Consent Scan
What is Baromio-ConsentScan?
Baromio-ConsentScan is the user agent our Consent Scan feature uses when it loads a page to observe which cookies it sets before and after visitors accept a cookie banner. If you found this page from a user agent string in your logs or your bot protection dashboard, this explains what it is.
The user agent
Every request the scanner makes appends the following to a standard headless Chrome user agent string:
Baromio-ConsentScan/1.0 (+https://baromio.io/consent-scan-bot)
The Chrome version number in the rest of the string changes as we update the browser the scanner runs. The "Baromio-ConsentScan" text is the stable part - match on that substring rather than the full string.
What it does and why
A Baromio customer who monitors your site with a Consent Scan enabled asked Baromio to check which cookies the page sets, once a week, before and after a visitor responds to its cookie banner. Every weekly scan loads the page twice: once to record cookies before any consent action, and once more after the scanner accepts the banner (when one is found) to record cookies afterwards. It reads cookies and page content; it never submits forms, signs in, or stores a cookie's value - only that the cookie exists.
Where it runs from
Consent Scan primarily runs from Baromio's own server infrastructure, with an additional fallback runner on Cloudflare's network for scans the primary runner cannot complete. Because more than one location can produce a scan, and that may change over time, Baromio does not publish a fixed IP address or IP range for it. If your bot protection allows rules based on the request header, allow it by user agent instead of by IP.
How to allow it through your WAF or bot protection
Most bot protection and CDN products, including Cloudflare, let you skip a rule or challenge for requests whose user agent contains a given substring. Add a rule that matches when the user agent contains:
Baromio-ConsentScan
For example, in Cloudflare this is a WAF custom rule with a condition such as "User Agent contains Baromio-ConsentScan" and an action of "Skip" for the managed challenge or bot fight mode. Other WAF and CDN products use similar user-agent allowlist rules under their bot protection settings.
What allowing it does not mean
Allowing Baromio-ConsentScan through your bot protection only lets the scan run and produce results. It is not a legal check, a certification, or a guarantee about your site's cookies or your legal obligations. Baromio only ever reports what it observed on one page at one moment - never a verdict.
FAQ
Frequently Asked Questions
Does allowing Baromio-ConsentScan mean my site meets cookie consent law?
No. Baromio only reports what it observed on one page at one moment, from one location. It never issues a legal verdict, a pass/fail result, or a certification, for your site or your client's. Whether a cookie needs consent depends on its purpose and on your own legal reading, which no automated scan can determine.
Will allowing this user agent let anyone else in?
No. An allowlist rule matched on the exact user agent string only affects requests that send that string. Baromio does not publish this string to third parties, but a rule based on it alone is not a strong access control - pair it with your WAF's other protections if that matters to you.
Can I allow Baromio by IP address instead?
Baromio does not publish a fixed IP address or IP range for Consent Scan, because the scan can run from more than one location and that may change over time. Allow the user agent instead.
What does the bot actually do on my page?
It loads the page in a headless browser, records which cookies are present, looks for a cookie consent banner, and if one is found, tries to accept it and records which cookies are present afterwards. It does not fill in forms, log in, or click anything other than a consent banner's accept control.
How often does it visit?
Once a week per monitor with Consent Scan enabled, with two page loads on that visit: one before consent and one after. A site owner can also trigger an extra scan manually, which is limited to once per hour per monitor.