Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Web Bot Auth is designed to authenticate automated HTTP clients to websites primarily intended for people—not to identify the person behind an agent, decide what a bot may access, or rate its trustworthiness. Its approved charter and current protocol draft define a deliberately bounded project: cryptographic bot identity for web traffic, with authorization, reputation, intent labels, and several other adjacent problems left to separate systems and origin policies.

What Web Bot Auth is meant to cover

The IETF’s approved Web Bot Auth charter focuses on methods for cryptographically authenticating automated clients and conveying additional information about their operators to websites whose primary audience is human users.

Examples named in the charter include search-index crawlers, web archives, link checkers and validators, AI training crawlers, and AI agents that retrieve or interact with content for end users. The planned work includes authentication, a widely used identifier for conveying additional information, and operational guidance on lifecycle management, key management, deployment, and effects on the openness of the Web.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For site operators, the motivation includes managing origin resources and access, reducing impersonation and damage to reputation, and differentiating service levels between automated and non-automated traffic. Those are reasons to establish a bot’s identity; they do not mean the authentication mechanism itself grants access or measures reputation.

What the charter explicitly excludes

The charter lists the following as out of scope. These exclusions describe the working group’s approved remit, not a claim that the problems are unimportant or cannot be addressed elsewhere.

  • API and agent-to-agent authentication: The charter excludes authenticating access to content not intended for human consumption, giving HTTP APIs and agent-to-agent interfaces as examples.
  • Identifying the end user: An agent acting for a person may be in scope, but authenticating that person is not. Web Bot Auth is about the agent’s identity.
  • Protocols other than HTTP: The project is scoped to HTTP, not authentication across arbitrary application protocols.
  • Non-cryptographic checks: The charter is about cryptographic authentication, not other ways of classifying or verifying clients.
  • A standard vocabulary of bot intents: It does not define common labels for what bots intend to do.
  • Bot reputation tracking: It does not track or assign a reputation score to particular bots.
  • Detecting non-participating bots: It does not specify how to distinguish a bot that does not use Web Bot Auth from an ordinary, non-bot client.

What the current protocol draft adds—and does not add

The working-group protocol document is titled “HTTP Message Signatures for automated traffic.” Its abstract describes automated HTTP clients cryptographically signing outbound requests so servers can verify identity. The draft specifies a Signature-Agent header for in-band key discovery, a JWKS-based key-directory format, and a well-known URI for serving that directory.

That document, draft-ietf-webbotauth-httpsig-protocol-00, is an Internet-Draft dated 2026-09-01, with an expiry date of 2027-03-05. It is not a finalized standard, and its boundaries may change as the work progresses.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The draft’s out-of-scope section says the protocol does not authenticate human users, provide anonymous authentication, or define authorization or delegation. It also does not determine how trust is accrued or held. A valid signature associates a request with an identity under the protocol’s checks; whether an origin processes that request depends on the origin’s policy. Additional signed fields may carry other meanings, but the identity signature alone does not establish them.

How to interpret a Web Bot Auth identity signal

Keep these distinctions in mind when reading claims about the project or considering its role in a site’s traffic policy:

  • Authenticated agent does not mean authenticated person. The agent may establish its own identity while the human on whose behalf it acts remains unidentified by this work.
  • Authentication does not mean authorization. A verified identity signal is not permission to access a resource. The origin makes that decision under its own policy.
  • Participation is not universal bot detection. The charter leaves recognition of non-participating bots outside the project, so Web Bot Auth is not a method for classifying every client.
  • Identity is not intent or reputation. The charter excludes both an intent vocabulary and reputation tracking; the current draft also leaves trust accrual and management unanswered.

How Web Bot Auth differs from adjacent authentication questions

The scope is easiest to understand by asking what is being authenticated, where the request is going, and what the result is meant to establish.

Question Web Bot Auth’s stated scope
Who or what is authenticated? An automated client. Identifying the end user is excluded by the charter and protocol draft.
What traffic is covered? Automated HTTP access to websites primarily intended for human users. API and agent-to-agent authentication are excluded by the charter.
Does authentication grant access? No. The protocol draft does not define authorization or delegation; an origin applies its own policy.
Must every bot participate? No universal classification is provided. Detecting non-participating bots is explicitly outside the charter’s scope.
Does it standardize intent or reputation? No. The charter excludes an intent vocabulary and bot reputation tracking; the draft does not define how trust is accrued or held.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Where to check the project’s current status

Web Bot Auth is an active IETF working group, but working-group status and Internet-Draft revisions can change. The IETF Web Bot Auth page lists the group’s documents and status; consult it for the latest versions rather than treating the September 2026 protocol draft as final.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.