ScoutSentinelScoutSentinel
Menu

Synthetic traffic

Seeing requests from ScoutSentinel?

Our customers ask us to test their journeys from the outside. Here’s how to recognise those requests, allowlist them safely, or ask us to stop.

What the traffic is

Probes run a short, fixed sequence of steps that a customer of ours approved: load a page, fill a form with synthetic test data, call an API, complete a purchase with a payment provider test card. Runs repeat on a schedule (typically every 1 to 15 minutes) from a small number of locations. Probes do not crawl, scan ports, test credentials or exceed the steps in the approved plan.

How to identify it

MarkerValue
User agentScoutSentinel/0.1 (+https://www.scoutsentinel.com/synthetic), sent by HTTP and API probes and used as the Chromium user agent by browser probes
Request headerX-ScoutSentinel-Probe: <probe run id>, present on every request a probe makes; the id identifies the exact run and its evidence
Customer markerOptionally a query parameter (default name scoutsentinel) or a header the customer chose, carrying a value only the customer and ScoutSentinel know
SourceCloudflare edge addresses, or published egress ranges for ScoutSentinel regional runners

The X-ScoutSentinel-Probe value is a correlation id, not a credential: it lets us, and our customer, match a request in your logs to one specific probe run. Anyone can copy a header, so allowlisting should rely on the customer marker and, for regional runners, the published egress ranges.

How to allowlist it

  1. Prefer the customer marker: allow requests carrying the configured value in the query string or header. It is changed from the ScoutSentinel app.
  2. Use the X-ScoutSentinel-Probe header to recognise and log probe traffic, not as the sole allowlist condition.
  3. For regional runners, allow the published egress ranges as a second factor.
  4. Do not allowlist by user agent alone; anyone can send that string.

Bot protection that challenges a probe does not break anything on your side; it records an unknown outcome for our customer with the reason blocked_by_bot_protection. Detailed guidance for customers is in the documentation.

Keeping it out of your analytics

Exclude the user agent or the marker from analytics and conversion reporting. Orders created by a probe use payment provider test cards and can be tagged using the marker so fulfilment ignores them.

How to opt out

If this traffic reaches a site you operate and you did not ask for it, email security@scoutsentinel.com with the hostname and, if you have them, a sample of the X-ScoutSentinel-Probe header values. We will identify the customer, verify domain control, and pause the Watch while we do so. We treat requests from a domain's own contacts as authoritative.

Customers may only point Watches at surfaces they own or are authorised to test; our terms make that a condition of use. We may suspend a Watch that a site owner objects to.

Contact

Abuse and opt-out: security@scoutsentinel.com. General questions: hello@scoutsentinel.com. Our policies: trust centre, privacy, terms.