spanly-enrich

What this client asked www.pathwren.workers.dev for, when, and what it got. Every number below is from this host's own server-side request log, 2026-09-01 11:44:27Z to 2026-09-01 11:44:28Z UTC.

spanly-enrich/1.0 (+https://spanly.com)

11 request(s) from 1 distinct address(es), 7 distinct path(s), first seen 2026-09-01 11:44:27Z, last seen 2026-09-01 11:44:28Z UTC. 1 separate visit(s), counting a gap of more than 30 minutes as a new one.

The user-agent strings, exactly as they arrived

user-agentrequestsaddressesfirst seenlast seen
spanly-enrich/1.0 (+https://spanly.com)1112026-09-01 11:44:27Z2026-09-01 11:44:28Z

What it asked for, in the order it asked

First request to each path, oldest first.

#pathat (UTC)status
1/.well-known/oauth-protected-resource2026-09-01 11:44:27Z404
2/.well-known/security.txt2026-09-01 11:44:27Z200
3/.well-known/oauth-authorization-server2026-09-01 11:44:27Z404
4/contact2026-09-01 11:44:27Z404
5/2026-09-01 11:44:27Z200
6/security2026-09-01 11:44:27Z404
7/about2026-09-01 11:44:27Z404

Everything it asked for

pathrequestsstatus codesfirstlast
/2200×22026-09-01 11:44:27Z2026-09-01 11:44:28Z
/about2404×22026-09-01 11:44:27Z2026-09-01 11:44:28Z
/contact2404×22026-09-01 11:44:27Z2026-09-01 11:44:28Z
/security2404×22026-09-01 11:44:27Z2026-09-01 11:44:28Z
/.well-known/oauth-authorization-server1404×12026-09-01 11:44:27Z2026-09-01 11:44:27Z
/.well-known/oauth-protected-resource1404×12026-09-01 11:44:27Z2026-09-01 11:44:27Z
/.well-known/security.txt1200×12026-09-01 11:44:27Z2026-09-01 11:44:27Z

What it asked for that did not exist

path it asked forwhat it gotfirst askedsince then
/.well-known/oauth-protected-resource404×12026-09-01 11:44:27Zstill absent — on purpose: No
/.well-known/oauth-authorization-server404×12026-09-01 11:44:27Zstill absent — on purpose: No
/contact404×22026-09-01 11:44:27Zstill absent
/security404×22026-09-01 11:44:27Zstill absent
/about404×22026-09-01 11:44:27Zstill absent

What it got, and what it sent

Status codes
404×8, 200×3
Accept headers
text/plain, text/html, */*, application/json, */*
Bytes served
53564
Attributed to a channel
none — it arrived at a plain path
Our instrument classed it
agent×11 — that is our classifier's label from the user-agent, not the operator's, and it has been wrong before.

How to verify it is really them

Not observed. This client publishes no address list we could read and no reverse-DNS convention we could test, so the user-agent is the only identity it has here — and a user-agent is a claim, not a proof. Anyone can send this string.

What it publishes about you afterwards

Not observed. We have not seen this client publish a grade, a listing or a record about this host anywhere, and we make no claim that it does or does not.

Its own documentation

It names https://spanly.com in its own user-agent. That is the operator's own claim about itself; we neither endorse nor verify what is on it.

This page as data

curl -s https://www.pathwren.workers.dev/bot/spanly-enrich.json
curl -s https://www.pathwren.workers.dev/data/observed-clients.json   # every client, one request

JSON · markdown · all clients seen here · index as JSON

Method, and what this page will not say

Rows come from a server-side log written before anything is served, so clients that run no JavaScript are counted exactly like browsers. The window is the whole life of the log, 2026-09-01 11:44:27Z to 2026-09-01 11:44:28Z UTC, and it is stated on every number because a count without a window is not a fact. Addresses are stored as salted hashes and counted, never printed. Our own checks send X-Self: 1 and are excluded, together with every request the analyst flagged as one of our own agents reaching for a URL through a model provider's fetch tool (the numbers are on the index). Nothing here is a claim about intent: where this page does not know something it says not observed.