Website capture bot
What CookieBeam captures and how to allow it through your site's protection.
CookieBeam captures a public homepage when an editor uses the designer's website preview or Match my website, and when the editor refreshes an old capture. It reads brand colours, fonts, shapes and logo candidates, and takes screenshots for the private designer preview. It does not sign in, submit forms or solve security challenges.
Identify capture requests
Browser captures use the bundled Chromium browser's actual major version in the user agent, followed by:
CookieBeamCapture/1.0 (+https://cookiebeam.com/capture-bot)
Direct HTML, stylesheet and logo requests use that same identifying token without claiming to be a browser. They parse styles without executing site scripts. Do not treat a user-agent token as authentication: other clients can copy it.
Allow capture through your protection
In your CDN or WAF's bot settings, add a narrowly scoped rule that allows the user agent containing CookieBeamCapture to read your public homepage and its public styles and images. Apply your normal rate limits and keep login pages and private endpoints protected. Ask your firewall administrator to check whether an existing rule blocks those requests.
CookieBeam does not currently publish capture IP ranges. Publishing stable, verified egress ranges is a follow-up; do not assume requests come from a fixed address.
When the browser cannot capture
CookieBeam stops when it recognises a bot challenge. It can read public HTML and styles directly instead, without a screenshot. It can also use a public web archive snapshot from the last twelve months; the designer labels that capture with its snapshot date. Archived styles can differ from your current site.
If neither source is usable, choose Continue with brand colours and enter your primary, background and text colours and a font. An optional logo URL uses the designer's existing safe logo download flow. Those inputs feed the same style suggestions, with no screenshot.