AI GlossaryㅇInfrastructure and chips
Web Bot Auth
A method that lets bots or AI agents cryptographically sign requests to prove their own identity — essentially saying 'this is what I am' with a verifiable signature
In plain words
Web Bot Auth is a way for robot programs to present a sealed ID card instead of a self-written introduction, the way a human might. Until now, websites have relied on a single label in the request header to tell whether a visitor is a search engine crawler, a malicious scraper, or a human. But anyone can write anything into that label, so a bad program could simply claim to be a well-known crawler, and the site had no good way to filter that out.
Web Bot Auth stamps that label with a seal that can't be forged. Whoever operates the bot signs its requests with a cryptographic key, and the receiving side can verify that signature to confirm the request really did come from that bot. It's the difference between just stating a name and presenting a signed document.
The problem has grown more pressing as AI agents increasingly act on behalf of people, directly using websites or APIs. Without a fixed identity for an agent, a site can't tell whether it's dealing with a genuinely authorized program or malicious traffic pretending to be one. Web Bot Auth is a mechanism for nailing down 'who sent this request' before matters like payment or account creation even come into play.
See also
Stories using this term
- Cloudflare Gives AI Agents a Wallet — Today, Only Name Reservation WorksAI · 2026.08.06
- Hermes Agent Cuts 12 Browser Tools Down to OneAI · 2026.08.11
- Claude MCP Connectors Get Centralized Enterprise AuthenticationAI · 2026.08.25
- ChatGPT Work can now handle tasks on sites that require loginAI · 2026.08.26
- 35% of Web Pages Published Since ChatGPT Show Signs of AI AuthorshipBusiness · 2026.08.21
- AWS connects local MCP tools to cloud agentsAI · 2026.08.06
