Pingaroo monitoring bot
PingarooBot performs the HTTP uptime checks configured by Pingaroo customers for websites they manage.
Request identity
User-Agent
PingarooBot/1.0 (+https://pingaroo.dev/bot)Method
GETWeb Bot Auth
Redirects
Up to five; private and reserved network destinations are rejected.
Uptime requests use short-lived Ed25519 HTTP Message Signatures for Web Bot Auth. A customer-specific X-Pingaroo-Monitor credential may also be sent as a WAF fallback; it is removed before an off-site redirect.
Cloudflare
Pingaroo signs monitoring requests using Cloudflare Web Bot Auth and publishes its verification keys above. Cloudflare Verified Bot registration removes the need for customers to weaken bot protection.
Until verified-bot recognition is active everywhere, customers using Super Bot Fight Mode or WAF rules can use the narrowly scoped Skip expression from their Pingaroo site page.