scripts from.
  • Takes one screenshot of the home page, shown in the site owner's dashboard.

On sites already running the CookieWave banner, the banner recognizes the scanner and grants all categories to it. Without that, the scan would only ever see the cookies that appear before consent — which is the smaller half of what an owner has to disclose. No consent record is written for these visits, and they are excluded from pageview counts and billing.

What it does not do ​

  • It does not index or retain page content for crawling or resale. The one exception is the home page screenshot noted above, stored for display in the site owner's dashboard.
  • It does not log in, submit forms, or click through checkout flows.
  • It does not follow links to other websites or crawl domains outside the registered domain. The URL list comes from your sitemap (see below). Pages may still load third-party resources the page itself requests — scripts, tags, fonts, analytics services — the same as they would for a visitor's browser.
  • It does not scan pages behind authentication.

Which pages it visits, and how often ​

Scans run when a site owner registers a domain and whenever they press Run new scan. Nothing is crawled continuously and there is no automatic re-scan — every visit traces back to someone asking for one. The free plan allows five scans per site per month and Start fifteen; Pro and Elite are unlimited under fair use.

URLs are discovered in this order:

  1. Sitemap: entries in your robots.txt
  2. /sitemap.xml, if robots.txt names none
  3. Your home page, if neither is reachable

The home page is always included, and the sample is spread across sections of the site rather than taken from the top of the sitemap. The number of URLs per scan is capped by the site owner's plan:

PlanURLs per scan
Free100
Start700
Pro5,000
Elite10,000

Request rate ​

A site scan takes at most five requests per minute per domain, with a short burst allowance of eight, unless your robots.txt sets a Crawl-delay — in that case the slower of the two limits applies. A checker visit is one request, and the same address cannot be re-checked for 24 hours. A 700-URL scan therefore spreads over a couple of hours rather than arriving at once.

robots.txt ​

Before a site scan, CookieWavebot fetches robots.txt and honors Disallow rules in the User-agent: * and User-agent: CookieWavebot sections, including wildcard paths. Crawl-delay, if set, is honored too — see Request rate.

User-agent: CookieWavebot
Disallow: /internal/
Disallow: /*.pdf

The cookie checker does not read robots.txt. As noted above, it runs as an intermediary lookup rather than a crawl: it fetches the single address a person typed into a form — the same request their browser would have made — and nothing else.

It may show up in your analytics ​

The second pass is a real browser: it executes JavaScript and loads third-party tags, so an analytics or tag-management tool can record it as a visit. It is a handful of sessions per scan, not ongoing traffic. Exclude it the same way you exclude other bots — by user agent (CookieWavebot) or by the IP addresses above.

Allowlisting ​

If your site is registered in CookieWave and your WAF, bot manager or CDN is challenging or blocking the scanner, the symptom is a scan that finds no cookies, or far fewer than the site really sets. Allow either the CookieWavebot user agent or the IP addresses, on the paths you want audited.

Cloudflare, as an example: Security → WAF → Custom rules, skip for http.user_agent contains "CookieWavebot".

Blocking it ​

Block the IP addresses, or return 403 to the user agent. Nothing breaks on your site — but scans of it stop returning useful results, so the cookie list in the banner will drift out of date. If the site is yours and you want it to stop being scanned altogether, removing it from the CookieWave account is the cleaner route.

Questions ​

Something in a scan looks wrong, or the bot is behaving in a way this page does not describe? Write to support@cookiewave.com with the date, the URL and the log lines, and we will look into it.

CookieWave consent management