ab//

// agents

what is Web Bot Auth: cryptographically declared agents?

The standards-track answer to declared-vs-stealth agents: a bot signs its requests (RFC 9421 HTTP Message Signatures) so an origin can cryptographically verify who it is instead of trusting a spoofable user-agent. It does not detect stealth agents; it turns the problem into a good-bot/bad-bot allow-list.. Drafts moving; signature-agent + well-known-jwks facets are speculative. asOf 2026-06-15.

source capture as of 2026-06-15

in the benchmark

Web Bot Auth: cryptographically declared agents is tracked as part of the agents taxonomy. see how tracked tools score against it on the capability matrix.

related

where to go from here