Web Bot Auth

Web Bot Auth lets verified agents prove who they are with HTTP Message Signatures, listed in a signatures directory.

Standard
Emerging checkEmerging
Off by default, turn on in settings

What it checks

A User-Agent header is easy to fake. Web Bot Auth lets an agent sign its requests with HTTP Message Signatures so a site can confirm who sent them.

The extension looks for a non-empty /.well-known/http-message-signatures-directory. Failing that, it checks the homepage response for a Signature-Agent or Accept-Signature header, which some servers use to advertise signature support.

Results

Status When
Pass A signatures directory is published, or the homepage sends Signature-Agent or Accept-Signature
N/A Neither was found

How to fix

If you operate an agent, publish your signing keys as a JSON Web Key Set at /.well-known/http-message-signatures-directory, served with Content-Type: application/http-message-signatures-directory+json:

{
  "keys": [
    {
      "kty": "OKP",
      "crv": "Ed25519",
      "x": "<base64url public key>"
    }
  ]
}

If you run a site and want to verify signed agents, most sites get this from their CDN or bot-management provider rather than building it themselves.