What Is Web Bot Auth?
Most websites still decide whether a visitor is a known crawler by looking at two signals: the User-Agent header and the IP address the request comes from. Both are weak. Any script can send a User-Agent that claims to be a famous search engine or AI assistant, and IP allowlists break whenever a bot operator moves to new cloud ranges or routes traffic through a proxy. Site owners end up either trusting liars or blocking legitimate bots by accident.
Web Bot Auth replaces those guesses with cryptography. The bot operator creates a key pair, publishes the public key at a well-known URL on a domain they control, and signs every outgoing request with the private key. A website (or the CDN in front of it) reads the signature headers, fetches the public key from the operator's key directory, and checks the math. If the signature verifies, the request really came from whoever holds that private key. Nobody else can produce a valid signature, no matter what User-Agent they send.
The signing itself is not new. It reuses HTTP Message Signatures, standardized as RFC 9421, which defines how to sign selected parts of an HTTP message and carry the result in the Signature-Input and Signature headers. Web Bot Auth adds a profile on top: which components bots should sign, a tag value of web-bot-auth, a Signature-Agent header that points to the key directory, and a JSON format for that directory.
Be aware that the Web Bot Auth pieces are still IETF Internet-Drafts, not finished RFCs. The architecture draft and the HTTP Message Signatures Directory draft can still change, and field names or required parameters may shift between revisions. Cloudflare already documents verification of these signatures, so there is real deployment, but you should follow the drafts and the verifier you care about and expect to adjust your signer over time.
This generator gives you everything needed to try the scheme end to end: an Ed25519 key, the directory to publish, and a signed example request you can compare against your own code.