Web Bot Auth
Web Bot Auth lets verified agents prove who they are with HTTP Message Signatures, listed in a signatures directory.
- Category
- Bot access control
- Standard
- Emerging checkEmerging
- Off by default, turn on in settings
What it checks
A User-Agent header is easy to fake. Web Bot Auth lets an agent sign its
requests with HTTP Message Signatures so a site can confirm who sent them.
The extension looks for a non-empty
/.well-known/http-message-signatures-directory. Failing that, it checks the
homepage response for a Signature-Agent or Accept-Signature header, which
some servers use to advertise signature support.
Results
| Status | When |
|---|---|
| Pass | A signatures directory is published, or the homepage sends Signature-Agent or Accept-Signature |
| N/A | Neither was found |
How to fix
If you operate an agent, publish your signing keys as a JSON Web Key Set at
/.well-known/http-message-signatures-directory, served with
Content-Type: application/http-message-signatures-directory+json:
{
"keys": [
{
"kty": "OKP",
"crv": "Ed25519",
"x": "<base64url public key>"
}
]
}
If you run a site and want to verify signed agents, most sites get this from their CDN or bot-management provider rather than building it themselves.