Moonshot AI
Kimi-User
What it is
Kimi-User fetches a URL for a specific Kimi user request. Aiola classifies it as AI answers because access happens on demand.
In Aiola's taxonomy, AI answers means fetched to answer a user's question now.
User agent
Look for the match token inside the complete HTTP User-Agent header. Tokens can be spoofed, so use the network checks below for authentication.
Kimi-UserKimi-UserOfficial IP ranges
Moonshot AI has not published official IP ranges that Aiola successfully fetched for Kimi-User. Aiola does not list cloud-provider ranges or community guesses as if they authenticated this crawler.
Verify authenticity
Start with the source IP recorded by your trusted edge or server, not an untrusted forwarded header.
host REQUEST_IP
# Confirm the hostname ends in an official suffix
host RETURNED_HOSTNAME
# The forward lookup must return REQUEST_IPFor production checks, test against every current prefix in the vendor feed. Re-fetch feeds regularly: a July 2026 snapshot is evidence of publication, not a permanent firewall list.
Control it with robots.txt
Kimi-User is user-triggered. Moonshot AI's controls may differ from automated crawling, so do not assume a robots.txt block is an authentication boundary.
User-agent: Kimi-User
Allow: /User-agent: Kimi-User
Disallow: /No official crawler documentation URL is listed because Aiola could not verify one confidently.
Track it
Aiola tracks this crawler on your site — crawls, pages, trends. See when Kimi-User arrives, which URLs it requests, and how activity changes over time.
Explore Aiola AnalyticsFAQ
What is Kimi-User?
Kimi-User fetches a URL for a specific Kimi user request. Aiola classifies it as AI answers because access happens on demand.
What user-agent token identifies Kimi-User?
Match the case-insensitive token “Kimi-User” in the User-Agent header. A matching header alone does not authenticate the sender.
Can I verify Kimi-User by IP address?
No official Kimi-User CIDR snapshot was successfully fetched for this verification date. Do not treat an arbitrary cloud IP as proof of identity.
Can robots.txt block Kimi-User?
Kimi-User is user-triggered. Moonshot AI's controls may differ from automated crawling, so do not assume a robots.txt block is an authentication boundary. Use the specific “Kimi-User” group when you want a rule for this identity without changing rules for every crawler.