DISPATCH · 16 SEP 2026

Web Bot Auth in 2026: from IETF drafts to CDN verification

How signed bot requests work, who checks them today, and what to do on each side of the request.


Agent Readiness Compare editors · Spec status checked September 2026

Agent Readiness Compare editors · · 6 min read

Answer

Web Bot Auth lets a bot operator sign HTTP requests so a site can verify who sent them, using HTTP Message Signatures (RFC 9421) and two IETF Internet-Drafts. It is not yet an RFC, but Cloudflare documents it as a bot verification method, Vercel's bot verification supports it, and since 28 August 2026 Cloudflare's BotBase validates Web Bot Auth signatures automatically when operators submit a bot. Sites mostly need a policy for verified agents; operators need keys and a key directory.

On this page
  1. 1. What problem does it solve?
  2. 2. How does it work?
  3. 3. Who verifies it today?
  4. 4. What should a website do?
  5. 5. What should an agent operator do?
  6. 6. What does it not do?
  7. 7. Where is it heading?
  8. 8. Sources

1.What problem does it solve?

A site that wants to let a known AI agent through, and keep other automation out, cannot rely on the User-Agent header, because any client can copy it. Web Bot Auth replaces the claim with a signature the site or its CDN can check. That lets a site treat verified agents differently from unknown traffic: pass them through a bot challenge, rate-limit them separately, or count them in analytics.

2.How does it work?

From Cloudflare's documentation:

  1. The bot operator generates an Ed25519 signing key.
  2. It hosts a key directory at /.well-known/http-message-signatures-directory over HTTPS.
  3. It signs requests with HTTP Message Signatures (RFC 9421).
  4. The receiving site or CDN fetches the key directory and verifies each signature.

The two drafts are draft-meunier-http-message-signatures-directory, which covers publishing the keys, and draft-meunier-webbotauth-httpsig-protocol, which covers how keys attach an identity to requests and replaced the earlier architecture draft. Cloudflare's documentation, updated 1 July 2026, cites directory draft 03 and architecture draft 02.

3.Who verifies it today?

  • Cloudflare documents Web Bot Auth as a bot verification method. Operators register through the Bot Submission Form, choosing "Request Signature" and providing the key directory URL.
  • On 28 August 2026 Cloudflare moved bot submissions to a BotBase dashboard for operators, with review status, editing and automatic validation of verification methods, including Web Bot Auth signatures.
  • Vercel's changelog announced that its bot verification supports Web Bot Auth, and BotID's checkBotId() returns isVerifiedBot, verifiedBotName and verifiedBotCategory, so a handler can allow a named verified bot. Vercel keeps a directory of known and verified bots at bots.fyi.
  • Readiness scanners check for it: ora.ai's AgentReady specification lists Web Bot Auth under identity and access, and Cloudflare's Is It Agent Ready lists it under bot access control.

4.What should a website do?

Most sites verify rather than sign. If your CDN or platform verifies Web Bot Auth, the work is a policy: which verified agents may pass challenges, which are rate-limited, and which are logged. Write it next to your robots.txt policy (lesson 9), then check that the challenge on your demo or checkout step lets verified agents through (checklist L4.2 and L5.1).

5.What should an agent operator do?

If you run a bot or agent that visits other sites, sign its requests and host a key directory at the well-known path over HTTPS (checklist L5.2). Register with the CDNs your agent meets most; on Cloudflare that now happens in BotBase, where the signature is validated automatically. Keep the key directory current whenever keys change.

6.What does it not do?

  • It identifies the operator, not the person the agent acts for. Delegated access to a user's account needs OAuth, and commerce identity is a separate layer: Forter, for example, describes linking agent shoppers to verified customer identities.
  • It does not set policy. The site still decides what a verified agent may do.
  • It is not yet an RFC. Expect changes to the drafts, and check your CDN's documentation for the versions it supports.

7.Where is it heading?

Agent identity is on the wider agenda. The MCP roadmap of 22 August 2026 lists agent identity and enterprise security among its five priorities, naming DPoP and Workload Identity Federation, and Cloudflare's BotBase describes bots with a taxonomy based on its Content Signals model. For now the practical steps are the ones above: verify at the edge, write the policy, and sign if you operate an agent. See the Web Bot Auth standard page.

8.Sources

Reviewed Sep 2026