How does a bot prove to websites that it is who it says it is?
Web Bot Auth lets the company behind a bot sign every request it sends, so a website can check the signature instead of trusting a name anyone can copy. The bot's owner publishes the public keys on their own domain. This check asks whether the scanned domain publishes those keys, which only makes sense if it runs a bot.
What it actually is
A bot's user-agent name is a name tag: anyone can write anything on one. A signature is a wax seal. The bot seals each request with a private key, and the website, or a service such as Cloudflare acting for it, fetches the matching public key from the operator's domain and checks the seal. The keys live in a small directory file under a well-known address.
Why it matters
Sites increasingly block or slow anything that looks automated, because so many bots lie about who they are. A bot that can prove its identity can be let through on purpose rather than caught in the net. For a company that runs a crawler or an agent, signing is fast becoming the price of being welcome.
What good looks like
Only if you operate a bot or agent: a key directory on the domain your bot signs as, holding current public keys and nothing else, matching the keys your bot actually signs with. We publish one ourselves, because our scanner is a bot and it signs its requests.
Being honest about it
This is an Advanced check: it never fails a page and stays out of your headline score. It is aimed at the operator of a bot, not at the sites bots visit, so for nearly every website a warning here is correct and nothing needs doing. Publishing keys for a bot you do not run would protect nothing. The standard itself is still an IETF draft.
Where most sites go wrong
The classic mistake is the wrong party: a publisher reads that signed bots are the future and publishes a key directory of its own, which proves nothing about the bots that visit it. On the operator side, the usual faults are keys rotated in the bot but not in the directory, or a directory that answers some request types and not others.
Not sure where yours stands?
A free scan checks this and everything else in about 20 seconds — no signup. Or if it's already flagged and you'd rather it were simply handled, we do that too.
Flagged for this one? We handle it. No pitch, just a plain-English chat.
Book a call