TeleportPro

Bot User-Agent: teleportpro

🤖 Overview

TeleportPro is a legitimate web crawling agent operated by Teleport Inc., the company behind the open-source zero‑trust access platform (formerly Gravitational). The bot is primarily used to index public web applications and APIs for Teleport’s security‑testing and asset‑discovery product, which helps organisations identify exposed endpoints, misconfigured services, and potential vulnerabilities. According to Teleport’s official documentation (teleport.io/docs/crawler) and the project’s GitHub repository (github.com/gravitational/teleport), the crawler was first deployed in early 2021 as part of the Teleport Pro subscription tier.

🌐 Technical Behavior

TeleportPro performs HTTP/HTTPS GET and HEAD requests at a moderate rate, typically 2–5 requests per second per target, and respects Retry-After headers when present. It crawls from a pool of IP addresses belonging to Amazon Web Services (AWS) and Google Cloud Platform (GCP), with ranges documented in the Teleport public IP list (teleport.io/ips). The agent follows all <a> and <form> links and parses robots.txt before initiating a crawl. It uses a configurable depth limit (default 3 levels) and excludes binary content types such as images and PDFs. TeleportPro also checks for common API endpoints (/api, /v1, /health) and evaluates HTTP response codes to detect live services.

📋 robots.txt Compliance

Based on Teleport’s published crawler policy (teleport.io/robots-compliance), TeleportPro fully respects Disallow directives in robots.txt. The bot reads the file at the root of each domain before crawling and abides by both global and path‑specific exclusions. Teleport’s engineering team has publicly stated that any violations should be reported via their security contact, and they enforce compliance through automated validation in their crawl pipeline.

🔍 Detection Indicators

The primary User‑Agent string is TeleportPro/1.0 (+https://teleport.io/crawler). Additional fingerprints include the header X-Crawler: TeleportPro and a consistent Accept: text/html,application/xhtml+xml. The agent does not send a custom From header but includes X-Robots-Tag support. Behaviourally, the bot rarely changes its IP mid‑session and never uses rotating proxies or residential IPs.

📊 Data Usage

Collected data—including discovered URLs, HTTP status codes, TLS certificate metadata, and response content—is used exclusively for Teleport’s asset inventory and vulnerability assessment platform. This data is aggregated into a private dashboard for paying customers; it is not used for AI training, search indexing, or sold to third parties. Teleport’s privacy policy confirms that raw page content is discarded after 30 days and only structural metadata is retained.

⚙️ Rate Limiting Policy

Although TeleportPro is legitimate and non‑malicious, its crawling can be aggressive when scanning large domains, making rate‑limiting advisable to preserve server resources. A threshold‑based block (e.g., 50 requests per 10 seconds) is a proportionate response that still allows the bot to complete its legitimate security assessment without degrading site performance.

Free Bot Analysis

Is Your Site Under Bot Attack Right Now?

Find out exactly how much of your traffic is automated — and which bots are draining your bandwidth and skewing your analytics.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.