Web Bot Auth architecture, an IETF Internet-Draft
This draft describes how an automated client proves who it is to a website by signing its own requests, replacing user agent strings and address allowlists. It is the identity layer for agents that browse rather than agents that call APIs, and it is the foundation the Visa agent commerce work builds on.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AAL-2026-0014
- Kind
- Draft in progress
- Jurisdiction
- Global
- Last verified
- Added
- The stated goal is to allow automated HTTP clients to cryptographically sign outbound requests, so servers can verify their identity with confidence.
- The architecture proposes that every request from a bot be signed by a private key owned by its provider, so every origin can validate the service identity.
- It addresses the weakness of identifying automated traffic by user agent string or address range.
- The version checked is draft-meunier-web-bot-auth-architecture-05, dated 2 March 2026.
Dimension by dimension
2 dimensions, each one stated, silent or open
Identity, Authorization. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentityStated
- The agent's operator signs each request with a key, and the origin verifies it, so identity is proven per request rather than asserted in a header.IETF Datatracker, draft-meunier-web-bot-auth-architecture, primary source, 2 March 2026.
- AuthorizationSilent
- The draft establishes who is calling. What that caller may then do is left to the origin's own policy.IETF Datatracker, draft-meunier-web-bot-auth-architecture, primary source, 2 March 2026.
What it changes
For a team deploying an agent
If your agent browses the open web, expect origins to start asking it to sign. Getting a key, publishing a directory and signing requests is now the difference between being served and being filtered with the scrapers. If you run a site, this is how you tell a paying customer's agent from a crawler.
Sources
What this record was verified against
- IETF Datatracker, draft-meunier-web-bot-auth-architecturePrimary · 2 March 2026
Related
Records that sit beside this one
Visa Trusted Agent Protocol
Global · verified 15 September 2026
Visa describes the specification as the official rulebook detailing the technical processes for recognizing a Visa approved agent, including the cryptographic standards in RFC 9421.
Agent Passport System, an IETF Internet-Draft
Global · verified 15 September 2026
The draft defines Ed25519 agent passports and separately signed principal bindings.
Does a spending limit belong to the agent or to the principal
Global · verified 15 September 2026
The Visa Trusted Agent Protocol addresses recognising an approved agent and its intent, and does not itself carry a spending ceiling.
How does a sub agent's authority attenuate
Global · verified 15 September 2026
RFC 8693 lets a token record that one party is acting for another, but does not require the exchanged token to be narrower.
Can an agent hold a credential of its own
Global · verified 15 September 2026
NIST SP 800-63-4 states that for that publication, person refers only to natural persons.
Who is liable when a delegated agent exceeds its mandate
Global · verified 15 September 2026
The EU AI Act allocates duties to providers and deployers, and does not address an agent acting beyond its instructions.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0014 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), web bot auth architecture, an ietf internet-draft.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Web Bot Auth architecture, an IETF Internet-Draft. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0014-web-bot-auth-architecture-internet-draft
- MLA
- "Web Bot Auth architecture, an IETF Internet-Draft." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0014-web-bot-auth-architecture-internet-draft.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Web Bot Auth architecture, an IETF Internet-Draft." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0014-web-bot-auth-architecture-internet-draft.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0014-web-bot-auth-architecture-internet-draft
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
Back to the full ledger, or every record for Global and every draft in progress record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.