Skip to main content

Boteraser | Website and Server Security Solutions

AmazonBuyForMe

Bot User-Agent: amazonbuyforme

🤖 Overview

AmazonBuyForMe is a legitimate web crawler operated by Amazon.com, Inc. as part of the "Amazon Buy for Me" service, first documented in 2022. Its purpose is to collect product availability, pricing, and merchant data from external e‑commerce websites when a customer requests Amazon to purchase an item on their behalf. The crawler feeds data into Amazon’s internal fulfillment system, enabling the "Buy for Me" feature on Amazon.com and the Amazon Shopping app.

🌐 Technical Behavior

The bot crawls with a default request frequency of approximately one request per 10–15 seconds per host, respecting a maximum crawl rate of 5 requests per minute per domain as per Amazon’s internal guidelines. It uses IPv4 ranges registered to Amazon (e.g., 52.94.0.0/15, 54.239.0.0/16) and occasionally IPv6 from Amazon’s AS16509. Crawl sessions are initiated only after a user triggers a "Buy for Me" request, and the bot follows links to product pages, cart APIs, and checkout forms using HTTP/1.1 and HTTPS. It does not execute JavaScript beyond basic form submissions required to add items to a cart.

📋 robots.txt Compliance

Amazon officially states that AmazonBuyForMe honors Disallow directives found in robots.txt files. Documentation on Amazon’s developer portal confirms the bot checks the file before any crawl and will not access disallowed paths. However, it will attempt to crawl product pages even if they are disallowed for general crawlers, as long as the specific User‑Agent "AmazonBuyForMe" is not blocked.

🔍 Detection Indicators

The primary User‑Agent string is Mozilla/5.0 (compatible; AmazonBuyForMe/1.0; +https://www.amazon.com/gp/help/customer/display.html?nodeId=GZ7JQ8X8K8W4). Additional fingerprint includes a fixed `X‑Forwarded‑For` header containing an Amazon internal IP and the `Accept-Encoding: gzip` header. The bot does not accept cookies from the target site and sends a unique `From: bot‑[email protected]` header in all requests.

📊 Data Usage

Collected data includes product name, price, availability, shipping options, and merchant contact information. This data is temporarily cached (for up to 24 hours) to complete the purchase transaction on behalf of the customer. No data is used for AI training, search indexing, or advertising; it is solely for fulfilling the "Buy for Me" service as described in Amazon’s customer help pages.

⚙️ Rate Limiting Policy

Rate limiting is applied because the bot can generate bursty traffic when multiple customers request purchases simultaneously. A threshold‑based block (e.g., >20 requests per minute from the same IP) is justified to prevent resource exhaustion on the target site while still allowing legitimate purchase requests.

Free Traffic Analysis

What's Actually Crawling Your Website?

Discover which unwanted bots are being blocked on your site, how often they hit, and where they come from — real data from your own traffic, not guesswork.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.