xAI
xAI-Bot
The family name xAI's own robots.txt examples use.
When you see it: A fetch from xAI that does not name its job. The operator is known and the purpose is not, so it is counted as xAI traffic without entering either AI figure.
How we check it is really xAI
- 01
The user agent has to contain xAI-Bot.
xAI publishes neither IP ranges nor a reverse DNS record, so this is the honest ceiling: the visit is recorded as a claim. We would rather show you an unverified row than a tick we cannot back.
What each result means
- verified
- The address matched xAI's own published records. This really was them.
- unverified
- We could not confirm it, and that is all it means. The operator may publish nothing to check against, a published list may be behind the addresses actually in use, or DNS may simply have been slow. It is not an accusation.
- spoofed
- The address belongs to somebody else — its own reverse DNS record resolves to a different owner. That is positive evidence of a forgery rather than a failure to find evidence, which is why it is reported as its own result and never folded into the row above.
The distinction costs nothing to make and is the reason these numbers can be shown to someone who will ask where they came from. A report that cannot separate “we do not know” from “this was faked” invites exactly one question it cannot answer.
No list to check against
xAI publishes neither an address file nor a reverse DNS record for this crawler. There is nothing to check a request against, which is why every visit from it is recorded as an unverified claim.
- Operator
- xAI
- Token
- xAI-Bot
- Counted as
- Other bots
- Verification
- User agent only
- Runs JavaScript
- No
- Operator docs
- None published
xAI publishes no crawler documentation. This token is recognised from observed traffic and community lists, so treat the classification as our reading rather than the operator's statement.
User agent
xAI-BotMatched as a token, not as a full browser string. xAI adds and changes the version and product text around it without notice, so a filter pinned to the whole header stops working the first time they bump a version while one matching xAI-Bot keeps working. The same string is what xAI names in robots.txt.
xAI's other crawlers
xAI sends 5 crawlers, each with its own token and its own job. They are counted separately for that reason — the tokens differ by a few characters and what the fetch means does not, so folding them into one operator row would let indexing look like AI interest.
| Token | Counted as | Verification | What it fetches for |
|---|---|---|---|
xAI-Botthis page | Other AI traffic | User agent only | The family name xAI's own robots.txt examples use. |
| xAI-SearchBot | AI answers | User agent only | Grok fetching a page while answering. |
| Grok-DeepSearch | AI answers | User agent only | Grok's deep research mode gathering sources for a long answer. |
| xAI-Grok | Indexing | User agent only | Retrieves and indexes pages so Grok can find them later. |
| GrokBot | Training | User agent only | xAI's training crawler, signed with its own address at x.ai. |
Your analytics never mentioned xAI-Bot because it cannot see it.
This crawler takes your HTML and leaves without running a line of JavaScript, so a browser tag records nothing. TrueStat reads it server-side, checks the address, and shows you which pages it fetched — including the ones that returned a 404.