TestOptim Bot
The automated browser TestOptim uses to explore and test web applications on behalf of our customers.
What it does
TestOptim is an AI-powered QA platform. When a customer adds their web application as a project, our bot opens it in a headless Chromium browser to map its pages, generate test cases, run those tests and re-check reported issues. It clicks, fills forms and logs in with credentials the customer provides, the way a QA engineer would.
It is not a crawler. It does not index the public web, and it only visits sites that a TestOptim customer has added to their own account.
When it visits
- When a customer creates a project or starts an exploration.
- When a customer runs tests, manually or on a schedule.
- When an issue is re-verified after a fix.
Each session behaves like a single user working through the application, at human scale rather than crawl scale.
How to identify it
Every request is signed with Web Bot Auth (HTTP Message Signatures, RFC 9421) using an Ed25519 key. Signed requests carry these headers:
Signature-Agent: "https://api.testoptim.com"Signature-Inputwithtag="web-bot-auth", covering@authorityandsignature-agentSignature
Our public keys are published at https://api.testoptim.com/.well-known/http-message-signatures-directory. A request is from TestOptim only if its signature verifies against one of those keys. The User-Agent header is a standard Chrome string, so do not rely on it alone.
Allowing or blocking it
On Cloudflare, verified TestOptim traffic can be allowed or blocked with WAF custom rules that match verified bots or signed agents. Outside Cloudflare, verify the signature against the key directory above.
Because the bot only tests applications that a customer has added, the quickest way to stop visits to your site is usually to contact whoever set up the TestOptim project. If you don't know who that is, email us and we will look into it.
Contact
Questions or abuse reports: hi@testoptim.com. Include the affected domain and the time of the requests.