Bot intelligence record

TikTok

Usually allow

TikTok is a link preview bot from ByteDance used for link unfurling, rich-card generation, social previews, messaging previews; it appears in server logs as `TikTok`.

Preview Verified Bot Confidence: Medium Verified: Yes robots.txt: Yes
Operator
ByteDance
Family
ByteDance
Type
Preview
Source type
Documented
Last checked
2026-05-20

User-Agent Pattern

ByteDance
TikTok
Verification note

User-agent strings are identification signals, not proof of identity. Confirm important allow, block, or rate-limit decisions with logs, DNS or IP evidence, request behavior, or operator documentation when available.

Robots.txt Snippet

Click snippet to copy
User-agent: TikTok
Disallow: /

Click the snippet to copy it, or highlight the text manually.

Handling Guidance

Depends

This bot is usually safe to allow when the request source is verified and the traffic matches your site policy.

TikTok is used for link unfurling, rich-card generation, social previews, messaging previews, and page metadata fetching.

Record Details

Structured data
Operator
ByteDance
Family
ByteDance
Type
Preview
Purpose
Preview
Identity type
Verified Bot
Confidence
Medium
Last verified
2026-04-29
Last checked
2026-05-20
Source type
Documented
Verification
Verify TikTok by matching `TikTok` to ByteDance evidence, then checking reverse DNS, source-network ownership, signed request data, or published crawler documentation when available.
Spoofing risk
TikTok has medium spoofing risk because user-agent strings can be copied; pair the match with DNS, IP, behavior, or operator evidence.

Notes

  • TikTok is a link preview bot from ByteDance used for link unfurling, rich-card generation, social previews, messaging previews, and page metadata fetching.
  • Its primary user-agent pattern is TikTok.
  • TikTok is verified with Medium confidence. The identity type is Verified Bot, and the evidence basis is documented crawler-pattern evidence.
  • TikTok is marked as respecting robots.txt directives for crawler access control.
  • TikTok can usually be allowed after confirming the source and monitoring request volume.

Evidence and Source

  • Verify TikTok by matching `TikTok` to ByteDance evidence, then checking reverse DNS, source-network ownership, signed request data, or published crawler documentation when available.
  • TikTok traffic is primarily detected by the `TikTok` user-agent pattern. Compare source IPs, reverse DNS, request paths, and crawl cadence with ByteDance infrastructure before trusting the traffic.
  • TikTok is used for link unfurling, rich-card generation, social previews, messaging previews, and page metadata fetching.
  • TikTok has medium spoofing risk because user-agent strings can be copied; pair the match with DNS, IP, behavior, or operator evidence.

Monitor This Bot In Edge

Botcrawl Edge

Use Botcrawl Edge to see matching traffic, identify related datacenter activity, and create allow, block, rate-limit, or log rules across connected sites.