---
title: "Web Bot Auth · Sitebulb Labs"
description: "Web Bot Auth lets verified agents prove who they are with HTTP Message Signatures, listed in a signatures directory."
url: https://labs.sitebulb.com/docs/checks/bot-access-control/web-bot-auth/
---

# Web Bot Auth

Web Bot Auth lets verified agents prove who they are with HTTP Message Signatures, listed in a signatures directory.

- Category

  [Bot access control](https://labs.sitebulb.com/docs/checks/bot-access-control)

- Standard

  - Emerging checkEmerging
  - Off by default, turn on in settings

## What it checks

A `User-Agent` header is easy to fake. Web Bot Auth lets an agent sign its requests with HTTP Message Signatures so a site can confirm who sent them.

The extension looks for a non-empty `/.well-known/http-message-signatures-directory`. Failing that, it checks the homepage response for a `Signature-Agent` or `Accept-Signature` header, which some servers use to advertise signature support.

## Results

| Status   | When                                                                                               |
| -------- | -------------------------------------------------------------------------------------------------- |
| **Pass** | A signatures directory is published, or the homepage sends `Signature-Agent` or `Accept-Signature` |
| **N/A**  | Neither was found                                                                                  |

## How to fix

If you operate an agent, publish your signing keys as a JSON Web Key Set at `/.well-known/http-message-signatures-directory`, served with `Content-Type: application/http-message-signatures-directory+json`:

```json
{
  "keys": [
    {
      "kty": "OKP",
      "crv": "Ed25519",
      "x": "<base64url public key>"
    }
  ]
}
```

If you run a site and want to verify signed agents, most sites get this from their CDN or bot-management provider rather than building it themselves.
