Web Bot Auth
IETF work on cryptographically authenticating automated clients, including agents, to websites.
Web Bot Auth is the name of an IETF working group that is standardising methods for cryptographically authenticating automated clients, such as crawlers, archivers and agents, to websites that mainly serve people. Its charter covers authenticating the agent and conveying more information about its operator, and places authentication of the end user out of scope. The drafts build on HTTP Message Signatures, and until they are published as RFCs they are work in progress.
Agent Minute explains this term on 13 February 2027.
Related terms
HTTP Message SignaturesAn IETF standard for signing selected parts of an HTTP request or response so the receiver can verify them.Know Your Agent (KYA)Checking which agent is acting, who operates it and whom it acts for, before letting it act.Trusted Agent ProtocolVisa's specification for signals that let merchants recognise trusted commerce agents and the consumer behind them.Agent cardIn A2A, a published description of an agent's identity, skills, endpoint and authentication requirements.