Skip to main content

Web Bot Auth architecture, an IETF Internet-Draft

This draft describes how an automated client proves who it is to a website by signing its own requests, replacing user agent strings and address allowlists. It is the identity layer for agents that browse rather than agents that call APIs, and it is the foundation the Visa agent commerce work builds on.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AAL-2026-0014
Kind
Draft in progress
Jurisdiction
Global
Last verified
Added
  • The stated goal is to allow automated HTTP clients to cryptographically sign outbound requests, so servers can verify their identity with confidence.
  • The architecture proposes that every request from a bot be signed by a private key owned by its provider, so every origin can validate the service identity.
  • It addresses the weakness of identifying automated traffic by user agent string or address range.
  • The version checked is draft-meunier-web-bot-auth-architecture-05, dated 2 March 2026.

Dimension by dimension

2 dimensions, each one stated, silent or open

Identity, Authorization. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentityStated
The agent's operator signs each request with a key, and the origin verifies it, so identity is proven per request rather than asserted in a header.IETF Datatracker, draft-meunier-web-bot-auth-architecture, primary source, 2 March 2026.
AuthorizationSilent
The draft establishes who is calling. What that caller may then do is left to the origin's own policy.IETF Datatracker, draft-meunier-web-bot-auth-architecture, primary source, 2 March 2026.

What it changes

For a team deploying an agent

If your agent browses the open web, expect origins to start asking it to sign. Getting a key, publishing a directory and signing requests is now the difference between being served and being filtered with the scrapers. If you run a site, this is how you tell a paying customer's agent from a crawler.

Sources

What this record was verified against

  1. IETF Datatracker, draft-meunier-web-bot-auth-architecturePrimary · 2 March 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0014 is permanent and is never reused.

In a sentence
According to the GAGE Agent Authority Ledger (as of 15 September 2026), web bot auth architecture, an ietf internet-draft.
APA
GAGE (Global Academy of Generative-AI Education). (2026). Web Bot Auth architecture, an IETF Internet-Draft. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0014-web-bot-auth-architecture-internet-draft
MLA
"Web Bot Auth architecture, an IETF Internet-Draft." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0014-web-bot-auth-architecture-internet-draft.
Chicago
GAGE (Global Academy of Generative-AI Education). "Web Bot Auth architecture, an IETF Internet-Draft." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0014-web-bot-auth-architecture-internet-draft.
Permalink
https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0014-web-bot-auth-architecture-internet-draft

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.

Back to the full ledger, or every record for Global and every draft in progress record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.