/ PROTOCOLS / WEB BOT AUTHVerified 7 Oct 2026

Web Bot Auth: a signature, not a permission.

Web Bot Auth is an IETF draft that lets an automated client, such as an AI agent, sign its HTTP requests and point to a published key directory, so a site can verify the signature instead of trusting a user-agent string or IP address. Cloudflare started the work. The IETF webbotauth working group adopted it as draft-ietf-webbotauth-httpsig-protocol-00 on 1 September 2026, with authors from Cloudflare and Google. It is not yet an RFC.

IETF working-group draftAdopted 1 Sep 2026Built on RFC 9421Not yet an RFC
/ 01How it works

What happens on the wire.

  1. 01

    Publish a key directory

    The operator serves its public keys as a JWKS at /.well-known/http-message-signatures-directory.

  2. 02

    Name where the key lives

    A required Signature-Agent header is a structured-field dictionary with one member per signature label, such as sig1="https://agent.example". Each member is an https URI with a type parameter for how to resolve it to keys; the default type is a key directory.

  3. 03

    Sign each request

    The client signs with the tag web-bot-auth, covering the target (@authority or @target-uri) and its own Signature-Agent member, for example ("@authority" "signature-agent";key="sig1"), with created and expires times. The draft recommends an expiry of no more than 24 hours. No required component covers the body.

  4. 04

    Verify

    The site resolves the Signature-Agent member that the signature covers, selects the key by its key ID, and checks the signature. It must not attribute a signature to a member the signature does not cover. The draft adds no nonce requirement of its own.

/ 02What it proves

What a valid result shows, and what it does not.

Shows

  • A holder of a key published at the named URL signed the covered parts of the request.
  • The signature was used inside its stated validity window.

Does not show

  • Who operates the agent. The draft says the signature “says nothing about who operates the Agent, whether the Agent is benign, or whether the request is authorized.”
  • That the request body was unchanged. The draft does not require covering it.
  • Any delegation from a buyer. The draft “does not define authorization or delegation.”
/ 03In a dispute

What it leaves on the record.

Web Bot Auth answers one dispute question: which published key signed the requests that led to the order. It cannot show that a buyer approved the purchase, it does not require covering the request body, and it says nothing about payment.

Keep the verification result, key ID, directory URL, and timestamps with the order. In October 2025, Mastercard said it is incorporating Web Bot Auth into Agent Pay, and American Express said it will use it in its agentic commerce program.

/ 04For merchants

What to do now.

  1. 01

    Check whether your CDN or firewall already verifies it. Cloudflare, AWS WAF, Vercel, and Akamai have announced support.

  2. 02

    Pass the verification result to checkout and record it with the order.

  3. 03

    Do not skip authorization checks because a signature is valid.

  4. 04

    If you verify it yourself, accept the dictionary form of Signature-Agent. Earlier drafts used a bare string, which verifiers may still accept but signers must no longer send.

  5. 05

    Record the draft version you implement. Field rules can change before it becomes an RFC.

/ 05Where KYA fits

What KYA does with Web Bot Auth today.

Directory and verifier routes are live. The verifier accepts the legacy string form of Signature-Agent only, so it rejects signatures that use the dictionary form the -00 draft requires. AgentCheck signs its outbound page requests when a Web Bot Auth key is provisioned; other outbound agent HTTP calls are not signed.

KYA: beta
/ 06Questions

Short answers.

Is Web Bot Auth a standard?

Not yet. It is an IETF working-group draft, draft-ietf-webbotauth-httpsig-protocol-00, adopted on 1 September 2026. The working group was chartered in October 2025.

What changed in Signature-Agent?

Earlier versions sent Signature-Agent as a bare string. The -00 working-group draft makes it a dictionary keyed by signature label, and each signature must cover its own member. Signers must send the dictionary form; verifiers may also accept the bare string from older deployments.

Does Web Bot Auth require Ed25519?

No. The draft asks for algorithms registered with IANA. Its test vectors and Cloudflare’s implementation use Ed25519.

Is Visa TAP built on Web Bot Auth?

Both use RFC 9421, and Visa calls TAP aligned with Web Bot Auth. TAP uses its own tags, keys that Visa publishes, and a nonce rule, so a Web Bot Auth verifier does not check TAP as-is.

Next step

Keep what each agent order leaves behind.

We’ll map what Web Bot Auth and the other specs reaching your checkout produce to one record per order, with the gaps marked.

Request a pilot