Overview
Apple App Site Association Bot is a service bot associated with Apple, used to fetch association metadata for iOS Universal Links.
Its primary user-agent pattern is AASA-Bot/; related patterns include AASA-Bot/1.0.0; Apple AASA bot; a representative HTTP user-agent is AASA-Bot/.
Apple App Site Association Bot is unverified with Low confidence. The identity type is Documented. This legacy or noncanonical identity is retained for historical log matching.
Robots.txt behavior for Apple App Site Association Bot is not confirmed. Do not treat a user-agent-only rule as guaranteed enforcement.
Use the canonical family record for current policy decisions; retain this pattern only for historical log matching.
Treat the user-agent or identity as a claim and corroborate it with published network data, reverse DNS, signed-request evidence, or current operator documentation when available.
Identity
- User-Agent Pattern
-
AASA-Bot/ - Aliases
- AASA-Bot/1.0.0; Apple AASA bot
- HTTP Agent Examples
-
AASA-Bot/ - Robots Token
- AASA-Bot/
- Identity Type
- Documented
- Evidence Method
- Verify Apple App Site Association Bot by matching `AASA-Bot/` to Apple evidence, then corroborating the request with source-network ownership, reverse DNS, signed request data, or current operator documentation.
Classification
- Type
- Service bot
- Kind
- Service bot
- Family
- Apple
- Purpose
- Universal links verification
Behavior and handling
- Common Use
- Apple App Site Association Bot fetches association metadata used by iOS Universal Links.
- Detection Notes
- Apple App Site Association Bot traffic is primarily detected by `AASA-Bot/`; related patterns include `AASA-Bot/1.0.0; Apple AASA bot`; a representative HTTP user-agent is `AASA-Bot/`. Treat these values as identification claims and corroborate them with source-network ownership, reverse DNS, signed request data, or current operator documentation.
- Respects robots.txt
- Unknown
- Spoofing Risk
- Apple App Site Association Bot can be spoofed if identification relies only on a user-agent string; corroborate the request with stronger operator-controlled evidence when available.
- Risk
- Neutral
- Recommended Handling
- Monitor
Rules and controls
- Robots.txt Snippet
-
# Legacy or noncanonical identity. Confirm the current canonical token before relying on robots.txt.
Relationships
- Operator
- Apple Checked 2026-08-02
Relationships without an Evidence link are normalized from the canonical directory record. They should not be interpreted as independent proof of physical presence or request origin.